[![Logo](https://www.paloaltonetworks.com/wp-content/uploads/2021/07/PANW_Parent.png)](https://www.paloaltonetworks.com/)  
[![Unit42 Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/unit42-logo-white.svg)](https://unit42.paloaltonetworks.com/)  
Menu

* [Tools](https://unit42.paloaltonetworks.com/tools/)
* [ATOMs](https://unit42.paloaltonetworks.com/atoms/)
* [Security Consulting](https://www.paloaltonetworks.com/unit42)
* [About Us](https://unit42.paloaltonetworks.com/about-unit-42/)
* [**Under Attack?**](https://start.paloaltonetworks.com/contact-unit42.html)
* [Threat Research Center](https://unit42.paloaltonetworks.com "Threat Research")
* [Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/ "Threat Research")
* [Ransomware](https://unit42.paloaltonetworks.com/category/ransomware/ "Ransomware")  
  [Ransomware](https://unit42.paloaltonetworks.com/category/ransomware/)

# Mole Ransomware: How One Malicious Spam Campaign Quickly Increased Complexity and Changed Tactics

![Clock Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-clock.svg) 8 min read

* ![Profile Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-profile-grey.svg)  
  By:
  
  * [Brad Duncan](https://unit42.paloaltonetworks.com/author/brad-duncan/)

* ![Published Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-calendar-grey.svg)  
  Published:April 25, 2017

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-category.svg)  
  Categories:
  
  * [Ransomware](https://unit42.paloaltonetworks.com/category/ransomware/)
  * [Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/)

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-tags-grey.svg)  
  Tags:
  
  * [Kovter](https://unit42.paloaltonetworks.com/tag/kovter/)
  * [Miuref](https://unit42.paloaltonetworks.com/tag/miuref/)
  * [Mole](https://unit42.paloaltonetworks.com/tag/mole/)
  * [Nemucod](https://unit42.paloaltonetworks.com/tag/nemucod/)
  * [Spam](https://unit42.paloaltonetworks.com/tag/spam/)
  * [USPS](https://unit42.paloaltonetworks.com/tag/usps/)

* [![Download Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-download.svg)](https://unit42.paloaltonetworks.com/unit42-mole-ransomware-one-malicious-spam-campaign-quickly-increased-complexity-changed-tactics/?pdf=download&lg=en&_wpnonce=1628116e08 "Click here to download")

* [![Print Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-print.svg)](https://unit42.paloaltonetworks.com/unit42-mole-ransomware-one-malicious-spam-campaign-quickly-increased-complexity-changed-tactics/?pdf=print&lg=en&_wpnonce=1628116e08 "Click here to print")

Share![Down arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/down-arrow.svg)

* ![Link Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-share-link.svg)
* [![Link Email](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-sms.svg)](mailto:?subject=Mole%20Ransomware:%20How%20One%20Malicious%20Spam%20Campaign%20Quickly%20Increased%20Complexity%20and%20Changed%20Tactics&body=Check%20out%20this%20article%20https%3A%2F%2Funit42.paloaltonetworks.com%2Funit42-mole-ransomware-one-malicious-spam-campaign-quickly-increased-complexity-changed-tactics%2F "Share in email")
* [![Facebook Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-fb-share.svg)](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Funit42.paloaltonetworks.com%2Funit42-mole-ransomware-one-malicious-spam-campaign-quickly-increased-complexity-changed-tactics%2F "Share in Facebook")
* [![LinkedIn Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-linkedin-share.svg)](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Funit42-mole-ransomware-one-malicious-spam-campaign-quickly-increased-complexity-changed-tactics%2F&title=Mole%20Ransomware:%20How%20One%20Malicious%20Spam%20Campaign%20Quickly%20Increased%20Complexity%20and%20Changed%20Tactics "Share in LinkedIn")
* [![Twitter Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-twitter-share.svg)](https://twitter.com/intent/tweet?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Funit42-mole-ransomware-one-malicious-spam-campaign-quickly-increased-complexity-changed-tactics%2F&text=Mole%20Ransomware:%20How%20One%20Malicious%20Spam%20Campaign%20Quickly%20Increased%20Complexity%20and%20Changed%20Tactics "Share in Twitter")
* [![Reddit Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-reddit-share.svg)](https://www.paloaltonetworks.com//www.reddit.com/submit?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Funit42-mole-ransomware-one-malicious-spam-campaign-quickly-increased-complexity-changed-tactics%2F&ts=markdown "Share in Reddit")
* [![Mastodon Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-mastodon-share.svg)](https://mastodon.social/share?text=Mole%20Ransomware:%20How%20One%20Malicious%20Spam%20Campaign%20Quickly%20Increased%20Complexity%20and%20Changed%20Tactics%20https%3A%2F%2Funit42.paloaltonetworks.com%2Funit42-mole-ransomware-one-malicious-spam-campaign-quickly-increased-complexity-changed-tactics%2F "Share in Mastodon")
  On April 11th 2017, we saw a [new malicious spam campaign](https://isc.sans.edu/forums/diary/Malspam+on+20170411+pushes+yet+another+ransomware+variant/22290/) using United States Postal Service (USPS)-themed emails with links that redirected to fake Microsoft Word online sites. These fake Word sites asked victims to install malware disguised as a Microsoft Office plugin.

This campaign introduced a new ransomware called [Mole](https://www.bleepingcomputer.com/news/security/mole-ransomware-distributed-through-fake-online-word-docs/), because names for any encrypted files by this ransomware end with ***.MOLE*** . Mole appears to be part of the [CryptoMix](https://www.webroot.com/blog/2016/07/22/about-cryptomix-ransomware/) family of ransomware since it shares many characteristics with the [Revenge](https://www.bleepingcomputer.com/news/security/revenge-ransomware-a-cryptomix-variant-being-distributed-by-rig-exploit-kit/) and [CryptoShield](https://isc.sans.edu/forums/diary/CryptoShield+Ransomware+from+Rig+EK/22047/) variants of CryptoMix.

The campaign quickly changed tactics and increased complexity.

