[![Logo](https://www.paloaltonetworks.com/wp-content/uploads/2021/07/PANW_Parent.png)](https://www.paloaltonetworks.com/)  
[![Unit42 Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/unit42-logo-white.svg)](https://unit42.paloaltonetworks.com/)  
Menu

* [Tools](https://unit42.paloaltonetworks.com/tools/)
* [ATOMs](https://unit42.paloaltonetworks.com/atoms/)
* [Security Consulting](https://www.paloaltonetworks.com/unit42)
* [About Us](https://unit42.paloaltonetworks.com/about-unit-42/)
* [**Under Attack?**](https://start.paloaltonetworks.com/contact-unit42.html)
* [Threat Research Center](https://unit42.paloaltonetworks.com "Threat Research")
* [Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/ "Threat Research")
* [Malware](https://unit42.paloaltonetworks.com/category/malware/ "Malware")  
  [Malware](https://unit42.paloaltonetworks.com/category/malware/)

# Muddying the Water: Targeted Attacks in the Middle East

![Clock Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-clock.svg) 8 min read  
Related Products  
[![Advanced WildFire icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Advanced WildFire](https://unit42.paloaltonetworks.com/product-category/advanced-wildfire/ "Advanced WildFire")

* ![Profile Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-profile-grey.svg)  
  By:
  
  * [Tom Lancaster](https://unit42.paloaltonetworks.com/author/tom-lancaster/)

* ![Published Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-calendar-grey.svg)  
  Published:November 14, 2017

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-category.svg)  
  Categories:
  
  * [Malware](https://unit42.paloaltonetworks.com/category/malware/)
  * [Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/)

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-tags-grey.svg)  
  Tags:
  
  * [FIN7](https://unit42.paloaltonetworks.com/tag/fin7/)
  * [Lazagne](https://unit42.paloaltonetworks.com/tag/lazagne/)
  * [Meterpreter](https://unit42.paloaltonetworks.com/tag/meterpreter/)
  * [Mimikatz](https://unit42.paloaltonetworks.com/tag/mimikatz/)
  * [MuddyWater](https://unit42.paloaltonetworks.com/tag/muddywater/)

* [![Download Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-download.svg)](https://unit42.paloaltonetworks.com/unit42-muddying-the-water-targeted-attacks-in-the-middle-east/?pdf=download&lg=en&_wpnonce=5f0cc26d8b "Click here to download")

* [![Print Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-print.svg)](https://unit42.paloaltonetworks.com/unit42-muddying-the-water-targeted-attacks-in-the-middle-east/?pdf=print&lg=en&_wpnonce=5f0cc26d8b "Click here to print")

Share![Down arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/down-arrow.svg)

* ![Link Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-share-link.svg)
* [![Link Email](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-sms.svg)](mailto:?subject=Muddying%20the%20Water:%20Targeted%20Attacks%20in%20the%20Middle%20East&body=Check%20out%20this%20article%20https%3A%2F%2Funit42.paloaltonetworks.com%2Funit42-muddying-the-water-targeted-attacks-in-the-middle-east%2F "Share in email")
* [![Facebook Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-fb-share.svg)](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Funit42.paloaltonetworks.com%2Funit42-muddying-the-water-targeted-attacks-in-the-middle-east%2F "Share in Facebook")
* [![LinkedIn Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-linkedin-share.svg)](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Funit42-muddying-the-water-targeted-attacks-in-the-middle-east%2F&title=Muddying%20the%20Water:%20Targeted%20Attacks%20in%20the%20Middle%20East "Share in LinkedIn")
* [![Twitter Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-twitter-share.svg)](https://twitter.com/intent/tweet?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Funit42-muddying-the-water-targeted-attacks-in-the-middle-east%2F&text=Muddying%20the%20Water:%20Targeted%20Attacks%20in%20the%20Middle%20East "Share in Twitter")
* [![Reddit Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-reddit-share.svg)](https://www.paloaltonetworks.com//www.reddit.com/submit?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Funit42-muddying-the-water-targeted-attacks-in-the-middle-east%2F&ts=markdown "Share in Reddit")
* [![Mastodon Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-mastodon-share.svg)](https://mastodon.social/share?text=Muddying%20the%20Water:%20Targeted%20Attacks%20in%20the%20Middle%20East%20https%3A%2F%2Funit42.paloaltonetworks.com%2Funit42-muddying-the-water-targeted-attacks-in-the-middle-east%2F "Share in Mastodon")
  Summary  
  This blog discusses targeted attacks against the Middle East taking place between February and October 2017 by a group Unit 42 is naming "MuddyWater". This blog links this recent activity with previous isolated public reporting on similar attacks we believe are related. We refer to these attacks as MuddyWater due to the confusion in attributing these attacks. Although the activity was previously linked by others to the FIN7 threat actor group, our research suggests the activity is in fact espionage related and unlikely to be FIN7 related.  
  The MuddyWater attacks are primarily against Middle Eastern nations. However, we have also observed attacks against surrounding nations and beyond, including targets in India and the USA. MuddyWater attacks are characterized by the use of a slowly evolving PowerShell-based first stage backdoor we call "POWERSTATS". Despite broad scrutiny and reports on MuddyWater attacks, the activity continues with only incremental changes to the tools and techniques.

