[![Logo](https://www.paloaltonetworks.com/wp-content/uploads/2021/07/PANW_Parent.png)](https://www.paloaltonetworks.com/)  
[![Unit42 Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/unit42-logo-white.svg)](https://unit42.paloaltonetworks.com/)  
Menu

* [Tools](https://unit42.paloaltonetworks.com/tools/)
* [ATOMs](https://unit42.paloaltonetworks.com/atoms/)
* [Security Consulting](https://www.paloaltonetworks.com/unit42)
* [About Us](https://unit42.paloaltonetworks.com/about-unit-42/)
* [**Under Attack?**](https://start.paloaltonetworks.com/contact-unit42.html)  
  English
* [English](https://unit42.paloaltonetworks.com/unit42-exploring-the-cybercrime-underground-part-2-the-forum-ecosystem/)
* [Japanese](https://unit42.paloaltonetworks.com/ja/unit42-exploring-the-cybercrime-underground-part-2-the-forum-ecosystem/)
* [Threat Research Center](https://unit42.paloaltonetworks.com "Threat Research")
* [Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/ "Threat Research")
* [Cybercrime](https://unit42.paloaltonetworks.com/category/cybercrime/ "Cybercrime")  
  [Cybercrime](https://unit42.paloaltonetworks.com/category/cybercrime/)

# Exploring the Cybercrime Underground: Part 2 -- The Forum Ecosystem

![Clock Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-clock.svg) 9 min read

* ![Profile Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-profile-grey.svg)  
  By:
  
  * [Rob Downs](https://unit42.paloaltonetworks.com/author/rob-downs/)
  * [Vicky Ray](https://unit42.paloaltonetworks.com/author/vicky-khan/)

* ![Published Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-calendar-grey.svg)  
  Published:August 29, 2016

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-category.svg)  
  Categories:
  
  * [Cybercrime](https://unit42.paloaltonetworks.com/category/cybercrime/)
  * [Malware](https://unit42.paloaltonetworks.com/category/malware/)
  * [Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/)

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-tags-grey.svg)  
  Tags:
  
  * [Actors](https://unit42.paloaltonetworks.com/tag/actors/)
  * [Cybercrime Underground](https://unit42.paloaltonetworks.com/tag/cybercrime-underground/)
  * [Forums](https://unit42.paloaltonetworks.com/tag/forums/)
  * [Services](https://unit42.paloaltonetworks.com/tag/services/)
  * [Tools](https://unit42.paloaltonetworks.com/tag/tools/)
  * [Underground](https://unit42.paloaltonetworks.com/tag/underground/)

* [![Download Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-download.svg)](https://unit42.paloaltonetworks.com/unit42-exploring-the-cybercrime-underground-part-2-the-forum-ecosystem/?pdf=download&lg=en&_wpnonce=7faf0ddf08 "Click here to download")

* [![Print Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-print.svg)](https://unit42.paloaltonetworks.com/unit42-exploring-the-cybercrime-underground-part-2-the-forum-ecosystem/?pdf=print&lg=en&_wpnonce=7faf0ddf08 "Click here to print")

Share![Down arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/down-arrow.svg)

* ![Link Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-share-link.svg)
* [![Link Email](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-sms.svg)](mailto:?subject=Exploring%20the%20Cybercrime%20Underground:%20Part%202%20–%20The%20Forum%20Ecosystem&body=Check%20out%20this%20article%20https%3A%2F%2Funit42.paloaltonetworks.com%2Funit42-exploring-the-cybercrime-underground-part-2-the-forum-ecosystem%2F "Share in email")
* [![Facebook Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-fb-share.svg)](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Funit42.paloaltonetworks.com%2Funit42-exploring-the-cybercrime-underground-part-2-the-forum-ecosystem%2F "Share in Facebook")
* [![LinkedIn Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-linkedin-share.svg)](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Funit42-exploring-the-cybercrime-underground-part-2-the-forum-ecosystem%2F&title=Exploring%20the%20Cybercrime%20Underground:%20Part%202%20–%20The%20Forum%20Ecosystem "Share in LinkedIn")
* [![Twitter Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-twitter-share.svg)](https://twitter.com/intent/tweet?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Funit42-exploring-the-cybercrime-underground-part-2-the-forum-ecosystem%2F&text=Exploring%20the%20Cybercrime%20Underground:%20Part%202%20–%20The%20Forum%20Ecosystem "Share in Twitter")
* [![Reddit Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-reddit-share.svg)](https://www.paloaltonetworks.com//www.reddit.com/submit?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Funit42-exploring-the-cybercrime-underground-part-2-the-forum-ecosystem%2F&ts=markdown "Share in Reddit")
* [![Mastodon Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-mastodon-share.svg)](https://mastodon.social/share?text=Exploring%20the%20Cybercrime%20Underground:%20Part%202%20–%20The%20Forum%20Ecosystem%20https%3A%2F%2Funit42.paloaltonetworks.com%2Funit42-exploring-the-cybercrime-underground-part-2-the-forum-ecosystem%2F "Share in Mastodon")
  In this second part of [Unit 42's Cybercrime Underground blog series](https://blog.paloaltonetworks.com/tag/underground/), we dive into the cybercrime forum ecosystem and focus on observed cybercriminal roles, as well as prevalent tools and services bought and sold in the underground. The goal of this post is not to provide an exhaustive directory, but rather to provide additional context on the operations and highly prevalent threats observed within this ecosystem.