After two days on April 13, 2017, [the attackers behind these fake office plugins changed the format](https://myonlinesecurity.co.uk/changes-to-fake-usps-delivery-messages-delivering-malware/) and began including additional malware. Along with Mole ransomware, victims would be infected with both [Kovter](https://www.microsoft.com/security/portal/threat/encyclopedia/Entry.aspx?Name=Trojan:Win32/Kovter) and [Miuref](https://www.microsoft.com/security/portal/threat/encyclopedia/Entry.aspx?Name=Win32/Miuref). Then, on the following day, April 14, 2017, the attackers stopped using a redirect link in the malicious spam and instead linked directly to a fake Word online site. Figure 1 shows the attackers' changing tactics from Tuesday April 11, 2017 through Friday April 14, 2017.

[![mole\_1](https://unit42.paloaltonetworks.com/wp-content/uploads/2017/04/Mole_1.png)](https://unit42.paloaltonetworks.com/wp-content/uploads/2017/04/Mole_1.png)

*Figure 1: Changing tactics April 11 - April 14, 2017*

### April 11th - Introducing Mole Ransomware

From Tuesday April 11th to the early hours of Wednesday April 12th, the fake Word Online used Google Docs links to provide Mole ransomware disguised as an Office plugin. Criminals behind this campaign abused Google Docs to provide a link for an executable file. File names were ***plug-in.exe*** or ***plugin.exe***. Figure 2 shows how these fake Microsoft Word Online documents would attempt to lure users into downloading the Mole ransomware.

[![mole\_2](https://unit42.paloaltonetworks.com/wp-content/uploads/2017/04/Mole_2.png)](https://unit42.paloaltonetworks.com/wp-content/uploads/2017/04/Mole_2.png)

*Figure 2: Fake Microsoft Word Online site with link to a Google Documents URL with the ransomware.*

After downloading the executable, the infection chain is straight-forward. The victim executes the ransomware and infects his or her Windows computer. The mechanics behind a Mole ransomware infection have already been covered at the [Internet Storm Center (ISC)](https://isc.sans.edu/forums/diary/Malspam+on+20170411+pushes+yet+another+ransomware+variant/22290/) and [Bleeping Computer](https://www.bleepingcomputer.com/news/security/mole-ransomware-distributed-through-fake-online-word-docs/). Figure 3 shows the April 12 Mole ransomware in action.

[![mole\_3](https://unit42.paloaltonetworks.com/wp-content/uploads/2017/04/Mole_3.png)](https://unit42.paloaltonetworks.com/wp-content/uploads/2017/04/Mole_3.png)

*Figure 3: Desktop of a Windows host infected with Mole ransomware on April 12th*

### April 13th - Introducing .js Files and Additional Malware

By Thursday April 13, 2017, this campaign changed tactics. The fake Microsoft Word Online sites no longer used a Google Docs URL to provide their malware. Instead, the malware was sent as a zip archive directly from the compromised site being used as a fake Microsoft Word Online page. The zip archives contained JavaScript (.js) files designed to infect Windows computers with Mole ransomware [and additional malware](https://myonlinesecurity.co.uk/changes-to-fake-usps-delivery-messages-delivering-malware/).

The Figures 4 and 5 below illustrate the newer format used for malware infections by this campaign, where the new file is a zip archive named ***plugin.zip*** that contains a .js-based downloader named ***plugin.js***.

[![mole\_4](https://unit42.paloaltonetworks.com/wp-content/uploads/2017/04/Mole_4.png)](https://unit42.paloaltonetworks.com/wp-content/uploads/2017/04/Mole_4.png)

*Figure 4: Fake Microsoft Word Online site later on April 13th with link to a zip archive instead of an executable*

[![mole\_5](https://unit42.paloaltonetworks.com/wp-content/uploads/2017/04/Mole_5.png)](https://unit42.paloaltonetworks.com/wp-content/uploads/2017/04/Mole_5.png)

*Figure 5: The zip archive contains a .js file*

The ***plugin.js*** is a type of file downloader commonly called a [Nemucod](https://www.microsoft.com/security/portal/threat/encyclopedia/entry.aspx?Name=TrojanDownloader:JS/Nemucod). This .js file downloads and installs three Windows executable files named ***exe1.exe*** , ***exe2.exe*** , and ***exe3.exe*** as shown below in Figure 6.

[![mole\_6](https://unit42.paloaltonetworks.com/wp-content/uploads/2017/04/Mole_6.png)](https://unit42.paloaltonetworks.com/wp-content/uploads/2017/04/Mole_6.png)

*Figure 6: Plugin.js installing 3 items of malware as shown in a* [*reverse.it analysis*](https://www.reverse.it/sample/b36a3a9e2b9129cbe7385c97fa24666d2d086f7bb8a3c9c4e019f14a41538be0?environmentId=100)

Network traffic generated by this infection is similar to Nemucod downloaders we have [seen from other campaigns](https://malware-traffic-analysis.net/2017/04/05/index3.html). In Figure 7 below, you can see URLs for ***exe1.exe*** , ***exe2.exe*** , and ***exe3.exe*** from ***forum-turism.org.ro***.

[![mole\_7](https://unit42.paloaltonetworks.com/wp-content/uploads/2017/04/Mole_7.png)](https://unit42.paloaltonetworks.com/wp-content/uploads/2017/04/Mole_7.png)

*Figure 7: Traffic from an infection filtered in Wireshark*

The three items of follow-up malware are named ***exe1.exe*** , ***exe2.exe*** , and ***exe3.exe***. In the early days of this campaign, they have been Mole ransomware, Kovter, and Miuref, respectively.

### The Emails

[![mole\_8](https://unit42.paloaltonetworks.com/wp-content/uploads/2017/04/Mole_8.png)](https://unit42.paloaltonetworks.com/wp-content/uploads/2017/04/Mole_8.png)

*Figure 8: An example of the malicious spam from Thursday April 13th*

Emails from this campaign follow the same format [as originally reported](https://isc.sans.edu/forums/diary/Malspam+on+20170411+pushes+yet+another+ransomware+variant/22290/) from Tuesday April 11, 2017. Figure 8 above shows an example email. They have a variety of subject lines, spoofed sending email addresses, and message text. Through Thursday April 13, 2017, the URLs were different for each message. By Friday April 14th, these emails were linking directly to the fake Microsoft Word Online pages, so the URLs for that day were the same.

### Conclusion

Most large-scale malicious spam campaigns tend to stick with operating patterns that are much easier to identify and track. This particular campaign has evolved more quickly than we usually see. Such changing tactics are likely a way to avoid detection.