Introduction \& Overview  
The Palo Alto Networks Unit 42 research team recently came across a series of malicious files which were almost identical to those targeting the Saudi Arabian government [previously discussed by MalwareBytes](https://blog.malwarebytes.com/threat-analysis/2017/09/elaborate-scripting-fu-used-in-espionage-attack-against-saudi-arabia-government_entity/). Which in turn, closely resembles a [previous article by Morphisec](https://blog.morphisec.com/fileless-attack-framework-discovery). These attacks have also been tracked by [several other researchers](https://sec0wn.blogspot.sg/2017/10/continued-activity-targeting-middle-east.html) on Twitter and elsewhere.  
The activity has been consistent throughout 2017 and, based on our analysis, targets or is suspected to target, entities in the following countries:

* Saudi Arabia
* Iraq
* Israel
* United Arab Emirates
* Georgia
* India
* Pakistan
* Turkey
* USA

The malicious documents were adjusted according to the target regions, often using the logos of branches of local government, prompting the users to bypass security controls and enable macros. An overview of the technical changes seen in the past year is given in the graphic below, note that raw IOCs present in this graphic can be found as text in the [Appendix](#Appendix)at the end of this article.  
![MuddyWater\_1](https://unit42.paloaltonetworks.com/wp-content/uploads/2017/11/MuddyWater_1.png)

*Figure 1. An overview of the delivery of POWERSTATS, C2 URLs used, and other changes in the malware*

MuddyWater in the Middle East  
The attackers behind MuddyWater have been active throughout 2017, with targets across the Middle East and surrounding areas, examples of the decoy documents observed is given in Table 1.  
Of course, being named in a decoy document doesn't mean any of these organizations have been attacked themselves or are involved in the attacks: the MuddyWater actors are abusing the trust these organizations' names and/or logos command for their malicious purposes.

|--------------|---------------------------------------------------------------------------------------------------|-------------------------------------|
| **Month**    | **File Name or Decoy Document Theme**                                                             | **Suspected Target Region**         |
| **Nov 2017** | The NSA Telenor.doc                                                                               | Unknown Pakistan                    |
| **Oct 2017** | Circulars.doc dollar.doc Pakistan Federal Investigation Agency CV of Middle Eastern Civil Servant | Turkey Pakistan                     |
| **Sep 2017** | Iraq National Intelligence Service Kaspersky Security solution 2017.doc                           | Iraq                                |
| **Aug 2017** | Arab Emirate سری.docm Iraq Commission of Integrity                                                | Arab Emirates                       |
| **Jul 2017** | Requirements of the Sago.doc CommIT-Document.doc Confidential letters.doc                         | Saudi Arabia Arab Emirates Pakistan |
| **Jun 2017** | Iraq Kurdistan Regional Government RFP\_VOIP.doc                                                   | Iraq                                |
| **May 2017** | RFP.doc Requirement.doc Iraq Kurdistan Regional Government                                        | Georgia Iraq                        |
| **Mar 2017** | court.doc                                                                                         | Georgia                             |
| **Feb 2017** | CERT-Audit-20172802-GEO.xls                                                                       | Georgia                             |

*Table 1 -- Examples of the lure documents observed in the MuddyWater attacks.*

All of these documents we observed and outlined above are related via:

* Shared C2 infrastructure.
* Use of the non-public PowerShell backdoor previously described by Morphisec and MalwareBytes (which we refer to as POWERSTATS).
* Shared attributes of the malicious documents used in attacks.
* Shared attributes as to how the documents were delivered.

Based on these connections we can be confident that all the files and infrastructure we give in our appendices are related, since more than one of these can be used to link each of the samples discussed in each case.

