[![Logo](https://www.paloaltonetworks.com/wp-content/uploads/2021/07/PANW_Parent.png)](https://www.paloaltonetworks.com/)  
[![Unit42 Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/unit42-logo-white.svg)](https://unit42.paloaltonetworks.com/)  
Menu

* [Tools](https://unit42.paloaltonetworks.com/tools/)
* [ATOMs](https://unit42.paloaltonetworks.com/atoms/)
* [Security Consulting](https://www.paloaltonetworks.com/unit42)
* [About Us](https://unit42.paloaltonetworks.com/about-unit-42/)
* [**Under Attack?**](https://start.paloaltonetworks.com/contact-unit42.html)  
  English
* [English](https://unit42.paloaltonetworks.com/unit42-bucbi-ransomware-is-back-with-a-ukrainian-makeover/)
* [Japanese](https://unit42.paloaltonetworks.com/ja/unit42-bucbi-ransomware-is-back-with-a-ukrainian-makeover/)
* [Threat Research Center](https://unit42.paloaltonetworks.com "Threat Research")
* [Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/ "Threat Research")
* [Ransomware](https://unit42.paloaltonetworks.com/category/ransomware/ "Ransomware")  
  [Ransomware](https://unit42.paloaltonetworks.com/category/ransomware/)

# Bucbi Ransomware Is Back With a Ukrainian Makeover

![Clock Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-clock.svg) 8 min read

* ![Profile Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-profile-grey.svg)  
  By:

* ![Published Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-calendar-grey.svg)  
  Published:May 6, 2016

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-category.svg)  
  Categories:
  
  * [Malware](https://unit42.paloaltonetworks.com/category/malware/)
  * [Ransomware](https://unit42.paloaltonetworks.com/category/ransomware/)
  * [Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/)

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-tags-grey.svg)  
  Tags:
  
  * [Bucbi](https://unit42.paloaltonetworks.com/tag/bucbi/)
  * [RDP](https://unit42.paloaltonetworks.com/tag/rdp/)

* [![Download Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-download.svg)](https://unit42.paloaltonetworks.com/unit42-bucbi-ransomware-is-back-with-a-ukrainian-makeover/?pdf=download&lg=en&_wpnonce=46edad538b "Click here to download")

* [![Print Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-print.svg)](https://unit42.paloaltonetworks.com/unit42-bucbi-ransomware-is-back-with-a-ukrainian-makeover/?pdf=print&lg=en&_wpnonce=46edad538b "Click here to print")

Share![Down arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/down-arrow.svg)

* ![Link Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-share-link.svg)
* [![Link Email](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-sms.svg)](mailto:?subject=Bucbi%20Ransomware%20Is%20Back%20With%20a%20Ukrainian%20Makeover&body=Check%20out%20this%20article%20https%3A%2F%2Funit42.paloaltonetworks.com%2Funit42-bucbi-ransomware-is-back-with-a-ukrainian-makeover%2F "Share in email")
* [![Facebook Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-fb-share.svg)](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Funit42.paloaltonetworks.com%2Funit42-bucbi-ransomware-is-back-with-a-ukrainian-makeover%2F "Share in Facebook")
* [![LinkedIn Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-linkedin-share.svg)](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Funit42-bucbi-ransomware-is-back-with-a-ukrainian-makeover%2F&title=Bucbi%20Ransomware%20Is%20Back%20With%20a%20Ukrainian%20Makeover "Share in LinkedIn")
* [![Twitter Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-twitter-share.svg)](https://twitter.com/intent/tweet?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Funit42-bucbi-ransomware-is-back-with-a-ukrainian-makeover%2F&text=Bucbi%20Ransomware%20Is%20Back%20With%20a%20Ukrainian%20Makeover "Share in Twitter")
* [![Reddit Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-reddit-share.svg)](https://www.paloaltonetworks.com//www.reddit.com/submit?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Funit42-bucbi-ransomware-is-back-with-a-ukrainian-makeover%2F&ts=markdown "Share in Reddit")
* [![Mastodon Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-mastodon-share.svg)](https://mastodon.social/share?text=Bucbi%20Ransomware%20Is%20Back%20With%20a%20Ukrainian%20Makeover%20https%3A%2F%2Funit42.paloaltonetworks.com%2Funit42-bucbi-ransomware-is-back-with-a-ukrainian-makeover%2F "Share in Mastodon")
  The Bucbi ransomware family, which dates back to early 2014, has received a significant update. In a recently observed attack, we also noted new tactics used to infect systems. The malware has historically been delivered via an HTTP download, most likely via an exploit kit or phishing email. However, in recent weeks, Palo Alto Networks researchers have observed attackers brute-forcing RDP accounts on Internet-facing Windows servers to deliver their malware. Additionally, the malware itself has been modified to no longer require an Internet connection.

Recent ransom notes left on infected systems identify the malware as belonging to the "Ukrainian Right Sector," a far-right Ukrainian nationalist political party with paramilitary operations that opposes Russia but operate outside of the Ukrainian government's authority. However, there are a number of Russian identifiers in the recent attacks. Consequently, it is unclear if the claims of responsibility by the "Ukrainian Right Sector" are accurate, and if so, what the reason behind and significance of the Russian identifiers.

### Infiltration

Unlike many other ransomware families, this particular variant of Bucbi was delivered via a RDP brute force attack. The following five IP addresses were observed attacking the victim machine starting in late March 2016:

* 31\.184.197.69
* 31\.44.191.251
* 79\.117.151.236
* 46\.161.40.11
* 191\.101.31.126

Many common usernames were used in attempted logins in this brute force attack, including a number of point of sale (PoS) specific usernames. It is likely that this attack originally began with the attackers seeking out PoS devices, and after a successful compromise, changed their tactics once they discovered that the compromised device did not process financial transactions. A truncated list of the usernames used in attempted logins can be found below.