And this campaign continues to evolve. By Tuesday April 18, 2017, it stopped distributing Mole ransomware, and it began pushing the [KINS banking Trojan](https://blogs.rsa.com/is-cybercrime-ready-to-crown-a-new-kins-inth3wild/) with Kovter and Miuref. By Friday April 21, 2017, this campaign moved from USPS-themed emails to messages about speeding tickets, and it began utilizing a fake parking services website.

Why did we stop seeing Mole ransomware? Because families of ransomware are constantly changing. CryptoMix variants like Mole rarely stay around for more than a few weeks before being repackaged and distributed as a new variant. The samples of Mole ransomware we have identified so far are tagged in [AutoFocus](https://www.paloaltonetworks.com/products/secure-the-network/subscriptions/autofocus) using the [MoleRansomware](https://autofocus.paloaltonetworks.com/#/tag/Unit42.MoleRansomware) tag.

We will continue to investigate this activity for applicable indicators to inform the community and further enhance our threat prevention platform.

**Indicators from this campaign**

Subject lines:

* ATTENTION REQUIRED: INFO ON YOUR IMPENDING REFUND
* ATTENTION REQUIRED: INFORMATION ON YOUR LATEST REFUND
* ATTENTION REQUIRED: you are legally obliged to review the status of your shipment
* AUTOMATED letter: refund information
* AUTOMATED notice in regards to your item's status
* AUTOMATED notification: refund information
* AUTOMATED notification: refund information
* AUTOMATED USPS notification: your shipment has been postponed
* AUTOMATED USPS OFFICIAL LETTER CONCERNING YOUR SHIPMENT
* AUTOMATED USPS statement: your package has been delayed
* AUTOMATIC letter: moneyback information
* AUTOMATIC notice concerning your package's location
* AUTOMATIC notice: refund information
* AUTOMATIC notification in regards to your package's status
* AUTOMATIC notification regarding your order's location
* IMMEDIATE ATTENTION NEEDED: your parcel's been delayed
* IMMEDIATE ATTENTION REQUIRED: your parcel's been delayed
* IMPORTANT USPS customer support letter
* IMPORTANT USPS REFUND INFO
* IMPORTANT USPS REFUND INFORMATION
* IMPORTANT USPS system notice
* Major problems reported to the USPS support team
* Major trouble reported to the USPS customer support
* Official letter from USPS support team
* Official letter in regards to your parcel
* Official notice from USPS support team
* Official notification concerning your package
* Official notification from USPS
* Official notification from USPS customer support team
* OFFICIAL USPS MONEYBACK INFO REGARDING YOUR ITEM
* OFFICIAL USPS MONEYBACK INFORMATION
* Official USPS notification concerning your package
* PROMPT ACTION NEEDED: your order's been delayed
* PROMPT ATTENTION NEEDED: your item's been delayed
* There has been an issue with your package
* There's been an issue with your package
* URGENT USPS customer support letter
* URGENT USPS customer support notification
* URGENT USPS MONEYBACK INFORMATION REGARDING YOUR ITEM
* URGENT: notice of postponement of your order
* USPS CLIENT IMPORANT NEW DETAILS REGARDING YOUR PACKAGE
* USPS CLIENT IMPORANT NEW INFORMATION REGARDING YOUR ITEM
* USPS customer support notification: your order has been postponed
* USPS OFFICIAL LETTER regarding your parcel
* USPS official letter: big problems with your shipment
* USPS official letter: serious issues with your order
* USPS official letter: serious problems with your shipment
* USPS official notice: serious trouble with your parcel
* USPS official notification: serious issues with your package
* USPS system notice: your package has been delayed
* USPS system notification: your package has been delayed
* USPS URGENT LETTER concerning your item
* USPS USER URGENT NEW INFO IN REGARDS TO YOUR PARCEL
* WARNING: DETAILS ON YOUR IMPENDING REFUND
* WARNING: INFORMATION ON YOUR LATEST REFUND
* WARNING: ISSUES WITH YOUR SHIPMENT
* WARNING: PROBLEMS WITH YOUR PACKAGE
* WARNING: TROUBLE WITH YOUR ITEM
* WARNING: TROUBLE WITH YOUR SHIPMENT
* WARNING: you are legally obliged to check the status of your order

Spoofed sending addresses (not from the actual domains listed):