I download my tools from GitHub, and so do my victims.  
The tools used by the MuddyWater attackers have been well documented by the previously cited research and a common theme of previous reporting was the open source nature of much of the toolset used by MuddyWater: Meterpreter, Mimikatz, Lazagne, Invoke-Obfuscation etc.. In some of their recent attack documents, the attackers also used GitHub as a hosting site for their custom backdoor, POWERSTATS. Specifically, the following GitHub repositories appear to be controlled by the MuddyWater threat actor(s):

* \[unknown SHA256\]
  
  * Downloads payload from: hxxps://raw.githubusercontent\[.\]com/F0R3X/BrowserFontArabic/master/ArabicBrowserFont.exe

* \[unknown SHA256\]
  
  * Downloads payload from: hxxps://raw.githubusercontent\[.\]com/F0R3X/BrowserFontArabic/master/FontArabic.exe

* 9b5e36bb7518a9e333c31d09b589102f89e3425571dd434820ab3c437dc4e0d9 (and several others)
  
  * Downloads payload from: hxxps://raw.githubusercontent\[.\]com/ReactDeveloper2017/react/master/src/test/test.js

Interestingly, both profiles were populated with forked repositories to give them an air of legitimacy as shown in figure 2. The POWERSTATS malware was compiled as an exe using [PS2EXE](https://github.com/vergl4s/pentesting-dump/blob/master/net/Windows/PS2EXE-v0.5.0.0/ps2exe.ps1). However, this was a minor anomaly, as it was only seen in this case: raw scripts being used in all other cases.  
![Muddywater\_2](https://unit42.paloaltonetworks.com/wp-content/uploads/2017/11/Muddywater_2.png)

*Figure 2 -- The GitHub profile for F0R3X containing both legitimate forked code and the binaries created by the attacker. Note that the username could be a small joke on the attackers' part regarding the attribution to FIN7.*

Pwn one to pwn them all  
In some of the instances we observed what appeared to be compromised accounts at third party organizations sending the malware. In one case, the attackers sent a malicious document which was nearly identical to a legitimate attachment which we observed later being sent to the same recipient. This indicates that the attackers stole and modified a legitimate document from the compromised user account, crafted a malicious decoy Word macro document using this stolen document and sent it to the target recipient who might be expecting the email from the original account user before the real sender had time to send it.

This targeting of third party organizations to attack further targets is a risky move on the attackers' part, as it potentially reveals their activity within the compromised third party organizations to the new target (those receiving the malicious documents

Making sense of MuddyWater  
When we looked at the cluster of activity which consisted of what appeared to be espionage-focused attacks in the Middle East, we were somewhat confused as the previous public reporting had attributed these attacks to FIN7. FIN7 is a threat actor group that is financially motivated with targets in the restaurant, services and financial sectors. Following the trail of existing public reporting, the tie to FIN7 is essentially made based on a download observed from a MuddyWater C2, of a non-public tool "DNSMessenger".  
For example, [Morphisec](https://blog.morphisec.com/fileless-attack-framework-discovery) wrote:  
"Later in our investigation, the same command server also delivered a variant of the DNS messenger similar to that [described by Talos](https://blog.talosintelligence.com/2017/03/dnsmessenger.html). The domain names differed but the script adheres to the same logic (including the logic function)."  
The DNSMessenger malware is an obfuscated and customized version of the popular [DNS\_TXT\_PWNAGE.ps1 script](https://github.com/samratashok/nishang/blob/master/Backdoors/DNS_TXT_Pwnage.ps1) available on GitHub and is [also referred to by FireEye as POWERSOURCE](https://www.fireeye.com/blog/threat-research/2017/03/fin7_spear_phishing.html). The use of the DNSMessenger tool appears primarily linked to FIN7, with no other samples being attributable to MuddyWater.  
This led us to query the relationship between the newer attacks we were looking at and the alleged FIN7 link. As part of this research, we came up with the following hypotheses along with their likelihoods, and a rationale for each one.  
**1)** **The FIN7 threat actor is also involved in espionage in the Middle East - Unlikely**  
Whilst this may seem an attractive hypothesis to some, there are aspects on the technical side that simply don't add up. Primarily, there are significant disparities between FIN7 and MuddyWater, specifically in terms of:

* Malware unique to FIN7, or commonly used by them has not yet been seen in any MuddyWater investigations (except for the single observation of the DNSMessenger sample)
* Other non-public malware and tools used by MuddyWater have not been observed in our FIN7 investigations.
* From an infrastructure point of view there is no overlap between the two sets of activity, the only overlap is the use of the unique tool "DNSMessenger"

When these points are considered together in conjunction with the significant difference in targeting they make a strong case for classifying this activity as distinct from FIN7 activity.  
**2)** **The DNSMessenger malware is a shared tool, used by FIN7, MuddyWater and perhaps other groups - Unlikely**  
We have attempted to find examples of code available in public data sources that would generate the variation of the DNSMessenger malware and had little luck in doing so. Even though the code for DNSMessenger is publicly available following research into attackers published by 3^rd^ parties, attackers would have to write the corresponding server side to use it, and as such they may well choose to use the public DNS\_TXT\_Pwnage.ps1 script instead.  
Despite this, based on the chain of analysis above we cannot discount the notion that DNSMessenger is shared by multiple attackers, including FIN7 and MuddyWater.  
**3) There was a mistake in the original Morphisec analysis which linked these attacks to FIN7 - Possible**  
Little detail is given on the nature of how the connection between DNSMessenger and MuddyWater was discovered it isn't possible for us to verify this link.  
**4)** **The attackers realized they were under investigation and planted a false flag - Possible**  
The attackers realized they were under investigation and planted a false flag on their C2 server, uploading a copy of the FIN7 DNSMessenger code which had been previously mentioned (and was since publicly available) by FireEye and delivering it to researchers to trick them into mis-attributing the campaign.  
Indeed, the sample shared by Morphisec on PasteBin is identical to the one dropped by [the sample discussed](https://www.hybrid-analysis.com/sample/c26a351c36ac03aa09f5d98531a103f971b84e22b6a1312bf1dc501421434290?environmentId=100) in the FireEye FIN7 SEC campaign blog except for the final line.

Final thoughts  
Whilst we could conclude with confidence that the attacks discussed in this article are not FIN7 related, we were not able to answer many of our questions about the MuddyWater attacks. We are currently unable to make a firm conclusion about the origin of the attackers, or the specific types of information they seek out once on a network. In any case we will continue to track their activities to provide protections for our customers.  
We hope the analysis presented shows the importance of drawing your own conclusions based on the data available to you, not just taking the conclusions given in the public domain at face value. This is especially true when actors who rely on slightly modified (and publicly available) open source tools are in play. Copycat threat actors can easily mimic attackers who use open source tools which can confuse attribution efforts meaning more than one aspect of the attacks observed must be considered when clustering.  
On top of this, whilst the vast majority of threat analysis in the public domain is repeatable and correct, in some cases it can be difficult to verify the analysis available. When it is hard to reproduce the analysis the confidence in any conclusions drawn must be lower than it would otherwise be, since you cannot know for sure that what is stated is true.  
Palo Alto Networks customers are protected from this threat in the following ways:

* WildFire and Traps detect all the malware supported in this report as malicious.
* Traps customers can deploy Heuristic methods to detect attacks that use these techniques.
* C2 domains used by the attackers are blocked via Threat Prevention.

AutoFocus customers can monitor ongoing activity from the threats discussed in this report by looking at the following tags:

* [MuddyWater](https://autofocus.paloaltonetworks.com/#/tag/Unit42.MuddyWater)
* [PowerStats](https://autofocus.paloaltonetworks.com/#/tag/Unit42.POWERSTATS)
* [LazaGne](https://autofocus.paloaltonetworks.com/#/tag/Unit42.Lazagne)
* [DNSMessenger](https://autofocus.paloaltonetworks.com/#/tag/Unit42.DNSMessenger)
* [FIN7](https://autofocus.paloaltonetworks.com/#/tag/Unit42.Fin7)