* Administrator
* Aloha
* Admin
* BPOS
* FuturePos
* HelpAssistant
* KahalaPOS
* Oracle
* POS
* SALES
* SERVER
* Sqladmin
* Staff
* Администратор \['Administrator' in Russian\]

Once the attackers successfully compromised this specific machine, they dropped an executable file that contains the following PDB string:

*C:\\inetpub\\restartprm\\Present\\Перед запуском софта\\dotNetFx45\_Full\_setup.exe*

The Russian string above roughly translates to 'Before running software'. Researching the filename above leads us to a number of Russian language forums that are discussing an RDP brute force utility named 'RDP Brute (Coded by z668)'. While not confirmed, there is a possibility that this tool was used to gain access to the victim machine originally. A screenshot of this utility can be found below:

[![Bucbi 1](http://blog.paloaltonetworks.com/wp-content/uploads/2016/05/Bucbi-1-500x531.png)](https://blog.paloaltonetworks.com/wp-content/uploads/2016/05/Bucbi-1.png)

*Figure 1 RDP brute force utility*

### Malware Analysis

The following sample was discovered on an attempted breach in early April 2016:

*MD5: 410E395600C291C59D8C9B93FA82A7F3*  
*SHA1: 2E385E8B8CEB01C9E638F8A95889B571D31AEF41*  
*SHA256: 26F2BF1FC3EE321D48DCE649FAE9951220F0F640C69D5433850B469115C144FE*  
*Timestamp: 2016-04-02 16:40:13 UTC*

This particular sample is configured to take one of the following two command-line (CLI) arguments. Should no argument be provided, it will attempt to start a service it expects to exist, named 'FileService'.

* /install
* /uninstall

When provided a CLI argument of '/install', the malware will proceed to create a service with the following properties.

*Service Name: FileService*  
*Display Name: File Service*  
*Startup: Auto*  
*Path: \[path of malware\]*

After the service has been successfully created, the malware outputs a printf statement of 'Installation OK'.

When give a CLI argument of '/uninstall', the malware will remove the previously created service and output a printf statement of 'Uninstallation OK'.

When the service is run, the malware will generate a number of debugging statements that are written to a randomly named file with an extension of '.log' in the %ALLUSERSPROFILE% directory. An example of this log file is below.

[![Bucbi 2](http://blog.paloaltonetworks.com/wp-content/uploads/2016/05/Bucbi-2-500x391.png)](https://blog.paloaltonetworks.com/wp-content/uploads/2016/05/Bucbi-2.png)

*Figure 2 Log file written by malware*

The malware begins by seeking out a file in the victim's %ALLUSERSPROFILE% directory. The filename is generated by a unique algorithm that uses the victim's volume serial number in conjunction with two 4-byte seeds provided to generate a unique 8-byte sequence. This sequence then has a search/replace performed on it in order to convert it into an alphabetic string. This function is represented below.  
signed int \_\_usercall filename\_generation@\<eax\>(WCHAR \*output@\<ebx\>, int s1, int a3) { signed int v3; // eax@2 BYTE volume\_serial\[8\]; // \[esp+8h\] \[ebp-24Ch\]@4 DWORD VolumeSerialNumber; // \[esp+14h\] \[ebp-240h\]@1 \_BYTE \*seed1; // \[esp+18h\] \[ebp-23Ch\]@3 WCHAR Buffer; // \[esp+38h\] \[ebp-21Ch\]@1 \_\_int16 v9; // \[esp+3Eh\] \[ebp-216h\]@2 \_\_int16 v10; // \[esp+240h\] \[ebp-14h\]@1 memset(\&Buffer, 0, 0x208u); v10 = 0; VolumeSerialNumber = 0; if ( !GetWindowsDirectoryW(\&Buffer, 0x104u) ) return 0; v9 = 0; GetVolumeInformationW(\&Buffer, 0, 0, \&VolumeSerialNumber, 0, 0, 0, 0); v3 = 0; do { (\&seed1)\[v3\] = (\_BYTE \*)s1; (\&seed1)\[v3 + 1\] = (\_BYTE \*)a3; v3 += 2; } while ( v3 \< 8 ); \*(\_DWORD \*)\&volume\_serial\[4\] = 0; \*(\_DWORD \*)volume\_serial = VolumeSerialNumber; GOST\_crypt((int)\&seed1, (int \*)volume\_serial); if ( volume\_serial\[0\] \< 'a' || volume\_serial\[0\] \> 'w' ) volume\_serial\[0\] = (unsigned \_\_int16)(volume\_serial\[0\] % 26) + 'a'; if ( volume\_serial\[1\] \< 'a' || volume\_serial\[1\] \> 'w' ) volume\_serial\[1\] = (unsigned \_\_int16)(volume\_serial\[1\] % 26) + 'a'; if ( volume\_serial\[2\] \< 'a' || volume\_serial\[2\] \> 'w' ) volume\_serial\[2\] = (unsigned \_\_int16)(volume\_serial\[2\] % 26) + 'a'; if ( volume\_serial\[3\] \< 'a' || volume\_serial\[3\] \> 'w' ) volume\_serial\[3\] = (unsigned \_\_int16)(volume\_serial\[3\] % 26) + 'a'; if ( volume\_serial\[4\] \< 'a' || volume\_serial\[4\] \> 'w' ) volume\_serial\[4\] = (unsigned \_\_int16)(volume\_serial\[4\] % 26) + 'a'; if ( volume\_serial\[5\] \< 'a' || volume\_serial\[5\] \> 'w' ) volume\_serial\[5\] = (unsigned \_\_int16)(volume\_serial\[5\] % 26) + 'a'; if ( volume\_serial\[6\] \< 'a' || volume\_serial\[6\] \> 'w' ) volume\_serial\[6\] = (unsigned \_\_int16)(volume\_serial\[6\] % 26) + 'a'; if ( volume\_serial\[7\] \< 'a' || volume\_serial\[7\] \> 'w' ) volume\_serial\[7\] = (unsigned \_\_int16)(volume\_serial\[7\] % 26) + 'a'; MultiByteToWideChar(0, 0, (LPCSTR)volume\_serial, 8, output, 8); output\[8\] = 0; return 1; }