### Typical Forum Actor Roles

The cybercrime underground market comprises several important actor roles overall efficient and effective forum operation. The following sections highlight typical key forum roles.

#### Malware / Exploit Developer

These individuals are the developers of the malicious tools and exploits used to perform cybercriminal activities. Developed tools include Remote Access Trojans / Remote Administration Tools (RATs), Exploit Kits (EKs), Crypters, Keyloggers, and Information Stealers (InfoStealers). Higher-end developers are technically proficient individuals who use their knowledge and skills to create software tools and exploits capable of reliably bypassing common security controls to accomplish attacker objectives.

Though the developers are the brains behind associated products, they don't typically use them to directly target victims. Instead, they sell these offerings in the underground forums for profit. Most developers market their offering with the disclaimer that the product is strictly for educational purposes and should not be used for any illegal activities. This language is typical of malware authors who seek to distance themselves from the likely (and often purpose-built) illegal use of their developed software.

#### Back Office Support: Marketing

Tools sold in the underground forums are increasingly advertised through attractive, professional-looking marketing layouts. Such advertisement incorporates elements such as features and capabilities of the respective tool or service. The designs and layouts are often created by graphic arts and design specialists who themselves competitively advertise their services on forums. This works out well for the tool developers, as they don't have to spend time on creating marketing materials; instead, developers outsource this work to these specialists. Having an attractive layout for the tools and services sold in the underground has become essential to attract buyers. Similar to a traditional business advertisement / marketing strategy, solid design and branding influence sales numbers.

#### Back Office Support: Malicious Training Provider

These individuals provide training services, including aspects such as attack techniques, malware infection and spreading methods, and hosting and managing botnet infrastructure. These offerings include well documented, easy to understand, and step-by-step procedures for anyone seeking to learn more about the tips and tricks of successful cybercrime operations.

#### Back Office Support: Resource-Based Services Provider

This category of malicious actor offers different types of services, such as Bullet Proof Hosting Service (BPHS), Distributed Denial of Service (DDoS), and others. Such offerings are leased at pre-arranged rates, often with guarantees on availability and performance.

#### Attack Operator: The Cybercriminal

These individuals typically buy the tools, exploits, and services advertised in underground forums. They use these purchases to compromise and steal data from targeted victims and organizations. The technical skillset and expertise of this group can vary greatly, ranging from actors who are experienced cybercriminals to those who are just starting their cybercrime careers.

[![Picture1](http://blog.paloaltonetworks.com/wp-content/uploads/2016/08/Picture1-500x580.png)](https://blog.paloaltonetworks.com/wp-content/uploads/2016/08/Picture1.png)

*Figure 1: Typical actor roles found in cybercrime underground forums.*

### Tools

Some of the most common tools which are being sold in the underground forums are RATs, Crypters, and Infostealers. Some of these tools are sold as malware creation kits, allowing for flexible incorporation of features into discrete builds for deployment, including both security control evasion and operational capabilities. The following sections describe some of the more prominent tools observed in the cybercrime ecosystem.

#### RATs

Remote Administration Tools, or alternatively Remote Access Trojans, enable a malicious actor to assume control over a victim's computer. Modern-day RATs are a reliable and versatile class of tool used by actors across a number of motivations.

#### LuminosityLink

At just $40 USD, LuminosityLink is a full featured RAT with keylogging capability that injects its code into almost every running process on a target computer. This malware can also download additional payloads, increasing its flexibility in use by attack operators. Unit 42 previously reported on [configuration extraction](https://blog.paloaltonetworks.com/2016/07/unit42-investigating-the-luminositylink-remote-access-trojan-configuration/) for this family of malware in July 2016. LuminosityLink's author openly advertises and sells this malware through a commercial website on the indexed web, under the guise of an administrative utility; however, it has gained in popularity across a number of malicious actors.

[![Picture2](http://blog.paloaltonetworks.com/wp-content/uploads/2016/08/Picture2-500x285.png)](https://blog.paloaltonetworks.com/wp-content/uploads/2016/08/Picture2.png)

*Figure 2: LuminosityLink website*

#### Ozone

Ozone RAT is a commercially-available tool, popular for its feature-rich capabilities, ease-of-use, and low cost. It is available from a website on the indexed web at $20 USD for a "Standard Package" and $50 USD for a "Platinum Package".