* "USPS Delivery" \<gyjkzau603@abramarketing.com\>
* "USPS Express Delivery" \<ebosuey27523@westusa.com\>
* "USPS Ground Support" \<sa67117644@bibik.com.sg\>
* "USPS Ground Support" \<tijcucey17858440@thefringesalonandspa.net\>
* "USPS Ground Support" \<wucyieal26@laurencehart.com\>
* "USPS Ground" \<awfeoq42111421@theartofsmiles.com\>
* "USPS Ground" \<emcijizu43@lornalloyd.co.uk\>
* "USPS Ground" \<geavpet531656@travis-com.com\>
* "USPS Ground" \<gelerina3705@shubhammetals.com\>
* "USPS Ground" \<oe60568@laxsun.co.in\>
* "USPS Ground" \<qwc6826628@symbionpharmacy.com\>
* "USPS Ground" \<ranrays1371636@methowvalleynews.com\>
* "USPS Ground" \<sosarrij87661705@intergsa.com.my\>
* "USPS Ground" \<syapota57504662@simon-reid.co.uk\>
* "USPS Ground" \<ymuzjmwy22030784@dvs.net\>
* "USPS Home Delivery" \<ddixnuty272104@helendowsley.com.au\>
* "USPS Home Delivery" \<ebeyzhmo3057833@premiereeye.com\>
* "USPS Home Delivery" \<iix61312867@briarcliffstables.com\>
* "USPS Home Delivery" \<ksacugo02105401@korabl-love.ru\>
* "USPS Home Delivery" \<lzaikja068473@vintwine.com\>
* "USPS Home Delivery" \<pfne3616038@heavyrods.com\>
* "USPS Home Delivery" \<waj74534@rebeccasturdy.com\>
* "USPS Home Delivery" \<xasa31221@nsksofia.eu\>
* "USPS Home Delivery" \<xxgap86162407@sharethinkact.co.uk\>
* "USPS Home Delivery" \<yuovior03871347@triplecores.com\>
* "USPS International" \<kihuw88@rcoverdale.co.uk\>
* "USPS International" \<oxioyo5221364@apazen.ro\>
* "USPS International" \<tffmu810@egoldentriangle.com\>
* "USPS Parcels Delivery" \<aawuprug810545@kylegbrown.com\>
* "USPS Parcels Delivery" \<atza2045685@gsb.columbia.edu\>
* "USPS Parcels Delivery" \<diaam8408270@isiamerica.com\>
* "USPS Parcels Delivery" \<eabzs1@leonardgray.co.uk\>
* "USPS Parcels Delivery" \<fyzojuxo46014074@kelleysindia.com\>
* "USPS Parcels Delivery" \<iytkd87@svbbed.com\>
* "USPS Parcels Delivery" \<uino7757@kentschool.cl\>
* "USPS Parcels Delivery" \<vuijpyf0607532@o4icolombia.com\>
* "USPS Priority Delivery" \<a53@websealinc.com\>
* "USPS Priority Delivery" \<newer0780385@iguana-dms.com\>
* "USPS Priority Delivery" \<vdymoi2584835@solind.com.au\>
* "USPS Priority Parcels" \<r4448011@lovethatsmile.net\>
* "USPS Priority" \<coy5@uchiyamagroup.com\>
* "USPS Priority" \<huroim3@rickone.com\>
* "USPS Priority" \<mau4087171@ask-sevgi.net\>
* "USPS Priority" \<o57678@ibiza-real-estate.ru\>
* "USPS Priority" \<oheeruak05250@nexusv.com\>
* "USPS Priority" \<qoeq285@cottageindustriesinc.com\>
* "USPS Priority" \<saayota4044706@garrett-hedlund.com\>
* "USPS SameDay" \<rnoqoi60870482@bantenhosting.net\>
* "USPS Station Management" \<jyee528@luciq.com\>
* "USPS Station Management" \<xejmooa55752638@gayson.co.in\>
* "USPS Station Management" \<zuealee038700@jacobsens.com\>
* "USPS Support Management" \<cihiawru116425@raltrad.net\>
* "USPS Support Management" \<fx7061835@coep.ufrj.br\>
* "USPS Support Management" \<yenxee27@stela.org.br\>
* "USPS Support" \<aumvic36@ariainsaat.com\>
* "USPS Support" \<eetuwusj402634@e-senzaz.com\>
* "USPS Support" \<i610245@baayadesign.com\>
* "USPS Support" \<ifizy41225574@brianseger.com\>
* "USPS Support" \<iqeyqozo35540355@wesleyvillagemacomb.com\>
* "USPS TechConnect" \<vodiybwi72734156@hira.or.kr\>

**Links from the emails on Wednesday, April 12:**

* uspsaeyyuia158140.ideliverys\[.\]com/ioxoory254772
* uspsbhusisoz75.ideliverys\[.\]com/aagupto83
* uspsboodud3731016.ideliverys\[.\]com/rzgyjotv3883685
* uspsekakozq20701607.ideliverys\[.\]com/ciyjfm1453247
* uspsfeu3245443.ideliverys\[.\]com/aivio24273
* uspsgcoez80061682.ideliverys\[.\]com/ipeetol5862
* uspsieibh26357.ideliverys\[.\]com/yey40177
* uspsirokgouu81321536.ideliverys\[.\]com/wokivy5257
* uspskposiuo204.ideliverys\[.\]com/ffauemyi1162
* uspslycoddja50715724.ideliverys\[.\]com/mnqnoh53682573
* uspsnarkk75185.ideliverys\[.\]com/syf11145060
* uspsrekeky57218225.ideliverys\[.\]com/qi72870401
* uspssenluefc87752667.ideliverys\[.\]com/pukooe40275334
* uspstucaej4570.ideliverys\[.\]com/pbpylye22012283
* uspsuhz63110412.ideliverys\[.\]com/t48844775
* uspsuuesylmz2162311.ideliverys\[.\]com/yorixaig28
* uspswmeeeny3538455.ideliverys\[.\]com/fgyzi77
* uspsyhiwejug182483.ideliverys\[.\]com/gjesul74180
* uspszovuoody3241005.ideliverys\[.\]com/deoa382
* uspszujoea26262.ideliverys\[.\]com/vzy575324

**Links from the emails on Thursday, April 13:**

* aexhnneq102342usps.maildeliverys\[.\]com/kovcemaw707572
* bdguz0371usps.maildeliverys\[.\]com/usvyneye6
* ebzizebk4124157usps.maildeliverys\[.\]com/uotajyax507
* eccov13346821usps.maildeliverys\[.\]com/natyxr51034320
* finupriw75037usps.maildeliverys\[.\]com/qaqabxei76122420
* hoemurha6838215usps.maildeliverys\[.\]com/becevo581082
* hwyrztkj8023435usps.maildeliverys\[.\]com/lyiaf13610344
* ibaoe40687236usps.maildeliverys\[.\]com/vevroyo40678322
* juo635usps.maildeliverys\[.\]com/hijxe7411
* pehoaki1160481usps.maildeliverys\[.\]com/mvaklhma54511567
* pfinyryf551041usps.maildeliverys\[.\]com/gsr58503
* poyjsofq7716usps.maildeliverys\[.\]com/irirorcq3818
* py18usps.maildeliverys\[.\]com/ou0453
* rafoyky41usps.maildeliverys\[.\]com/ke244
* roaaheis34435732usps.maildeliverys\[.\]com/iywyerk54374618
* tenyti58325153usps.maildeliverys\[.\]com/mogfulep66534
* ucasucu5264usps.maildeliverys\[.\]com/irwoqoqy563108
* xicyw707845usps.maildeliverys\[.\]com/kyzupyi74721211
* yfypus7588300usps.maildeliverys\[.\]com/n807837
* zfsiqyjh4508687usps.maildeliverys\[.\]com/woorutu63408454

**Links from the emails on Friday, April 14:**

* anilstone\[.\]ir/libraries/joomla/string/wrapper/counter/1.htm

**Associated file hashes:**

SHA256 hash: 8e210658f17a265f0c595b4f63ee7ba3db4c83f64c93f522e74e57e6fc547b11

* File name: ***plugin.exe***
* File size: 149,346 bytes
* File description: Mole ransomware from thru Google Docs URL on April 12th