|-------------------------------------------------------------------------------------------------------------------------------------------|--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 | signed int \_\_usercall filename\_generation@\<eax\>(WCHAR \*output@\<ebx\>, int s1, int a3) { signed int v3; // eax@2 BYTE volume\_serial\[8\]; // \[esp+8h\] \[ebp-24Ch\]@4 DWORD VolumeSerialNumber; // \[esp+14h\] \[ebp-240h\]@1 \_BYTE \*seed1; // \[esp+18h\] \[ebp-23Ch\]@3 WCHAR Buffer; // \[esp+38h\] \[ebp-21Ch\]@1 \_\_int16 v9; // \[esp+3Eh\] \[ebp-216h\]@2 \_\_int16 v10; // \[esp+240h\] \[ebp-14h\]@1 memset(\&Buffer, 0, 0x208u); v10 = 0; VolumeSerialNumber = 0; if ( !GetWindowsDirectoryW(\&Buffer, 0x104u) ) return 0; v9 = 0; GetVolumeInformationW(\&Buffer, 0, 0, \&VolumeSerialNumber, 0, 0, 0, 0); v3 = 0; do { (\&seed1)\[v3\] = (\_BYTE \*)s1; (\&seed1)\[v3 + 1\] = (\_BYTE \*)a3; v3 += 2; } while ( v3 \< 8 ); \*(\_DWORD \*)\&volume\_serial\[4\] = 0; \*(\_DWORD \*)volume\_serial = VolumeSerialNumber; GOST\_crypt((int)\&seed1, (int \*)volume\_serial); if ( volume\_serial\[0\] \< 'a' || volume\_serial\[0\] \> 'w' ) volume\_serial\[0\] = (unsigned \_\_int16)(volume\_serial\[0\] % 26) + 'a'; if ( volume\_serial\[1\] \< 'a' || volume\_serial\[1\] \> 'w' ) volume\_serial\[1\] = (unsigned \_\_int16)(volume\_serial\[1\] % 26) + 'a'; if ( volume\_serial\[2\] \< 'a' || volume\_serial\[2\] \> 'w' ) volume\_serial\[2\] = (unsigned \_\_int16)(volume\_serial\[2\] % 26) + 'a'; if ( volume\_serial\[3\] \< 'a' || volume\_serial\[3\] \> 'w' ) volume\_serial\[3\] = (unsigned \_\_int16)(volume\_serial\[3\] % 26) + 'a'; if ( volume\_serial\[4\] \< 'a' || volume\_serial\[4\] \> 'w' ) volume\_serial\[4\] = (unsigned \_\_int16)(volume\_serial\[4\] % 26) + 'a'; if ( volume\_serial\[5\] \< 'a' || volume\_serial\[5\] \> 'w' ) volume\_serial\[5\] = (unsigned \_\_int16)(volume\_serial\[5\] % 26) + 'a'; if ( volume\_serial\[6\] \< 'a' || volume\_serial\[6\] \> 'w' ) volume\_serial\[6\] = (unsigned \_\_int16)(volume\_serial\[6\] % 26) + 'a'; if ( volume\_serial\[7\] \< 'a' || volume\_serial\[7\] \> 'w' ) volume\_serial\[7\] = (unsigned \_\_int16)(volume\_serial\[7\] % 26) + 'a'; MultiByteToWideChar(0, 0, (LPCSTR)volume\_serial, 8, output, 8); output\[8\] = 0; return 1; } |

The algorithm above makes use of the [GOST block cipher](<https://en.wikipedia.org/wiki/GOST_(block_cipher)>) to generate a unique filename. GOST is fairly obscure, as it was developed in the 1970s by the Soviet government. It was declassified to the public in 1994. This particular technique for generating a unique filename looks to be specific to Bucbi, as no other malware families have been discovered using it.

The algorithm is used to determine if a key file is present on the victim. If this particular file is not present, the malware proceeds to generate one. Two files are created---one 580 bytes in size, and one 1060 bytes in size. Both files begin with a DWORD of 0x60000, as shown in the screenshot below.

[![Bucbi 3](http://blog.paloaltonetworks.com/wp-content/uploads/2016/05/Bucbi-3-500x220.png)](https://blog.paloaltonetworks.com/wp-content/uploads/2016/05/Bucbi-3.png)

*Figure 3 Example key file written by malware*

The cryptography used by Bucbi is still being researched by Palo Alto Networks. After the key files are generated, the malware will spawn a new thread that is responsible for encrypting network resources.

A call to WNetOpenEnum is made to enumerate all network disk resources available. Should a network disk be identified, the encryption routine will be run against this resource. The malware will ignore the following directories, but otherwise will encrypt every file it encounters.

* C:\\WINDOWS
* C:\\Windows
* C:\\Program Files
* C:\\Program Files (x86)

No file type denylisting results in this particular malware being very inefficient, often taking several minutes before encryption is complete.

Files are overwritten, leaving them with the same filename that was originally present. Unlike other more popular ransomware families, Bucbi does not use a specific file extension for files that are encrypted.

It's also important to note that the key files that were originally created are not removed. Additionally, the malware includes a decryption routine, which, while never called by the malware, exists and can be used with a simple binary modification to the sample. This would allow victims to recover their files without resorting to paying the ransom.

Once encryption completes, a README.txt file is placed on the victim's desktop. This file contains the following information:

[![Bucbi 4](http://blog.paloaltonetworks.com/wp-content/uploads/2016/05/Bucbi-4-500x112.png)](https://blog.paloaltonetworks.com/wp-content/uploads/2016/05/Bucbi-4.png)

*Figure 4 Ransom message dropped by malware*

The BitCoin address mentioned in the above screenshot has a single payment of 0.00896 BTC at the time of writing. This payment, being so low in value, was likely a test transaction used. The email address of 'dopomoga.rs@gmail.com' has ties with the Ukrainian Right Sector in a number of external publications, as noted in the following examples.