[![Picture3](http://blog.paloaltonetworks.com/wp-content/uploads/2016/08/Picture3-500x329.png)](https://blog.paloaltonetworks.com/wp-content/uploads/2016/08/Picture3.png)

*Figure 3: Ozone remote control program website*

#### Netwire

Netwire is commercially available and used by a wide range of malicious actors to remotely take control of a compromised victim system. Its website offers a trial version for free, as well as support / update versions: Lite ($50 USD semi-annually), Basic ($90 USD annually), and Pro ($160 USD biennially). Unit 42 first highlighted this threat's use by a malicious actor in our [419 Evolution Report](https://connect.paloaltonetworks.com/adversary-report).

[![Picture4](http://blog.paloaltonetworks.com/wp-content/uploads/2016/08/Picture4-500x291.png)](https://blog.paloaltonetworks.com/wp-content/uploads/2016/08/Picture4.png)

*Figure 4: Netwire plans and pricing*

#### Orcus

Orcus is a new RAT that has been on the market since April 2016. This RAT costs $40 USD, comparably priced in the range of many other popular RATs. However, this RAT provides some distinguishing features, such as plugin support and development with well documented guides. This allows buyers with knowledge of at least one supported programming language (e.g., Visual Basic .NET, Visual C# or C++), to extend Orcus features. We anticipate a number of threat actors will integrate this RAT into their toolset, given its rich feature set and flexibility. Unit 42 recently [reported](https://blog.paloaltonetworks.com/2016/08/unit42-orcus-birth-of-an-unusual-plugin-builder-rat/) on the capabilities and the impact observed from this malware family.

[![Picture5](http://blog.paloaltonetworks.com/wp-content/uploads/2016/08/Picture5-500x338.png)](https://blog.paloaltonetworks.com/wp-content/uploads/2016/08/Picture5.png)

*Figure 5: Orcus website*

### InfoStealers

InfoStealers are a sub-class of surveillance malware that capture elements such as keystrokes, screen state, and files or data stores of interest from a victim's computer to then send to an attacker. This class of malware offers both immediate benefits for an attack and can also serve as input for integrated, progressive adversary operations.

#### Keybase

[Keybase](https://blog.paloaltonetworks.com/2015/06/keybase-keylogger-malware-family-exposed/) is a family of keylogger malware that Unit 42 has been tracking since June 2015, at which time it was sold for $50 USD directly from the author's commercial website. We also followed up with a blog on its increased malicious actor usage in February 2016, despite its initial author shutting down the corresponding commercial website and discontinuing development. As it turned out, the source code for this malware's builder was leaked around that time, making this malware family accessible and customizable to a number of malicious actors who possess or can afford requisite technical proficiency.

#### Predator Pain / HawkEye

Both Predator Pain and its derivative, HawkEye, are primarily considered keyloggers, but they also include additional features, such as web browser and e-mail client credential dumping, display capture, and captured information exfiltration. Both are usually acquired through underground forums, although HawkEye was formerly offered for some time through a commercial website on the indexed web. Unit 42 previously [described active](https://blog.paloaltonetworks.com/2015/10/surveillance-malware-trends-tracking-predator-pain-and-hawkeye/) use of this tool set by a cybercrime actor in 2014, as well as observed trends in October 2015.

#### iSpy

This off-the-shelf keylogger is marketed to unsophisticated actors, with both a low technical proficiency required of its user and price point. Marketed as a way to monitor family members and employees, this infostealer is fully functional "out-of-box" for approximately $20 USD.

### Crypters

Crypters play an important role in the overall malware creation cycle. They enable cybercriminals to create malware that can bypass legacy security solutions without raising any alarms. As discussed in a [prior Unit 42 blog](https://blog.paloaltonetworks.com/2015/02/examining-cybercrime-underground-part-1-crypters/), crypters are software that use a combination of obfuscation, encryption, and code manipulation to make malware FUD (Fully Undetectable). After malware binaries are created, they can then be passed through a crypter to increase their likelihood of successfully bypassing security measures protecting their target.

[![Picture6](http://blog.paloaltonetworks.com/wp-content/uploads/2016/08/Picture6-500x156.png)](https://blog.paloaltonetworks.com/wp-content/uploads/2016/08/Picture6.png)

*Figure 6: Applying a crypter to malware*

#### Kazy Crypter

Kazy Crypter has been sold in the underground market since 2014, with version 5 currently available. The cost of this crypter can range from $13 USD for 30 days to $35 USD for a 180-day package. This tool provides various evasion techniques and advertises that it is fully compatible and tested with most well-known RATs, such as LuminosityLink, NanoCore, and many others.

[![Picture7](http://blog.paloaltonetworks.com/wp-content/uploads/2016/08/Picture7-500x305.png)](https://blog.paloaltonetworks.com/wp-content/uploads/2016/08/Picture7.png)

*Figure 7: Kazy Crypter features*

#### Ghost Crypter

Another widely adopted crypter on the market is Ghost Crypter, which is distributed without any dependencies. This is uncommon with such tools; for comparison, Kazy Crypter has a dependency on .NET 2.0, without which the files will fail to execute. As shown in the image below, this crypter is available through three package offerings: 1 month at $12 USD, 3 months at $25 USD, and a lifetime access for $50 USD, respectively.