SHA256 hash: b36a3a9e2b9129cbe7385c97fa24666d2d086f7bb8a3c9c4e019f14a41538be0

* File name: ***plugin.js***
* File size: 1,369 bytes
* File description: Contents of plugin.zip from ***tramplin.online\[.\]ru*** on April 13th

SHA256 hash: a1670db6204f7666ad246cc11736b052713a4413663f5cbe6aec90ab299431a7

* File name: ***plugin.js***
* File size: 1,537 bytes
* File description: Contents of plugin.zip from ***mattsfotoalbum\[.\]de*** on April 13th

SHA256 hash: 40e8dc147f189baf4660d5db8e0cd1c647c7f167f7176c5d8ee03b6cac26fed2

* File name: ***plugin.js***
* File size: 1,382 bytes
* File description: Contents of plugin.zip from ***anilstone\[.\]ir*** on April 14th

SHA256 hash: 3b5b19ebe8d8b6c7e5b2ffd2cc194fad1ae6c9eade7646f48c595bd154f4b1e1

* File name: ***exe1.exe***
* File size: 85,504 bytes
* File description: Mole ransomware (follow-up malware retrieved by ***plugin.js***on April 13th)

SHA256 hash: 50117ce3fe5dba572cf23584dc7541a7cfd4026d4316e69d29cdf536873fdf20

* File name: ***exe1.exe***
* File size: 91,136 bytes
* File description: Mole ransomware (follow-up malware retrieved by ***plugin.js***on April 14th)

SHA256 hash: d9189f6df89acf8e2f0d689ab73429cde37f974ed423f91d1bcabfe5dda700fa

* File name: ***exe2.exe***
* File size: 366,249 bytes
* File description: Kovter malware (follow-up malware retrieved by ***plugin.js*** on April 13th)

SHA256 hash: 41f171eb916d555dc7771ce71013572c498b8d620d2f72872c4b2f3b50c7ccb1

* File name: ***exe2.exe***
* File size: 363,728 bytes
* File description: Kovter malware (follow-up malware retrieved by ***plugin.js***on April 13th)

SHA256 hash: b2dfa063fa605d942822cc84ef90419e26cfa0030444751fc2b87f1456b72e30

* File name: ***exe2.exe***
* File size: 363,922 bytes
* File description: Kovter malware (follow-up malware retrieved by ***plugin.js***on April 14th)

SHA256 hash: ba1327106fa0bf82050cf1a1b9c0c119eb0ded63931af4127e5d541dfa2c6850

* File name: ***exe3.exe***
* File size: 221,974 bytes
* File description: Miuref malware (follow-up malware retrieved by ***plugin.js*** on April 13th)

SHA256 hash: 5459be968e2296a759dcafa7107ef06d02331b5291c9f3056077bcf38ce37d9e

* File name: ***exe3.exe***
* File size: 117,561 bytes
* File description: Miuref malware (follow-up malware retrieved by ***plugin.js*** on April 14th)

**Other URLs associated with this activity:**

Examples of fake Microsoft Microsoft Word Online pages:

* posof.bel\[.\]tr/counter/1.htm
* tramplinonline\[.\]ru/counter/1.htm
* mattsfotoalbum\[.\]de/cache/counter/1.htm
* anilstone\[.\]ir/libraries/joomla/string/wrapper/counter/1.htm

**Examples of malware URLs disguised as Microsoft Office plugin:**

* posof.bel\[.\]tr/counter/plugin.exe
* posof.bel\[.\]tr/counter/plugin.zip
* mattsfotoalbum\[.\]de/cache/counter/plugin.zip
* tramplinonline\[.\]ru/counter/plugin.zip

**Examples for start of URLs generated by plugin.js:**

* alita\[.\]kz/tmp/installation/language/cs-CZ/counter/
* avtotur.com/libraries/fof/utils/ip/counter/
* circus-stroy.ru/counter/
* boorsemsport\[.\]be/templates/yoo\_aurora/less/uikit/counter/
* eurostandard\[.\]ro/pics/size1/counter/
* forum-turism.org\[.\]ro/images/layout/counter/
* glochemindia\[.\]com/modules/mod\_roknavmenu/lib/librokmenu/counter/
* sportbelijning\[.\]be/libraries/joomla/application/web/counter/
  Back to top

### Tags

* [Kovter](https://unit42.paloaltonetworks.com/tag/kovter/ "Kovter")
* [Miuref](https://unit42.paloaltonetworks.com/tag/miuref/ "Miuref")
* [Mole](https://unit42.paloaltonetworks.com/tag/mole/ "Mole")
* [Nemucod](https://unit42.paloaltonetworks.com/tag/nemucod/ "Nemucod")
* [Spam](https://unit42.paloaltonetworks.com/tag/spam/ "Spam")
* [USPS](https://unit42.paloaltonetworks.com/tag/usps/ "USPS")  
  [Threat Research Center](https://unit42.paloaltonetworks.com "Threat Research") [Next: Review of Regional Malware Trends in EMEA: Part 2](https://unit42.paloaltonetworks.com/unit42-review-of-regional-malware-trends-in-emea-part-2/ "Review of Regional Malware Trends in EMEA: Part 2")

### Related Articles

* [Takedowns and Adventures in Deceptive Affiliate Marketing](https://unit42.paloaltonetworks.com/takedowns-and-adventures-in-deceptive-affiliate-marketing/ "article - table of contents")
* [Threat Brief: Why You Need to Be Careful of Links in Email](https://unit42.paloaltonetworks.com/unit42-threat-brief-need-careful-links-email/ "article - table of contents")
* [Practice Makes Perfect: Nemucod Evolves Delivery and Obfuscation Techniques to Harvest Credentials](https://unit42.paloaltonetworks.com/unit42-practice-makes-perfect-nemucod-evolves-delivery-obfuscation-techniques-harvest-credentials/ "article - table of contents")