[![Bucbi 5](http://blog.paloaltonetworks.com/wp-content/uploads/2016/05/Bucbi-5-500x677.png)](https://blog.paloaltonetworks.com/wp-content/uploads/2016/05/Bucbi-5.png)

*Figure 5 Facebook post from November 4, 2015*

[![Bucbi 6](http://blog.paloaltonetworks.com/wp-content/uploads/2016/05/Bucbi-6-500x645.png)](https://blog.paloaltonetworks.com/wp-content/uploads/2016/05/Bucbi-6.png)

*Figure 6 Translated post from sectorpravdy.com*

However, as mentioned earlier, there are a number of indications that the actor is of Russian origin or speaks the Russian language, such as the existence of Russian PE resources within the malware executable, as well as the Russian-related files discovered in the attack.

### Similarities and Differences With Older Versions of Bucbi

As mentioned earlier, the Bucbi malware family is quite old, dating back to January 2014. Very little public information about Bucbi is available, other than [an entry by Microsoft in mid-2014](https://www.microsoft.com/security/portal/threat/encyclopedia/Entry.aspx?Name=Ransom%3AWin32%2FBucbi.A).

When comparing the newly discovered Ukrainian variant of Bucbi to [an older sample](https://www.virustotal.com/en/file/b561b91cce444e9dc768bd93e0404e67f79900598ef03f175a10887c7b94c30c/analysis/), we see a number of similarities. Certainly one of the most noticeable similarities comes in the form of a debug string present in both samples:

*Ukrainian Variant: C:\\Users\\admin\\Desktop\\FileService\\FileCrypt\\Release\\payload.pdb*  
*Older Bucbi Sample: C:\\FileCrypt\\Release\\FileCrypt.pdb*

The original filename of 'FileCrypt' is present in all observed Bucbi samples. Another glaring similarity comes in the form of how filenames are generated. All samples observed use the same GOST block cipher function mentioned in the malware analysis section. This function has only been observed in Bucbi samples to date.

Additionally, the key files used across samples is consistent, in both size and the leading 0x60000 DWORD value. Coding style between samples is consistent as well between all observed instances of Bucbi.

While these similarities are present, a number of changes have been observed as well. Most notably is the service installation method, as well as the command-line arguments of '/install' and '/uninstall'. While the older Bucbi sample also took a command-line argument, it instead searched for the existence of the '-e' parameter.

The implementation of a network-resource encrypt function looks to be new in the Ukrainian variant of Bucbi. Conversely, the use of an HTTP command and control (C2) channel looks to have been removed from this variant. Previous versions of Bucbi, seen as recently as June 2015, made use of a remote server, where victim information and the generated key information was uploaded.

Finally, we also observe a change in ransom notes. The following ransom page is presented to the victim in this older version of Bucbi:

[![Bucbi 7](http://blog.paloaltonetworks.com/wp-content/uploads/2016/05/Bucbi-7-500x376.png)](https://blog.paloaltonetworks.com/wp-content/uploads/2016/05/Bucbi-7.png)

*Figure 7 Original Bucbi ransom page*

### Conclusion

Overall, this proved to be a curious attack, as the attackers originally gained access using techniques common to those of attacks seen against point of sale devices. It appears that once access was acquired, the attackers shifted gears to deploy a new variant of the fairly old Bucbi ransomware family. This particular variant purports to belong to the 'Ukrainian Right Sector', a far-right Ukrainian national political party. If true, this would indicate that this particular national political party has entered the ransomware space, potentially to fund their cause. However, various Russian-related strings and references leave doubt as to who exactly is behind this attack. Attribution of this particular attack is difficult as there simply isn't enough evidence to conclusively determine who is behind it. Various conflicting evidence make it impossible to say for sure. However, what is clear is that attackers are shifting tactics in how ransomware is deployed, and ensuring their malware is constantly being updated to deter defenders.

Palo Alto Networks customers are protected against this threat in the following ways:

* WildFire correctly identifies all Bucbi samples as malicious
* A Bucbi [AutoFocus](https://autofocus.paloaltonetworks.com/)tag has been created in order to track this malware family has been created in order to track this malware family
* All domains/IPs used in this attack have been flagged as malicious.

### Indicators of Compromise

**SHA256 Hashes -- Ukrainian Variant**

*26f2bf1fc3ee321d48dce649fae9951220f0f640c69d5433850b469115c144fe*  
*4c698f5a005a74570a10a69a82317b0c87207934fe82907ee7df3348096cd66c*