Appendix A -- C2 Addresses

148\.251.204\[.\]131  
144\.76.109\[.\]88  
138\.201.75\[.\]227  
**Compromised Legitimate Sites**  
106\[.\]187\[.\]38\[.\]21  
arbiogaz\[.\]com  
azmwn\[.\]suliparwarda\[.\]com  
bangortalk\[.\]org\[.\]uk  
best2\[.\]thebestconference\[.\]org  
camco\[.\]com\[.\]pk  
cbpexbrasilia\[.\]com\[.\]br  
cgss\[.\]com\[.\]pk  
diplomat\[.\]com\[.\]sa  
feribschat\[.\]eu  
ghanaconsulate\[.\]com\[.\]pk  
magical-energy\[.\]com  
mainandstrand\[.\]com  
riyadhfoods\[.\]com  
school\[.\]suliparwarda\[.\]com  
suliparwarda\[.\]com  
tmclub\[.\]eu  
watyanagr\[.\]nfe\[.\]go\[.\]th  
whiver\[.\]in  
www\[.\]4seasonrentacar\[.\]com  
www\[.\]akhtaredanesh\[.\]com  
www\[.\]arcadecreative\[.\]com  
www\[.\]armaholic\[.\]com  
www\[.\]asan-max\[.\]com  
www\[.\]autotrans\[.\]hr  
www\[.\]dafc\[.\]co\[.\]uk  
www\[.\]eapa\[.\]org  
www\[.\]elev8tor\[.\]com  
www\[.\]jdarchs\[.\]com  
www\[.\]kunkrooann\[.\]com  
www\[.\]mackellarscreenworks\[.\]com  
www\[.\]mitegen\[.\]com  
www\[.\]nigelwhitfield\[.\]com  
www\[.\]pomegranates\[.\]org  
www\[.\]ridefox\[.\]com  
www\[.\]shapingtomorrowsworld\[.\]org  
www\[.\]vanessajackson\[.\]co\[.\]uk  
www\[.\]yaran\[.\]co  
www\[.\]ztm\[.\]waw\[.\]pl  
coa\[.\]inducks\[.\]org  
mhtevents\[.\]com  
skepticalscience\[.\]com  
wallpapercase\[.\]com  
www\[.\]spearhead-training\[.\]com  
**Appendix B -- Related files**