## Related Ransomware Resources

![Pictorial representation of Iran cyber attacks. Close-up of a person wearing glasses, with computer code reflected in the lenses.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/12_Security-Technology_Category_1920x900-786x368.jpg)  
[![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)High Profile Threats](https://unit42.paloaltonetworks.com/category/top-cyberthreats/) April 17, 2026 [#### Threat Brief: Escalation of Cyber Risk Related to Iran (Updated April 17)](https://unit42.paloaltonetworks.com/iranian-cyberattacks-2026/)

* [APK](https://unit42.paloaltonetworks.com/tag/apk/ "APK")

* [DDoS attacks](https://unit42.paloaltonetworks.com/tag/ddos-attacks/ "DDoS attacks")

* [GenAI](https://unit42.paloaltonetworks.com/tag/genai/ "GenAI")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/iranian-cyberattacks-2026/ "Threat Brief: Escalation of Cyber Risk Related to Iran (Updated April 17)")  
  ![Pictorial representation of RaaS RansomHouse. Digital representation of cybersecurity concept with a padlock superimposed over computer circuit boards, symbolizing data protection and encryption technologies.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/12/06_Ransomware_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) December 17, 2025 [#### From Linear to Complex: An Upgrade in RansomHouse Encryption](https://unit42.paloaltonetworks.com/ransomhouse-encryption-upgrade/)

* [ESXi](https://unit42.paloaltonetworks.com/tag/esxi/ "ESXi")

* [Jolly Scorpius](https://unit42.paloaltonetworks.com/tag/jolly-scorpius/ "Jolly Scorpius")

* [RansomHouse](https://unit42.paloaltonetworks.com/tag/ransomhouse/ "RansomHouse")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ransomhouse-encryption-upgrade/ "From Linear to Complex: An Upgrade in RansomHouse Encryption")  
  ![Pictorial representation of 01flip ransomware written in Rust. Digital artwork of a pixelated U.S. dollar bill disintegrating into small blocks against a blue data matrix background.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/12/05_Ransomware_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) December 10, 2025 [#### 01flip: Multi-Platform Ransomware Written in Rust](https://unit42.paloaltonetworks.com/new-ransomware-01flip-written-in-rust/)

* [Bitcoin](https://unit42.paloaltonetworks.com/tag/bitcoin/ "Bitcoin")

* [CL-CRI-103](https://unit42.paloaltonetworks.com/tag/cl-cri-103/ "CL-CRI-103")

* [Cryptocurrency](https://unit42.paloaltonetworks.com/tag/cryptocurrency/ "Cryptocurrency")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/new-ransomware-01flip-written-in-rust/ "01flip: Multi-Platform Ransomware Written in Rust")  
  ![Pictorial representation of malicious LLMs. Close-up view of a digital wall displaying various glowing icons, representing a high-tech network interface.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/11/AdobeStock_1270203474-786x440.jpeg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) November 25, 2025 [#### The Dual-Use Dilemma of AI: Malicious LLMs](https://unit42.paloaltonetworks.com/dilemma-of-ai-malicious-llms/)

* [Credential Harvesting](https://unit42.paloaltonetworks.com/tag/credential-harvesting/ "Credential Harvesting")

* [Data exfiltration](https://unit42.paloaltonetworks.com/tag/data-exfiltration/ "data exfiltration")

* [LLM](https://unit42.paloaltonetworks.com/tag/llm/ "LLM")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/dilemma-of-ai-malicious-llms/ "The Dual-Use Dilemma of AI: Malicious LLMs")  
  ![Constellation image representing the constellation schema used by Palo Alto Networks Unit 42 to track nation-state and cybercrime threat actor groups](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/Generic-B-1920x900-1-786x368.png)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/threat-actor-groups.svg)Threat Actor Groups](https://unit42.paloaltonetworks.com/category/threat-actor-groups/) August 1, 2025 [#### Threat Actor Groups Tracked by Palo Alto Networks Unit 42 (Updated Aug. 1, 2025)](https://unit42.paloaltonetworks.com/threat-actor-groups-tracked-by-palo-alto-networks-unit-42/)

* [Academic Serpens](https://unit42.paloaltonetworks.com/tag/academic-serpens/ "Academic Serpens")

* [Agent Serpens](https://unit42.paloaltonetworks.com/tag/agent-serpens/ "Agent Serpens")

* [Agonizing Serpens](https://unit42.paloaltonetworks.com/tag/agonizing-serpens/ "Agonizing Serpens")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/threat-actor-groups-tracked-by-palo-alto-networks-unit-42/ "Threat Actor Groups Tracked by Palo Alto Networks Unit 42 (Updated Aug. 1, 2025)")  
  ![Pictorial representation of Unit 42 threat attribution system. Illustration featuring a white triangle centered within an abstract cosmic background of purple and blue swirls and stars.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/07/Generic-A-1920x900-1-786x368.png)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/threat-actor-groups.svg)Threat Actor Groups](https://unit42.paloaltonetworks.com/category/threat-actor-groups/) July 31, 2025 [#### Introducing Unit 42's Attribution Framework](https://unit42.paloaltonetworks.com/unit-42-attribution-framework/)

* [Advanced Persistent Threat](https://unit42.paloaltonetworks.com/tag/advanced-persistent-threat/ "Advanced Persistent Threat")

* [Bookworm](https://unit42.paloaltonetworks.com/tag/bookworm/ "Bookworm")

* [Nomenclature](https://unit42.paloaltonetworks.com/tag/nomenclature/ "nomenclature")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/unit-42-attribution-framework/ "Introducing Unit 42’s Attribution Framework")  
  ![Pictorial representation of the ransomware landscape. Digital artwork of a disintegrating U.S. dollar bill with pixelated effects on a cyber-inspired background.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/04/05_Ransomware_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-report-white-1.svg)Trend Reports](https://unit42.paloaltonetworks.com/category/trend-reports/) April 23, 2025 [#### Extortion and Ransomware Trends January-March 2025](https://unit42.paloaltonetworks.com/2025-ransomware-extortion-trends/)

* [BianLian](https://unit42.paloaltonetworks.com/tag/bianlian/ "BianLian")

* [Akira ransomware](https://unit42.paloaltonetworks.com/tag/akira-ransomware/ "Akira ransomware")