**SHA256 Hashes -- Original Bucbi**

*ad16c5246675b807cd04c33f5186f26c1c677e7b2f3baea3305b23e7cac34f8e*  
*be63b6a01e57a7a409647bdf221a37a0be0d470d488136228a4c1d1defbd05f4*  
*98e901f362641ae1fc6527215f496c9fd5de2d7f69b136ac610e453469831d07*  
*2f8597a18c24d9c7ee4442f607b518c065bfef376c554ea80b303875bb0f5c4f*  
*713413ee1a008b91a6afb29c52d2beda829778b8072c5ba5171bb50277104ebc*  
*8577216183fc19767788e3d078eaeb754d18141c80c2554f9c3c359cc470c4f6*  
*feb6eccc9d254fb0e1c818be50ec183a472ed064d4071f380ac131c262da0689*  
*0ed72a28ba5bac7f44f9e4519db5f8c8d94076d85a929c2004da1cba99559610*  
*ea7896c06595a261b140f1ce192230e0fc0bdb9213023db0a5d1b07eb91f7af3*  
*27ba82a72339fef306ef6ce83c055c35caa7bf7116eea0edad22966d297661f3*  
*70d59a3f1f508668b1ae214022a140fb96f90c221a192443b87a1fbe621cee0b*  
*feecc0baccecabeddc8f0e07b3a7aa54d7f13d60e232b7a538b10cd773b4c5e5*  
*766b3a58b5ff86b1070c186b72854c69fff6fc11ce384d70c71db66f6c18a8c8*  
*a65293abd10e7c4a306ddfae94c67df2db411c4a29ca71a1ca8169ee640a8ed3*  
*62f199dedfffef4eb71c33bdf22f4a9b3276f8a831999788059163fae43db48e*  
*8988f592efb88b4998b54c9736898339811bda3578b27e0a4a03ed9a4c5ca363*  
*60fb4c67f4fade5b00d1f57810ec379df3c39b546ead0865296a077e6a8b2f42*  
*ce122be2e52159c3e441c43b81a334b49b7763cf6a2265768d8e2df45478fc6a*  
*30645cdf85546f51862c7dc4750016f872683bc060cc34e4b462e01445a8abfd*  
*9b1b25ab5a6e5291a509c4ad94ab16c25925feaf9e6e8b217494596f76888202*  
*558d32c77167d08ab8594c5df99dd162ae975d8ceb1d169108fe0d70ac8df11a*  
*6e279ea746bc4692ff32acb697da0147ec056700fc095f8ff248317548bcbdcb*  
*56da464cd45f17bacf52b6497396e2c801625bd4068790d9d9515a087584f630*  
*14ff3948a11b7469882bda4e8fcf89600aaaf84d5d5b4bfcea1896acc4ed2ca5*  
*63492d05b5bd0fd132dbb92142f6c8911325899c7a1cd9a462edf720ce27d47c*  
*697266cac58ba555fb3d7dd6e0afd08ecfc57702f3e3a9df96e9e4eef8b722d6*  
*b561b91cce444e9dc768bd93e0404e67f79900598ef03f175a10887c7b94c30c*  
*06fee4e154ad90945be70aae671aeefd103fa0947d957fdc973848221ada635c*  
*b497c79c027bab2b9a30c613b2c603296bcb29d63c8f30c27864c860955b3ebd*  
*a1dc73eaaaa11ef3585bf389fcc3301c20c0636a144778d3ffb657110d911d1b*  
*d65593e94ef433a2597cf01591e96067180e548cd418327476931c642e01bdff*  
*4ec6ee80323c2365dfd4cfeba9a64f043df026a98b026ecb1e757c9df532f064*  
*cc7c24dd062e8538984a9d640600b91ff6c3a0404a5caf4f174c513c7f16fba4*  
*5d753520b6c97bace23dbbece93ecd9eb9ac3cea1d8c9b4ccf6dfca43dc47556*  
*f51719dfeac4f52a90d52188c3b3e9145d77f612da784510c968564aa0d46e9e*  
*907d245b8854a8277379fb59d65102c2fd440c0bf850939e2a775a3bebb4cb1d*  
*0957912344ff93cba65088c4aed2bd2631e8a5788604520955104e05dcfb4b0c*  
*7cc35bbd4327a4212069eab5747944c5e8dedb82f02f695b0248d026a733f0c6*  
*56485d996b50610b3c0ab86d7136bde215401c2f30154e818b4b18d3a4457eea*  
*11cc17e5e06f7d5e7c52979b5e7b75ea083e46a59e73ea245872e72084f44099*  
*dfb355d874db6f2d141c2789a041ccfa91775508fae2fedd86c48f0089abe00a*  
*15608834007b61eb4426bf034e8923733100fccf872ffebe2e05aea3d9f63fef*  
*26f2bf1fc3ee321d48dce649fae9951220f0f640c69d5433850b469115c144fe*  
*6edf7c043348efe02d94c97a4d06ec735fb90a77ea290509e03991edadb24716*  
*4c5a0fd976f04c63faa32e1a74edd59c5c39ce0e143e69d464f95872b8357e8e*  
*59e06b077b8ac0472cb95401bf5d99301e0e807ed74d698a3953bc96c0eb568e*

**Command and Control Servers -- Original Bucbi**

*bbb.bth.in\[.\]ua*  
*shalunishka12\[.\]org*  
*ceckiforeftukreksyxomoa\[.\]org*  
*87.249.215\[.\]196*  
*chultolsylrytseewooketh\[.\]biz*

**Attacker IP Addresses**

*31.184.197.69*  
*31.44.191.251*  
*79.117.151.236*  
*46.161.40.11*  
*191.101.31.126*  
Back to top

### Tags

* [Bucbi](https://unit42.paloaltonetworks.com/tag/bucbi/ "Bucbi")
* [RDP](https://unit42.paloaltonetworks.com/tag/rdp/ "RDP")  
  [Threat Research Center](https://unit42.paloaltonetworks.com "Threat Research") [Next: AutoFocus Lenz: Taking the Blue (Team) Pill](https://unit42.paloaltonetworks.com/unit42-autofocus-lenz-taking-the-blue-team-pill/ "AutoFocus Lenz: Taking the Blue (Team) Pill")

### Related Articles

* [How We Added WebAuthn to a Browser-Based RDP Client](https://unit42.paloaltonetworks.com/webauthn-added-to-browser-based-rdp/ "article - table of contents")
* [Wireshark Tutorial: Decrypting RDP Traffic](https://unit42.paloaltonetworks.com/wireshark-tutorial-decrypting-rdp-traffic/ "article - table of contents")
* [Exploitation of Windows RDP Vulnerability CVE-2019-0708 (BlueKeep): Get RCE with System Privilege Using Refresh Rect PDU and RDPDR Client Name Request PDU](https://unit42.paloaltonetworks.com/cve-2019-0708-bluekeep/ "article - table of contents")