[![Picture8](http://blog.paloaltonetworks.com/wp-content/uploads/2016/08/Picture8-500x540.png)](https://blog.paloaltonetworks.com/wp-content/uploads/2016/08/Picture8.png)

*Figure 8: Ghost Crypter packages*

### Services

The cyber underground marketplace not only provides buying and selling of tools, but also services that range across malware spreading, hacking / exploitation, DDoS/ Stress testing, marketing / graphics design, hosting, currency exchange, and much more. We will discuss some of the prevalent services advertised explicitly or implicitly through forums, which are commonly used by cybercriminals to achieve their malicious objectives.

#### Malware Spreading Services

Malware Spreading services provide step-by-step tutorials to conduct malicious campaigns. They typically provide guides and procedures to conduct campaigns to exploit, infect computer systems with malware, exfiltrate information using various tools, techniques and procedures.

#### Instantlyspreading

"Instantlyspreading" is one such malware spreading services, which is being sold in the underground market with three different pricing plans as shown in Figure 9 below.

[![Picture9](http://blog.paloaltonetworks.com/wp-content/uploads/2016/08/Picture9-500x507.png)](https://blog.paloaltonetworks.com/wp-content/uploads/2016/08/Picture9.png)

*Figure 9: Instantlyspreading service plans*

### Bullet Proof Hosting Service Providers

Bullet Proof Hosting Service (BPHS) service providers enable cyber criminals to host malicious contents without the risk of being taken down. There are several BPHS providers that offer services under the banner of legitimate business services. However, there are also some BPHS providers that openly advertise their services to malicious actors, highlighting their lack of enforcement on most types of content hosted on their servers and dedicated packages for hosting different kinds of malicious hosting services.

One example of this latter class of BPHS provider is 'hostmy.su', a popular choice amongst malicious actors that uses a custom made Fast Flux system to ensure high availability. The cost of their services can start from $39.99 USD to $700 USD per month for dedicated pre-configured packages.

[![Picture10](http://blog.paloaltonetworks.com/wp-content/uploads/2016/08/Picture10-500x462.png)](https://blog.paloaltonetworks.com/wp-content/uploads/2016/08/Picture10.png)

*Figure 10: 'Host.my' website selling BPHS*

### DDoS Services

Distributed Denial of Service (DDoS), also known as Booter or Stress Testing services, are online resources primarily used to test the resilience of websites. Malicious actors use these services to bring down websites and individual online Internet users. Typically, these services provide Layer - 4 (transport) and Layer -7 (application) volumetric attacks that consume the resources of the target and make it unresponsive to legitimate requests, ultimately bringing the service down. Though these DDoS services may not impact large and / or well-funded enterprises that employ DDoS prevention technologies, they can be very effective when used against medium size enterprises. These services usually cost between $10 USD to $200 USD per month, depending on the level of package bought.

[![Picture11](http://blog.paloaltonetworks.com/wp-content/uploads/2016/08/Picture11-500x203.png)](https://blog.paloaltonetworks.com/wp-content/uploads/2016/08/Picture11.png)

*Figure 11: Sample advertisement for a DDoS service*

### Marketing Services

Marketing services such as graphic design, brand management, and advertisements play a part in communicating the professionalism and longevity of associated cybercrime underground offerings. These efforts strive to recreate a community perception and "feel" for products and services that rivals the planning and quality of those achieved by conventional businesses for corresponding real world public consumers.

[![Picture 12](http://blog.paloaltonetworks.com/wp-content/uploads/2016/08/Picture-12-500x661.png)](https://blog.paloaltonetworks.com/wp-content/uploads/2016/08/Picture-12.png)

*Figure 12: Sample advertisement for malware marketing*

### Payment Services

Methods for processing underground marketplace payments vary based on factors such as the plausible legality of offerings and the segment of the cybercrime underground through which that offering is available (e.g., Indexed Web versus Dark Web).

#### BitCoin

BitCoin (BTC) is the premier cryptocurrency of the day. BTC is used for lawful financial transactions every day; however, it is also preferred by most malicious actors due to its built-in model of anonymity. This reduces the likelihood of payments being tracked to or from associated parties. This anonymity extends to funds pilfered through digital heists of BitCoin wallets either using BTC-targeting malware or direct actor activity, which can further conflate the exercise of determining at which point transactions are applied towards illegal endeavors.

#### Conventional Payment Cards

Some tools and services may be purchased using conventional payment cards and methods, such as commercial bank and credit card company accounts, or generally legitimate intermediary broker services such as those available through PayPal. This happens at at least in part to support the argument that there are legal or educational uses for those offerings, and therefore associated purchases should not be perceived as illegal. On the other hand, cybercriminals of sufficient means can just as easily use stolen payment card information for such purchases, whether stolen directly or obtained through bundles of such information available on carder forums.