* [Muddled Libra](https://unit42.paloaltonetworks.com/tag/muddled-libra/ "Muddled Libra")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/2025-ransomware-extortion-trends/ "Extortion and Ransomware Trends January-March 2025")  
  ![A pictorial representation of Akira ransomware, distributed by Howling Scorpius. A person's hand typing on a keyboard with a digital screen displaying the word "password" highlighted in blue, set against a backdrop of various cybersecurity interface graphics.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/11/09_Cybercrime_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)High Profile Threats](https://unit42.paloaltonetworks.com/category/top-cyberthreats/) December 2, 2024 [#### Threat Assessment: Howling Scorpius (Akira Ransomware)](https://unit42.paloaltonetworks.com/threat-assessment-howling-scorpius-akira-ransomware/)

* [Howling Scorpius](https://unit42.paloaltonetworks.com/tag/howling-scorpius/ "Howling Scorpius")

* [Leak site](https://unit42.paloaltonetworks.com/tag/leak-site/ "Leak site")

* [Torrenting](https://unit42.paloaltonetworks.com/tag/torrenting/ "torrenting")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/threat-assessment-howling-scorpius-akira-ransomware/ "Threat Assessment: Howling Scorpius (Akira Ransomware)")  
  ![Pictorial representation of a threat like BlackSuit ransomware. An illustration of a modern workspace with a laptop displaying cybersecurity icons, surrounded by stacks of coins and a credit card, all depicted in a neon, digital art style.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/11/04_Ransomware_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)High Profile Threats](https://unit42.paloaltonetworks.com/category/top-cyberthreats/) November 20, 2024 [#### Threat Assessment: Ignoble Scorpius, Distributors of BlackSuit Ransomware](https://unit42.paloaltonetworks.com/threat-assessment-blacksuit-ransomware-ignoble-scorpius/)

* [BlackSuit ransomware](https://unit42.paloaltonetworks.com/tag/blacksuit-ransomware/ "BlackSuit ransomware")

* [Construction](https://unit42.paloaltonetworks.com/tag/construction/ "construction")

* [Education](https://unit42.paloaltonetworks.com/tag/education/ "Education")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/threat-assessment-blacksuit-ransomware-ignoble-scorpius/ "Threat Assessment: Ignoble Scorpius, Distributors of BlackSuit Ransomware")  
  ![A representation of a threat group like Jumpy Pisces. Illustrative image featuring two fish and the Pisces constellation superimposed on a stylized, abstract background with flowing purple waves and a starry night sky.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/10/Pisces-NK-A-1920x900-1-786x368.png)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/threat-actor-groups.svg)Threat Actor Groups](https://unit42.paloaltonetworks.com/category/threat-actor-groups/) October 30, 2024 [#### Jumpy Pisces Engages in Play Ransomware](https://unit42.paloaltonetworks.com/north-korean-threat-group-play-ransomware/)

* [North Korea](https://unit42.paloaltonetworks.com/tag/north-korea/ "North Korea")

* [Jumpy Pisces](https://unit42.paloaltonetworks.com/tag/jumpy-pisces/ "Jumpy Pisces")

* [Fiddling Scorpius](https://unit42.paloaltonetworks.com/tag/fiddling-scorpius/ "Fiddling Scorpius")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/north-korean-threat-group-play-ransomware/ "Jumpy Pisces Engages in Play Ransomware")

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)  
  ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg) ![Enlarged Image]()  
  ![Newsletter](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/unit42-footer-subscribe-desktop.png)  
  ![UNIT 42 Small Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/palo-alto-logo-small.svg) Get updates from Unit 42

## Peace of mind comes from staying ahead of threats. Subscribe today.

Your Email

Subscribe for email updates to all Unit 42 threat research.  
By submitting this form, you agree to our [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use "Terms of Use") and acknowledge our [Privacy Statement.](https://www.paloaltonetworks.com/legal-notices/privacy "Privacy Statement")

This site is protected by reCAPTCHA and the Google [Privacy Policy](https://policies.google.com/privacy) and [Terms of Service](https://policies.google.com/terms) apply.

Invalid captcha!
Subscribe ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg) ![loader](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-loader.svg)  
{#footer} Products and Services

* [AI-Powered Network Security Platform](https://www.paloaltonetworks.com/network-security)

* [Secure AI by Design](https://www.paloaltonetworks.com/ai-security)

* [Prisma AIRS](https://www.paloaltonetworks.com/ai-security/prisma-airs)

* [AI Access Security](https://www.paloaltonetworks.com/sase/ai-access-security)

* [Cloud Delivered Security Services](https://www.paloaltonetworks.com/network-security/security-subscriptions)

* [Advanced Threat Prevention](https://www.paloaltonetworks.com/network-security/advanced-threat-prevention)

* [Advanced URL Filtering](https://www.paloaltonetworks.com/network-security/advanced-url-filtering)

* [Advanced WildFire](https://www.paloaltonetworks.com/network-security/advanced-wildfire)

* [Advanced DNS Security](https://www.paloaltonetworks.com/network-security/advanced-dns-security)

* [Enterprise Data Loss Prevention](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention)

* [Enterprise IoT Security](https://www.paloaltonetworks.com/network-security/enterprise-device-security)

* [Medical IoT Security](https://www.paloaltonetworks.com/network-security/medical-device-security)

* [Industrial OT Security](https://www.paloaltonetworks.com/network-security/ot-security-solution)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security)

* [Next-Generation Firewalls](https://www.paloaltonetworks.com/network-security/next-generation-firewall)

* [Hardware Firewalls](https://www.paloaltonetworks.com/network-security/hardware-firewall-innovations)

* [Software Firewalls](https://www.paloaltonetworks.com/network-security/software-firewalls)

* [Strata Cloud Manager](https://www.paloaltonetworks.com/network-security/strata-cloud-manager)

* [SD-WAN for NGFW](https://www.paloaltonetworks.com/network-security/sd-wan-subscription)

* [PAN-OS](https://www.paloaltonetworks.com/network-security/pan-os)

* [Panorama](https://www.paloaltonetworks.com/network-security/panorama)

* [Secure Access Service Edge](https://www.paloaltonetworks.com/sase)

* [Prisma SASE](https://www.paloaltonetworks.com/sase)

* [Application Acceleration](https://www.paloaltonetworks.com/sase/app-acceleration)

* [Autonomous Digital Experience Management](https://www.paloaltonetworks.com/sase/adem)

* [Enterprise DLP](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention)