## Related Resources

![Pictorial representation of a magnifying glass illuminating a glowing orange circular digital circuit interface on a dark, high-tech background.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/09/04_Myth-Busting_Overview_1920x900-786x368.jpg)  
[![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/08/Insights-icon-white.svg)Insights](https://unit42.paloaltonetworks.com/category/insights/) September 16, 2026 [#### Atomic macOS (AMOS) Stealer Activity](https://unit42.paloaltonetworks.com/atomic-macos-amos-stealer-activity/)

* [MacOS](https://unit42.paloaltonetworks.com/tag/macos/ "macOS")

* [Threat intelligence](https://unit42.paloaltonetworks.com/tag/threat-intelligence/ "threat intelligence")

* [Unit 42](https://unit42.paloaltonetworks.com/tag/unit-42/ "Unit 42")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/atomic-macos-amos-stealer-activity/ "Atomic macOS (AMOS) Stealer Activity")  
  ![Pictorial representation of post-exploitation identity misuse in SPIFFE/SPIRE. Close-up of a person wearing glasses, with computer code reflected in the lenses.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/09/12_Security-Technology_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) September 10, 2026 [#### The Machine With Many Faces: Post-Exploitation Identity Misuse in SPIFFE/SPIRE](https://unit42.paloaltonetworks.com/kubernetes-spiffe-spire-identity-spoofing/)

* [API](https://unit42.paloaltonetworks.com/tag/api/ "API")

* [Cryptographic](https://unit42.paloaltonetworks.com/tag/cryptographic/ "cryptographic")

* [JSON](https://unit42.paloaltonetworks.com/tag/json/ "JSON")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/kubernetes-spiffe-spire-identity-spoofing/ "The Machine With Many Faces: Post-Exploitation Identity Misuse in SPIFFE/SPIRE")  
  ![Pictorial representation of a pay-per-install threat group campaign prodiving infection service for spreading malware. A close-up of a computer circuit board with a central microchip is depicted. Red digital data streams in the form of glowing binary numbers and arrows appear to flow in and out of the chip, symbolizing data processing and transfer. The scene is illuminated with a futuristic blue and red glow.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/09/04_Malware_Category_1920x900-6-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) September 9, 2026 [#### Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure](https://unit42.paloaltonetworks.com/ppi-network-malware-campaign-analysis/)

* [ARKTunnel](https://unit42.paloaltonetworks.com/tag/arktunnel/ "ARKTunnel")

* [C2](https://unit42.paloaltonetworks.com/tag/c2/ "C2")

* [CL-CRI-1171](https://unit42.paloaltonetworks.com/tag/cl-cri-1171/ "CL-CRI-1171")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ppi-network-malware-campaign-analysis/ "Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure")  
  ![Pictorial representation of attackers using AI tools to target Latin American organizations. A vibrant cityscape with silhouettes of numerous people walking along a bustling street. The scene is illuminated by bright urban lights and digital-like particles, creating a dynamic and futuristic atmosphere.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/09/AdobeStock_768915868-2-1-786x373.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) September 3, 2026 [#### Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America](https://unit42.paloaltonetworks.com/ai-tool-use-targeting-latam-orgs/)

* [Agentic AI](https://unit42.paloaltonetworks.com/tag/agentic-ai/ "Agentic AI")

* [ChatGPT](https://unit42.paloaltonetworks.com/tag/chatgpt/ "ChatGPT")

* [CL-CRI-1131](https://unit42.paloaltonetworks.com/tag/cl-cri-1131/ "CL-CRI-1131")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ai-tool-use-targeting-latam-orgs/ "Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America")  
  ![Pictorial representation of vishing campaigns in Microsoft Teams. A digital image of a skull formed by blue binary code on a black background, with scattered ones and zeros and digital noise, symbolizes how stealthy prompt injection attacks can exploit AI logic to bypass security controls.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/01_Malware_Category_1920x900-5-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 31, 2026 [#### Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams](https://unit42.paloaltonetworks.com/spring-ring-voice-phishing-campaigns/)

* [Cloaked Ursa](https://unit42.paloaltonetworks.com/tag/cloaked-ursa/ "Cloaked Ursa")

* [Entra ID](https://unit42.paloaltonetworks.com/tag/entra-id/ "Entra ID")

* [Microsoft Teams](https://unit42.paloaltonetworks.com/tag/microsoft-teams/ "Microsoft Teams")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/spring-ring-voice-phishing-campaigns/ "Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams")  
  ![Pictorial representation of AI-enabled malware. A vibrant digital interface displaying various icons and graphs, resembling a futuristic network or data analysis dashboard. The scene is illuminated with glowing lights and patterns.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/AdobeStock_1270203474-2-1-786x368.png)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 25, 2026 [#### The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution](https://unit42.paloaltonetworks.com/ai-enabled-malware-analysis/)

* [Backdoor](https://unit42.paloaltonetworks.com/tag/backdoor/ "backdoor")

* [Bitcoin](https://unit42.paloaltonetworks.com/tag/bitcoin/ "Bitcoin")

* [DLL hijacking](https://unit42.paloaltonetworks.com/tag/dll-hijacking/ "DLL hijacking")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ai-enabled-malware-analysis/ "The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution")  
  ![Pictorial representation of identity abuse through trusted communication channels. Close-up view of a digital screen displaying a glitched and pixelated image of a skull-like shape.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/02_Malware_Category_1920x900-2-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 20, 2026 [#### Identity Abuse Through Trusted Communication Channels](https://unit42.paloaltonetworks.com/communication-channel-identity-risks/)

* [Authentication](https://unit42.paloaltonetworks.com/tag/authentication/ "authentication")

* [Identity theft](https://unit42.paloaltonetworks.com/tag/identity-theft/ "identity theft")

* [Malware](https://unit42.paloaltonetworks.com/tag/malware/ "malware")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/communication-channel-identity-risks/ "Identity Abuse Through Trusted Communication Channels")  
  ![Pictorial representation of Kimwolf botnet malware family. Digital screen with a warning sign reading "Malware." The background features lines of computer code and graphics, creating a sense of cybersecurity threat.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/07_Malware_Category_1920x900-3-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 11, 2026 [#### Kimwolf v7: An Evolution of the Kimwolf Botnet](https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/)