### Core Takeaways: Underground Forums

Tools and services used by malicious actors are constantly developed and sold in the cybercrime underground (some of which have been discussed in this post). These ever-evolving offerings pose a significant threat to organizations and individuals alike. The ease of availability, simplicity of usage, and low cost of these tools and services allow cybercrime to grow and thrive in this digital world Awareness and deeper understanding of these tools, services, and how individuals within the cybercrime underground ecosystem collaborate and operate to enable financial gains are essential inputs into defending both organizations and individuals and preventing threats.

### Coming Up...

The next installment in this blog series will focus on the impacts observed from some of the type of tools discussed so far.
Back to top

### Tags

* [Actors](https://unit42.paloaltonetworks.com/tag/actors/ "actors")
* [Cybercrime Underground](https://unit42.paloaltonetworks.com/tag/cybercrime-underground/ "Cybercrime Underground")
* [Forums](https://unit42.paloaltonetworks.com/tag/forums/ "forums")
* [Services](https://unit42.paloaltonetworks.com/tag/services/ "services")
* [Tools](https://unit42.paloaltonetworks.com/tag/tools/ "tools")
* [Underground](https://unit42.paloaltonetworks.com/tag/underground/ "underground")  
  [Threat Research Center](https://unit42.paloaltonetworks.com "Threat Research") [Next: LabyREnth Capture the Flag (CTF): Unix Track Solutions](https://unit42.paloaltonetworks.com/labyrenth-capture-the-flag-ctf-unix-track-solutions/ "LabyREnth Capture the Flag (CTF): Unix Track Solutions")

### Related Articles

* [01flip: Multi-Platform Ransomware Written in Rust](https://unit42.paloaltonetworks.com/new-ransomware-01flip-written-in-rust/ "article - table of contents")
* [Unveiling 11 New Adversary Playbooks](https://unit42.paloaltonetworks.com/unveiling-11-new-adversary-playbooks/ "article - table of contents")
* [Introducing the Adversary Playbook: First up, OilRig](https://unit42.paloaltonetworks.com/unit42-introducing-the-adversary-playbook-first-up-oilrig/ "article - table of contents")

## Related Resources

![Pictorial representation of a magnifying glass illuminating a glowing orange circular digital circuit interface on a dark, high-tech background.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/09/04_Myth-Busting_Overview_1920x900-786x368.jpg)  
[![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/08/Insights-icon-white.svg)Insights](https://unit42.paloaltonetworks.com/category/insights/) September 16, 2026 [#### Atomic macOS (AMOS) Stealer Activity](https://unit42.paloaltonetworks.com/atomic-macos-amos-stealer-activity/)

* [MacOS](https://unit42.paloaltonetworks.com/tag/macos/ "macOS")

* [Threat intelligence](https://unit42.paloaltonetworks.com/tag/threat-intelligence/ "threat intelligence")

* [Unit 42](https://unit42.paloaltonetworks.com/tag/unit-42/ "Unit 42")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/atomic-macos-amos-stealer-activity/ "Atomic macOS (AMOS) Stealer Activity")  
  ![Pictorial representation of post-exploitation identity misuse in SPIFFE/SPIRE. Close-up of a person wearing glasses, with computer code reflected in the lenses.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/09/12_Security-Technology_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) September 10, 2026 [#### The Machine With Many Faces: Post-Exploitation Identity Misuse in SPIFFE/SPIRE](https://unit42.paloaltonetworks.com/kubernetes-spiffe-spire-identity-spoofing/)

* [API](https://unit42.paloaltonetworks.com/tag/api/ "API")

* [Cryptographic](https://unit42.paloaltonetworks.com/tag/cryptographic/ "cryptographic")

* [JSON](https://unit42.paloaltonetworks.com/tag/json/ "JSON")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/kubernetes-spiffe-spire-identity-spoofing/ "The Machine With Many Faces: Post-Exploitation Identity Misuse in SPIFFE/SPIRE")  
  ![Pictorial representation of a pay-per-install threat group campaign prodiving infection service for spreading malware. A close-up of a computer circuit board with a central microchip is depicted. Red digital data streams in the form of glowing binary numbers and arrows appear to flow in and out of the chip, symbolizing data processing and transfer. The scene is illuminated with a futuristic blue and red glow.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/09/04_Malware_Category_1920x900-6-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) September 9, 2026 [#### Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure](https://unit42.paloaltonetworks.com/ppi-network-malware-campaign-analysis/)

* [ARKTunnel](https://unit42.paloaltonetworks.com/tag/arktunnel/ "ARKTunnel")

* [C2](https://unit42.paloaltonetworks.com/tag/c2/ "C2")

* [CL-CRI-1171](https://unit42.paloaltonetworks.com/tag/cl-cri-1171/ "CL-CRI-1171")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ppi-network-malware-campaign-analysis/ "Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure")  
  ![Pictorial representation of attackers using AI tools to target Latin American organizations. A vibrant cityscape with silhouettes of numerous people walking along a bustling street. The scene is illuminated by bright urban lights and digital-like particles, creating a dynamic and futuristic atmosphere.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/09/AdobeStock_768915868-2-1-786x373.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) September 3, 2026 [#### Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America](https://unit42.paloaltonetworks.com/ai-tool-use-targeting-latam-orgs/)