* [Prisma Access](https://www.paloaltonetworks.com/sase/access)

* [Prisma Browser](https://www.paloaltonetworks.com/sase/prisma-browser)

* [Prisma SD-WAN](https://www.paloaltonetworks.com/sase/sd-wan)

* [Remote Browser Isolation](https://www.paloaltonetworks.com/sase/remote-browser-isolation)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security)

* [AI-Driven Security Operations Platform](https://www.paloaltonetworks.com/cortex)

* [Cloud Security](https://www.paloaltonetworks.com/cortex/cloud)

* [Cortex Cloud](https://www.paloaltonetworks.com/cortex/cloud)

* [Application Security](https://www.paloaltonetworks.com/cortex/cloud/application-security)

* [Cloud Posture Security](https://www.paloaltonetworks.com/cortex/cloud/cloud-posture-security)

* [Cloud Runtime Security](https://www.paloaltonetworks.com/cortex/cloud/runtime-security)

* [Prisma Cloud](https://www.paloaltonetworks.com/prisma/cloud)

* [AI-Driven SOC](https://www.paloaltonetworks.com/cortex)

* [Cortex XSIAM](https://www.paloaltonetworks.com/cortex/cortex-xsiam)

* [Cortex XDR](https://www.paloaltonetworks.com/cortex/cortex-xdr)

* [Cortex XSOAR](https://www.paloaltonetworks.com/cortex/cortex-xsoar)

* [Cortex Xpanse](https://www.paloaltonetworks.com/cortex/cortex-xpanse)

* [Unit 42 Managed Detection \& Response](https://www.paloaltonetworks.com/unit42/respond/managed-detection-response)

* [Managed XSIAM](https://www.paloaltonetworks.com/cortex/managed-xsiam)

* [Next-Generation Identity Security](https://www.paloaltonetworks.com/idira)

* [Privileged Access Management](https://www.paloaltonetworks.com/idira/human/privileged-access-management)

* [Identity and Access Management](https://www.paloaltonetworks.com/idira/human/identity-and-access-management)

* [Endpoint Privilege Manager](https://www.paloaltonetworks.com/idira/human/endpoint-privilege-manager)

* [Identity Governance](https://www.paloaltonetworks.com/idira/human/identity-governance)

* [Workforce Password Management](https://www.paloaltonetworks.com/idira/human/workforce-password-management)

* [Agentic Identities](https://www.paloaltonetworks.com/idira/agentic)

* [Secrets Management](https://www.paloaltonetworks.com/idira/machine/secrets-management)

* [Unified Secrets Governance](https://www.paloaltonetworks.com/idira/machine/unified-secrets-governance)

* [Application Credentials Delivery](https://www.paloaltonetworks.com/idira/machine/application-credentials-delivery)

* [Vendor Privileged Access](https://www.paloaltonetworks.com/idira/human/vendor-privileged-access)

* [Threat Intel and Incident Response Services](https://www.paloaltonetworks.com/unit42)

* [Prepare for Emerging Risks](https://www.paloaltonetworks.com/unit42/prepare-for-emerging-risks/continuous-frontier-ai-defense)

* [Strengthen Your Defenses](https://www.paloaltonetworks.com/unit42/strengthen-your-defenses)

* [Build Your Security Strategy](https://www.paloaltonetworks.com/unit42/build-your-security-strategy)

* [Understand the Adversary](https://www.paloaltonetworks.com/unit42/threat-intelligence)

* [Respond to a Cyber Attack](https://www.paloaltonetworks.com/unit42/respond)  
  Company

* [About Us](https://www.paloaltonetworks.com/about-us)

* [Careers](https://jobs.paloaltonetworks.com/en/)

* [Contact Us](https://www.paloaltonetworks.com/company/contact-sales)

* [Corporate Responsibility](https://www.paloaltonetworks.com/about-us/corporate-responsibility)

* [Customers](https://www.paloaltonetworks.com/customers)

* [Investor Relations](https://investors.paloaltonetworks.com/)

* [Location](https://www.paloaltonetworks.com/about-us/locations)

* [Newsroom](https://www.paloaltonetworks.com/company/newsroom)  
  Popular Links

* [Blog](https://www.paloaltonetworks.com/blog/)

* [Communities](https://www.paloaltonetworks.com/communities)

* [Content Library](https://www.paloaltonetworks.com/resources)

* [Cyberpedia](https://www.paloaltonetworks.com/cyberpedia)

* [Event Center](https://events.paloaltonetworks.com/)

* [Manage Email Preferences](https://start.paloaltonetworks.com/preference-center)

* [Products A-Z](https://www.paloaltonetworks.com/products/products-a-z)

* [Product Certifications](https://www.paloaltonetworks.com/legal-notices/trust-center/certifications)

* [Report a Vulnerability](https://www.paloaltonetworks.com/security-disclosure)

* [Sitemap](https://www.paloaltonetworks.com/sitemap)

* [Tech Docs](https://docs.paloaltonetworks.com/)

* [Unit 42](https://unit42.paloaltonetworks.com/)

* [Do Not Sell or Share My Personal Information](https://panwedd.exterro.net/portal/dsar.htm?target=panwedd)
  ![Palo Alto Networks Logo](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/pan-logo-dark.svg)

* [Privacy](https://www.paloaltonetworks.com/legal-notices/privacy)

* [Trust Center](https://www.paloaltonetworks.com/legal-notices/trust-center)

* [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use)

* [Documents](https://www.paloaltonetworks.com/legal)

Copyright © 2026 Palo Alto Networks. All Rights Reserved

* [![Youtube](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/youtube-black.svg)](https://www.youtube.com/user/paloaltonetworks)
* [![Podcast](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/icons/podcast.svg)](https://www.paloaltonetworks.com/podcasts/threat-vector)
* [![Facebook](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/facebook-black.svg)](https://www.facebook.com/PaloAltoNetworks/)
* [![LinkedIn](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/linkedin-black.svg)](https://www.linkedin.com/company/palo-alto-networks)
* [![Twitter](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/twitter-x-black.svg)](https://twitter.com/PaloAltoNtwks)
* EN  
  Select your language  
  ![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg) ![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg) ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg)

### Default Heading

Read the article ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg)  
Seekbar

![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg)  
![Volume](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-volume.svg)  
Volume
![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg)