* [Android APK](https://unit42.paloaltonetworks.com/tag/android-apk/ "Android APK")

* [Ethereum](https://unit42.paloaltonetworks.com/tag/ethereum/ "Ethereum")

* [HTTP](https://unit42.paloaltonetworks.com/tag/http/ "HTTP")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/ "Kimwolf v7: An Evolution of the Kimwolf Botnet")  
  ![Pictorial representatiom pf Aeternum's blockchain C2. A close-up of a computer circuit board with a central microchip is depicted. Red digital data streams in the form of glowing binary numbers and arrows appear to flow in and out of the chip. The scene is illuminated with a futuristic blue and red glow.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/04_Malware_Category_1920x900-4-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 10, 2026 [#### The Permanent Threat: Analyzing Aeternum's Blockchain-Based C2 Operations and Communications](https://unit42.paloaltonetworks.com/aeternum-blockchain-c2-analysis/)

* [Aeternum](https://unit42.paloaltonetworks.com/tag/aeternum/ "Aeternum")

* [Infection chain](https://unit42.paloaltonetworks.com/tag/infection-chain/ "infection chain")

* [JSON](https://unit42.paloaltonetworks.com/tag/json/ "JSON")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/aeternum-blockchain-c2-analysis/ "The Permanent Threat: Analyzing Aeternum’s Blockchain-Based C2 Operations and Communications")  
  ![Pictorial representation of ChainDrop, a self-propagating npm worm. An artistic depiction of a digital workspace featuring an open laptop with a red virus on the screen.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/03_Malware_Category_1920x900-7-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)High Profile Threats](https://unit42.paloaltonetworks.com/category/top-cyberthreats/) August 6, 2026 [#### ChainDrop: Inside a Self-Propagating npm Worm](https://unit42.paloaltonetworks.com/chaindrop-npm-worm-analysis/)

* [Blockchain](https://unit42.paloaltonetworks.com/tag/blockchain/ "blockchain")

* [ChainDrop](https://unit42.paloaltonetworks.com/tag/chaindrop/ "ChainDrop")

* [Claude code](https://unit42.paloaltonetworks.com/tag/claude-code/ "Claude code")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/chaindrop-npm-worm-analysis/ "ChainDrop: Inside a Self-Propagating npm Worm")

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)  
  ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg) ![Enlarged Image]()  
  ![Newsletter](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/unit42-footer-subscribe-desktop.png)  
  ![UNIT 42 Small Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/palo-alto-logo-small.svg) Get updates from Unit 42

## Peace of mind comes from staying ahead of threats. Subscribe today.

Your Email

Subscribe for email updates to all Unit 42 threat research.  
By submitting this form, you agree to our [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use "Terms of Use") and acknowledge our [Privacy Statement.](https://www.paloaltonetworks.com/legal-notices/privacy "Privacy Statement")

This site is protected by reCAPTCHA and the Google [Privacy Policy](https://policies.google.com/privacy) and [Terms of Service](https://policies.google.com/terms) apply.

Invalid captcha!
Subscribe ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg) ![loader](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-loader.svg)  
{#footer} Products and Services

* [AI-Powered Network Security Platform](https://www.paloaltonetworks.com/network-security)

* [Secure AI by Design](https://www.paloaltonetworks.com/ai-security)

* [Prisma AIRS](https://www.paloaltonetworks.com/ai-security/prisma-airs)

* [AI Access Security](https://www.paloaltonetworks.com/sase/ai-access-security)

* [Cloud Delivered Security Services](https://www.paloaltonetworks.com/network-security/security-subscriptions)

* [Advanced Threat Prevention](https://www.paloaltonetworks.com/network-security/advanced-threat-prevention)

* [Advanced URL Filtering](https://www.paloaltonetworks.com/network-security/advanced-url-filtering)

* [Advanced WildFire](https://www.paloaltonetworks.com/network-security/advanced-wildfire)

* [Advanced DNS Security](https://www.paloaltonetworks.com/network-security/advanced-dns-security)

* [Enterprise Data Loss Prevention](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention)

* [Enterprise IoT Security](https://www.paloaltonetworks.com/network-security/enterprise-device-security)

* [Medical IoT Security](https://www.paloaltonetworks.com/network-security/medical-device-security)

* [Industrial OT Security](https://www.paloaltonetworks.com/network-security/ot-security-solution)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security)

* [Next-Generation Firewalls](https://www.paloaltonetworks.com/network-security/next-generation-firewall)

* [Hardware Firewalls](https://www.paloaltonetworks.com/network-security/hardware-firewall-innovations)

* [Software Firewalls](https://www.paloaltonetworks.com/network-security/software-firewalls)

* [Strata Cloud Manager](https://www.paloaltonetworks.com/network-security/strata-cloud-manager)

* [SD-WAN for NGFW](https://www.paloaltonetworks.com/network-security/sd-wan-subscription)

* [PAN-OS](https://www.paloaltonetworks.com/network-security/pan-os)

* [Panorama](https://www.paloaltonetworks.com/network-security/panorama)

* [Secure Access Service Edge](https://www.paloaltonetworks.com/sase)

* [Prisma SASE](https://www.paloaltonetworks.com/sase)

* [Application Acceleration](https://www.paloaltonetworks.com/sase/app-acceleration)

* [Autonomous Digital Experience Management](https://www.paloaltonetworks.com/sase/adem)

* [Enterprise DLP](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention)

* [Prisma Access](https://www.paloaltonetworks.com/sase/access)

* [Prisma Browser](https://www.paloaltonetworks.com/sase/prisma-browser)

* [Prisma SD-WAN](https://www.paloaltonetworks.com/sase/sd-wan)

* [Remote Browser Isolation](https://www.paloaltonetworks.com/sase/remote-browser-isolation)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security)