* [Agentic AI](https://unit42.paloaltonetworks.com/tag/agentic-ai/ "Agentic AI")

* [ChatGPT](https://unit42.paloaltonetworks.com/tag/chatgpt/ "ChatGPT")

* [CL-CRI-1131](https://unit42.paloaltonetworks.com/tag/cl-cri-1131/ "CL-CRI-1131")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ai-tool-use-targeting-latam-orgs/ "Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America")  
  ![Pictorial representation of vishing campaigns in Microsoft Teams. A digital image of a skull formed by blue binary code on a black background, with scattered ones and zeros and digital noise, symbolizes how stealthy prompt injection attacks can exploit AI logic to bypass security controls.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/01_Malware_Category_1920x900-5-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 31, 2026 [#### Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams](https://unit42.paloaltonetworks.com/spring-ring-voice-phishing-campaigns/)

* [Cloaked Ursa](https://unit42.paloaltonetworks.com/tag/cloaked-ursa/ "Cloaked Ursa")

* [Entra ID](https://unit42.paloaltonetworks.com/tag/entra-id/ "Entra ID")

* [Microsoft Teams](https://unit42.paloaltonetworks.com/tag/microsoft-teams/ "Microsoft Teams")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/spring-ring-voice-phishing-campaigns/ "Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams")  
  ![Pictorial representation of AI-enabled malware. A vibrant digital interface displaying various icons and graphs, resembling a futuristic network or data analysis dashboard. The scene is illuminated with glowing lights and patterns.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/AdobeStock_1270203474-2-1-786x368.png)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 25, 2026 [#### The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution](https://unit42.paloaltonetworks.com/ai-enabled-malware-analysis/)

* [Backdoor](https://unit42.paloaltonetworks.com/tag/backdoor/ "backdoor")

* [Bitcoin](https://unit42.paloaltonetworks.com/tag/bitcoin/ "Bitcoin")

* [DLL hijacking](https://unit42.paloaltonetworks.com/tag/dll-hijacking/ "DLL hijacking")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ai-enabled-malware-analysis/ "The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution")  
  ![Pictorial representation of identity abuse through trusted communication channels. Close-up view of a digital screen displaying a glitched and pixelated image of a skull-like shape.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/02_Malware_Category_1920x900-2-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 20, 2026 [#### Identity Abuse Through Trusted Communication Channels](https://unit42.paloaltonetworks.com/communication-channel-identity-risks/)

* [Authentication](https://unit42.paloaltonetworks.com/tag/authentication/ "authentication")

* [Identity theft](https://unit42.paloaltonetworks.com/tag/identity-theft/ "identity theft")

* [Malware](https://unit42.paloaltonetworks.com/tag/malware/ "malware")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/communication-channel-identity-risks/ "Identity Abuse Through Trusted Communication Channels")  
  ![Pictorial representation of Kimwolf botnet malware family. Digital screen with a warning sign reading "Malware." The background features lines of computer code and graphics, creating a sense of cybersecurity threat.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/07_Malware_Category_1920x900-3-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 11, 2026 [#### Kimwolf v7: An Evolution of the Kimwolf Botnet](https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/)

* [Android APK](https://unit42.paloaltonetworks.com/tag/android-apk/ "Android APK")

* [Ethereum](https://unit42.paloaltonetworks.com/tag/ethereum/ "Ethereum")

* [HTTP](https://unit42.paloaltonetworks.com/tag/http/ "HTTP")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/ "Kimwolf v7: An Evolution of the Kimwolf Botnet")  
  ![Pictorial representatiom pf Aeternum's blockchain C2. A close-up of a computer circuit board with a central microchip is depicted. Red digital data streams in the form of glowing binary numbers and arrows appear to flow in and out of the chip. The scene is illuminated with a futuristic blue and red glow.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/04_Malware_Category_1920x900-4-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 10, 2026 [#### The Permanent Threat: Analyzing Aeternum's Blockchain-Based C2 Operations and Communications](https://unit42.paloaltonetworks.com/aeternum-blockchain-c2-analysis/)

* [Aeternum](https://unit42.paloaltonetworks.com/tag/aeternum/ "Aeternum")

* [Infection chain](https://unit42.paloaltonetworks.com/tag/infection-chain/ "infection chain")

* [JSON](https://unit42.paloaltonetworks.com/tag/json/ "JSON")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/aeternum-blockchain-c2-analysis/ "The Permanent Threat: Analyzing Aeternum’s Blockchain-Based C2 Operations and Communications")  
  ![Pictorial representation of ChainDrop, a self-propagating npm worm. An artistic depiction of a digital workspace featuring an open laptop with a red virus on the screen.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/03_Malware_Category_1920x900-7-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)High Profile Threats](https://unit42.paloaltonetworks.com/category/top-cyberthreats/) August 6, 2026 [#### ChainDrop: Inside a Self-Propagating npm Worm](https://unit42.paloaltonetworks.com/chaindrop-npm-worm-analysis/)

* [Blockchain](https://unit42.paloaltonetworks.com/tag/blockchain/ "blockchain")

* [ChainDrop](https://unit42.paloaltonetworks.com/tag/chaindrop/ "ChainDrop")

* [Claude code](https://unit42.paloaltonetworks.com/tag/claude-code/ "Claude code")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/chaindrop-npm-worm-analysis/ "ChainDrop: Inside a Self-Propagating npm Worm")

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)  
  ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg) ![Enlarged Image]()  
  ![Newsletter](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/unit42-footer-subscribe-desktop.png)  
  ![UNIT 42 Small Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/palo-alto-logo-small.svg) Get updates from Unit 42

## Peace of mind comes from staying ahead of threats. Subscribe today.

Your Email

Subscribe for email updates to all Unit 42 threat research.  
By submitting this form, you agree to our [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use "Terms of Use") and acknowledge our [Privacy Statement.](https://www.paloaltonetworks.com/legal-notices/privacy "Privacy Statement")

This site is protected by reCAPTCHA and the Google [Privacy Policy](https://policies.google.com/privacy) and [Terms of Service](https://policies.google.com/terms) apply.

Invalid captcha!
Subscribe ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg) ![loader](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-loader.svg)  
{#footer} Products and Services

* [AI-Powered Network Security Platform](https://www.paloaltonetworks.com/network-security)

* [Secure AI by Design](https://www.paloaltonetworks.com/ai-security)

* [Prisma AIRS](https://www.paloaltonetworks.com/ai-security/prisma-airs)

* [AI Access Security](https://www.paloaltonetworks.com/sase/ai-access-security)

* [Cloud Delivered Security Services](https://www.paloaltonetworks.com/network-security/security-subscriptions)

* [Advanced Threat Prevention](https://www.paloaltonetworks.com/network-security/advanced-threat-prevention)

* [Advanced URL Filtering](https://www.paloaltonetworks.com/network-security/advanced-url-filtering)

* [Advanced WildFire](https://www.paloaltonetworks.com/network-security/advanced-wildfire)

* [Advanced DNS Security](https://www.paloaltonetworks.com/network-security/advanced-dns-security)

* [Enterprise Data Loss Prevention](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention)

* [Enterprise IoT Security](https://www.paloaltonetworks.com/network-security/enterprise-device-security)

* [Medical IoT Security](https://www.paloaltonetworks.com/network-security/medical-device-security)

* [Industrial OT Security](https://www.paloaltonetworks.com/network-security/ot-security-solution)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security)

* [Next-Generation Firewalls](https://www.paloaltonetworks.com/network-security/next-generation-firewall)

* [Hardware Firewalls](https://www.paloaltonetworks.com/network-security/hardware-firewall-innovations)

* [Software Firewalls](https://www.paloaltonetworks.com/network-security/software-firewalls)

* [Strata Cloud Manager](https://www.paloaltonetworks.com/network-security/strata-cloud-manager)

* [SD-WAN for NGFW](https://www.paloaltonetworks.com/network-security/sd-wan-subscription)

* [PAN-OS](https://www.paloaltonetworks.com/network-security/pan-os)

* [Panorama](https://www.paloaltonetworks.com/network-security/panorama)

* [Secure Access Service Edge](https://www.paloaltonetworks.com/sase)

* [Prisma SASE](https://www.paloaltonetworks.com/sase)

* [Application Acceleration](https://www.paloaltonetworks.com/sase/app-acceleration)

* [Autonomous Digital Experience Management](https://www.paloaltonetworks.com/sase/adem)

* [Enterprise DLP](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention)

* [Prisma Access](https://www.paloaltonetworks.com/sase/access)

* [Prisma Browser](https://www.paloaltonetworks.com/sase/prisma-browser)

* [Prisma SD-WAN](https://www.paloaltonetworks.com/sase/sd-wan)

* [Remote Browser Isolation](https://www.paloaltonetworks.com/sase/remote-browser-isolation)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security)

* [AI-Driven Security Operations Platform](https://www.paloaltonetworks.com/cortex)

* [Cloud Security](https://www.paloaltonetworks.com/cortex/cloud)

* [Cortex Cloud](https://www.paloaltonetworks.com/cortex/cloud)

* [Application Security](https://www.paloaltonetworks.com/cortex/cloud/application-security)

* [Cloud Posture Security](https://www.paloaltonetworks.com/cortex/cloud/cloud-posture-security)

* [Cloud Runtime Security](https://www.paloaltonetworks.com/cortex/cloud/runtime-security)

* [Prisma Cloud](https://www.paloaltonetworks.com/prisma/cloud)

* [AI-Driven SOC](https://www.paloaltonetworks.com/cortex)

* [Cortex XSIAM](https://www.paloaltonetworks.com/cortex/cortex-xsiam)

* [Cortex XDR](https://www.paloaltonetworks.com/cortex/cortex-xdr)