* [AI-Driven Security Operations Platform](https://www.paloaltonetworks.com/cortex)

* [Cloud Security](https://www.paloaltonetworks.com/cortex/cloud)

* [Cortex Cloud](https://www.paloaltonetworks.com/cortex/cloud)

* [Application Security](https://www.paloaltonetworks.com/cortex/cloud/application-security)

* [Cloud Posture Security](https://www.paloaltonetworks.com/cortex/cloud/cloud-posture-security)

* [Cloud Runtime Security](https://www.paloaltonetworks.com/cortex/cloud/runtime-security)

* [Prisma Cloud](https://www.paloaltonetworks.com/prisma/cloud)

* [AI-Driven SOC](https://www.paloaltonetworks.com/cortex)

* [Cortex XSIAM](https://www.paloaltonetworks.com/cortex/cortex-xsiam)

* [Cortex XDR](https://www.paloaltonetworks.com/cortex/cortex-xdr)

* [Cortex XSOAR](https://www.paloaltonetworks.com/cortex/cortex-xsoar)

* [Cortex Xpanse](https://www.paloaltonetworks.com/cortex/cortex-xpanse)

* [Unit 42 Managed Detection \& Response](https://www.paloaltonetworks.com/content/pan/en_US/cortex/managed-detection-and-response)

* [Managed XSIAM](https://www.paloaltonetworks.com/cortex/managed-xsiam)

* [Next-Generation Identity Security](https://www.paloaltonetworks.com/idira)

* [Privileged Access Management](https://www.paloaltonetworks.com/idira/human/privileged-access-management)

* [Identity and Access Management](https://www.paloaltonetworks.com/idira/human/identity-and-access-management)

* [Endpoint Privilege Manager](https://www.paloaltonetworks.com/idira/human/endpoint-privilege-manager)

* [Identity Governance](https://www.paloaltonetworks.com/idira/human/identity-governance)

* [Workforce Password Management](https://www.paloaltonetworks.com/idira/human/workforce-password-management)

* [Agentic Identities](https://www.paloaltonetworks.com/idira/agentic)

* [Secrets Management](https://www.paloaltonetworks.com/idira/machine/secrets-management)

* [Unified Secrets Governance](https://www.paloaltonetworks.com/idira/machine/unified-secrets-governance)

* [Application Credentials Delivery](https://www.paloaltonetworks.com/idira/machine/application-credentials-delivery)

* [Vendor Privileged Access](https://www.paloaltonetworks.com/idira/human/vendor-privileged-access)

* [Threat Intel and Incident Response Services](https://www.paloaltonetworks.com/unit42)

* [Prepare for Emerging Risks](https://www.paloaltonetworks.com/unit42/frontier-ai-defense)

* [Strengthen Your Defenses](https://www.paloaltonetworks.com/unit42/strengthen-your-defenses)

* [Build Your Security Strategy](https://www.paloaltonetworks.com/unit42/build-your-security-strategy)

* [Understand the Adversary](https://www.paloaltonetworks.com/unit42/threat-intelligence)

* [Respond to a Cyber Attack](https://www.paloaltonetworks.com/unit42/respond)  
  Company

* [About Us](https://www.paloaltonetworks.com/about-us)

* [Careers](https://jobs.paloaltonetworks.com/en/)

* [Contact Us](https://www.paloaltonetworks.com/company/contact-sales)

* [Corporate Responsibility](https://www.paloaltonetworks.com/about-us/corporate-responsibility)

* [Customers](https://www.paloaltonetworks.com/customers)

* [Investor Relations](https://investors.paloaltonetworks.com/)

* [Location](https://www.paloaltonetworks.com/about-us/locations)

* [Newsroom](https://www.paloaltonetworks.com/company/newsroom)  
  Popular Links

* [Blog](https://www.paloaltonetworks.com/blog/)

* [Communities](https://www.paloaltonetworks.com/communities)

* [Content Library](https://www.paloaltonetworks.com/resources)

* [Cyberpedia](https://www.paloaltonetworks.com/cyberpedia)

* [Event Center](https://events.paloaltonetworks.com/)

* [Manage Email Preferences](https://start.paloaltonetworks.com/preference-center)

* [Products A-Z](https://www.paloaltonetworks.com/products/products-a-z)

* [Product Certifications](https://www.paloaltonetworks.com/legal-notices/trust-center/certifications)

* [Report a Vulnerability](https://www.paloaltonetworks.com/security-disclosure)

* [Sitemap](https://www.paloaltonetworks.com/sitemap)

* [Tech Docs](https://docs.paloaltonetworks.com/)

* [Unit 42](https://unit42.paloaltonetworks.com/)

* [Do Not Sell or Share My Personal Information](https://panwedd.exterro.net/portal/dsar.htm?target=panwedd)
  ![Palo Alto Networks Logo](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/pan-logo-dark.svg)

* [Privacy](https://www.paloaltonetworks.com/legal-notices/privacy)

* [Trust Center](https://www.paloaltonetworks.com/legal-notices/trust-center)

* [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use)

* [Documents](https://www.paloaltonetworks.com/legal)

Copyright © 2026 Palo Alto Networks. All Rights Reserved

* [![Youtube](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/youtube-black.svg)](https://www.youtube.com/user/paloaltonetworks)
* [![Podcast](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/icons/podcast.svg)](https://www.paloaltonetworks.com/podcasts/threat-vector)
* [![Facebook](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/facebook-black.svg)](https://www.facebook.com/PaloAltoNetworks/)
* [![LinkedIn](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/linkedin-black.svg)](https://www.linkedin.com/company/palo-alto-networks)
* [![Twitter](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/twitter-x-black.svg)](https://twitter.com/PaloAltoNtwks)
* EN  
  Select your language  
  ![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg) ![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg) ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg)

### Default Heading

Read the article ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg)  
Seekbar

![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg)  
![Volume](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-volume.svg)  
Volume
![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg)