* [Cortex XSOAR](https://www.paloaltonetworks.com/cortex/cortex-xsoar)

* [Cortex Xpanse](https://www.paloaltonetworks.com/cortex/cortex-xpanse)

* [Unit 42 Managed Detection \& Response](https://www.paloaltonetworks.com/content/pan/en_US/cortex/managed-detection-and-response)

* [Managed XSIAM](https://www.paloaltonetworks.com/cortex/managed-xsiam)

* [Next-Generation Identity Security](https://www.paloaltonetworks.com/idira)

* [Privileged Access Management](https://www.paloaltonetworks.com/idira/human/privileged-access-management)

* [Identity and Access Management](https://www.paloaltonetworks.com/idira/human/identity-and-access-management)

* [Endpoint Privilege Manager](https://www.paloaltonetworks.com/idira/human/endpoint-privilege-manager)

* [Identity Governance](https://www.paloaltonetworks.com/idira/human/identity-governance)

* [Workforce Password Management](https://www.paloaltonetworks.com/idira/human/workforce-password-management)

* [Agentic Identities](https://www.paloaltonetworks.com/idira/agentic)

* [Secrets Management](https://www.paloaltonetworks.com/idira/machine/secrets-management)

* [Unified Secrets Governance](https://www.paloaltonetworks.com/idira/machine/unified-secrets-governance)

* [Application Credentials Delivery](https://www.paloaltonetworks.com/idira/machine/application-credentials-delivery)

* [Vendor Privileged Access](https://www.paloaltonetworks.com/idira/human/vendor-privileged-access)

* [Threat Intel and Incident Response Services](https://www.paloaltonetworks.com/unit42)

* [Prepare for Emerging Risks](https://www.paloaltonetworks.com/unit42/frontier-ai-defense)

* [Strengthen Your Defenses](https://www.paloaltonetworks.com/unit42/strengthen-your-defenses)

* [Build Your Security Strategy](https://www.paloaltonetworks.com/unit42/build-your-security-strategy)

* [Understand the Adversary](https://www.paloaltonetworks.com/unit42/threat-intelligence)

* [Respond to a Cyber Attack](https://www.paloaltonetworks.com/unit42/respond)  
  Company

* [About Us](https://www.paloaltonetworks.com/about-us)

* [Careers](https://jobs.paloaltonetworks.com/en/)

* [Contact Us](https://www.paloaltonetworks.com/company/contact-sales)

* [Corporate Responsibility](https://www.paloaltonetworks.com/about-us/corporate-responsibility)

* [Customers](https://www.paloaltonetworks.com/customers)

* [Investor Relations](https://investors.paloaltonetworks.com/)

* [Location](https://www.paloaltonetworks.com/about-us/locations)

* [Newsroom](https://www.paloaltonetworks.com/company/newsroom)  
  Popular Links

* [Blog](https://www.paloaltonetworks.com/blog/)

* [Communities](https://www.paloaltonetworks.com/communities)

* [Content Library](https://www.paloaltonetworks.com/resources)

* [Cyberpedia](https://www.paloaltonetworks.com/cyberpedia)

* [Event Center](https://events.paloaltonetworks.com/)

* [Manage Email Preferences](https://start.paloaltonetworks.com/preference-center)

* [Products A-Z](https://www.paloaltonetworks.com/products/products-a-z)

* [Product Certifications](https://www.paloaltonetworks.com/legal-notices/trust-center/certifications)

* [Report a Vulnerability](https://www.paloaltonetworks.com/security-disclosure)

* [Sitemap](https://www.paloaltonetworks.com/sitemap)

* [Tech Docs](https://docs.paloaltonetworks.com/)

* [Unit 42](https://unit42.paloaltonetworks.com/)

* [Do Not Sell or Share My Personal Information](https://panwedd.exterro.net/portal/dsar.htm?target=panwedd)
  ![Palo Alto Networks Logo](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/pan-logo-dark.svg)

* [Privacy](https://www.paloaltonetworks.com/legal-notices/privacy)

* [Trust Center](https://www.paloaltonetworks.com/legal-notices/trust-center)

* [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use)

* [Documents](https://www.paloaltonetworks.com/legal)

Copyright © 2026 Palo Alto Networks. All Rights Reserved

* [![Youtube](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/youtube-black.svg)](https://www.youtube.com/user/paloaltonetworks)
* [![Podcast](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/icons/podcast.svg)](https://www.paloaltonetworks.com/podcasts/threat-vector)
* [![Facebook](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/facebook-black.svg)](https://www.facebook.com/PaloAltoNetworks/)
* [![LinkedIn](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/linkedin-black.svg)](https://www.linkedin.com/company/palo-alto-networks)
* [![Twitter](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/twitter-x-black.svg)](https://twitter.com/PaloAltoNtwks)
* EN  
  Select your language  
  ![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg) ![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg) ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg)

### Default Heading

Read the article ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg)  
Seekbar

![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg)  
![Volume](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-volume.svg)  
Volume
![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg)