|------------------------------------------------------------------|--------------------------------------|
| **sha256**                                                       | **Overall Description**              |
| d2a0eec18d755d456a34865ff2ffc14e3969ea77f7235ef5dfc3928972d7960f | Loader script from 144.76.109\[.\]88 |
| 1421a5cd0566f4a69e7ca9cdefa380507144d7ed59cd22e53bfd25263c201a6f | MuddyWater Macro                     |
| 4e3c7defd6f3061b0303e687a4b5b3cc2a4ae84cdc48706c65a7b1e53402efc0 | MuddyWater Macro                     |
| 8b96804d861ea690fcb61224ec27b84476cf3117222cca05e6eba955d9395deb | Lazagne                              |
| 16985600c959f6267476da614243a585b1b222213ec938351ef6a26560c992db | PS2EXE PowerStats (GitHub)           |
| cf87a2ac51503d645e827913dd69f3d80b66a58195e5a0044af23ea6ba46b823 | PS2EXE PowerStats (GitHub)           |
| 3030d80cfe1ee6986657a2d9b76b626ea05e2c289dee05bd7b9553b10d14e4a1 | Decoded PowerStats payload           |
| 99077dcb37395603db0f99823a190f50313dc4e9819462c7da29c4bc983f42fd | Lazagne Runner Script                |
| 1b60b7f9b0faf25288f1057b154413921a6cb373dcee43e831b9263c5b3077ce | MuddyWater Macro                     |
| 2c8d18f03b6624fa38cae0141b91932ba9dc1221ec5cf7f841a2f7e31685e6a1 | MuddyWater Macro                     |
| 367021beedb3ad415c69c9a0e657dc3ed82b1b24a41a71537d889f5e2b7ca433 | MuddyWater Macro                     |
| 58282917a024ac252966650361ac4cbbbed48a0df7cab7b9a6329d4a04551c0d | MuddyWater Macro                     |
| 58898648a68f0639c06bedc8242ca48bc6ec56f11ed40d00aa5fdda4e5553482 | MuddyWater Macro                     |
| 81523e0199ae1dc9e87d2b952642785bfbda6326f22e4c0794a19afdf001a9a3 | MuddyWater Macro                     |
| 90b66b3fef77962fbfda364a4f8799bfcc9ab73772026d7a8922a7cf5556a024 | MuddyWater Macro                     |
| 96101de2386e35bc5e38d32524a02c6c5ca7cc6624e656a629b2e0f1693a76fd | MuddyWater Macro                     |
| 964aaf5d9b1c749df0a2df1f1b4193e5a643893f251e2d74b47663f895da9b13 | MuddyWater Macro                     |
| 97f9a83bc6bb1b3f5cb7ac9401f95265597bff796bb4901631d6fa2c79a48bdc | MuddyWater Macro                     |
| a3c1fd46177a078c4b95c744a24103df7d0a58cee1a3be92bc4cdd7dec1b1aa5 | MuddyWater Macro                     |
| fcfbdffbcad731e0a5aad349215c87ed919865d66c287a6723fd8e2f896c5834 | MuddyWater Macro                     |
| 2bb1637c80f0a7df7260a8583beb033f4afbdd5c321ff5642bc8e1868194e009 | MuddyWater Macro                     |
| 58aec38e98aba66f9f01ca53442d160a2da7b137efbc940672982a4d8415a186 | MuddyWater Macro                     |
| 605fefc7829cfa41710e0b844084eab1f180fe513adc1d8f0f82501a154db0f4 | MuddyWater Macro                     |
| e8a832b04dbdc413b71076754c3a0bf07cb7b9b61927248c482ddca32e1dab89 | MuddyWater Macro                     |
| 5d049bd7f478ea5d978b3c78f7f0afdf294a94f526fc20ffd6e33022d40d15ae | MuddyWater Macro                     |
| 12a7898fe5c75e0b57519f1e7019b5d09f5c5cbe49c48ab91daf6fcc09ee8a30 | MuddyWater Macro                     |
| 2602e817a67949860733b3548b37792616d52ffd305405ccab0409bcfedc5d63 | MuddyWater Macro                     |
| 42a4d9527063f73004b049a093a34a4fc3b6ea9505cb9b50b895486cb2dca94b | MuddyWater Macro                     |
| 5ed5fc6c6918ff6fa4eab7742c03d59155ca87e0fe12bac339f18928e2924a96 | MuddyWater Macro                     |
| a2ad6bfc47c4f69a2170cc1a9fd620a68b1ebb474b7bdf601066e780e592222f | MuddyWater Macro                     |
| c23ece07fc5432ca200f3de3e4c4b68430c6a22199d7fab11916a8c404fb63dc | MuddyWater Macro                     |
| cb96cd26f36a3b1aacabfc79bbb5c1e0c9850b1c75c30aa498ad2d4131b02b98 | MuddyWater Macro                     |
| ed2f9c9d5554d5248a7ad9ad1017af5f1bbadbd2275689a8b019a04c516eeec2 | MuddyWater Macro                     |
| fe16543109f640ddbf3725e4d9f593de9f13ee9ae96c5e41e9cdccb7ab35b661 | MuddyWater Macro                     |
| 886e3a2f74bf8f46b23c78a6bad80c74fe33579f6fe866bc5075b034c4d5d432 | MuddyWater Macro                     |
| 8ec108b8f66567a8d84975728b2d5e6a2786c2ca368310cca55acad02bb00fa6 | MuddyWater Macro                     |
| 96d80ae577e9b899772a940b4941da39cf7399b5c852048f0d06926eb6c9868a | MuddyWater Macro                     |
| bb1a5fb87d34c63ade0ed8a8b95412ba3795fd648a97836cb5117aff8ea08423 | MuddyWater Macro                     |
| d65e2086aeab56a36896a56589e47773e9252747338c6b59c458155287363f28 | MuddyWater Macro                     |
| 588cd0fe3ae6fbd2fa4cf8de8db8ae2069ea62c9eaa6854caedf45045780661f | MuddyWater Macro                     |
| 917a6c816684f22934e2998f43633179e14dcc2e609c6931dd2fc36098c48028 | MuddyWater Macro                     |
| db7bdd6c3ff7a27bd4aa9acc17dc35c38b527fb736a17d0927a0b3d7e94acb42 | MuddyWater Macro                     |
| de6ce9b75f4523a5b235f90fa00027be5920c97a972ad6cb2311953446c81e1d | MuddyWater Macro                     |
| a6673c6d52dd5361afd96f8143b88810812daa97004f69661da625aaaba9363b | MuddyWater Macro                     |
| 40a6b4c6746e37d0c5ecb801e7656c9941f4839f94d8f4cd61eaf2b812feaabe | MuddyWater Macro                     |

**Appendix C -- Proxy URLs found from POWERSTATS samples from October 2017 onwards**  
hxxp://106\[.\]187\[.\]38\[.\]21/short\_qr/work\[.\]php?c=  
hxxp://arbiogaz\[.\]com/upload/work\[.\]php?c=  
hxxp://azmwn\[.\]suliparwarda\[.\]com/wp-content/plugins/wpdatatables/panda\[.\]php?c=  
hxxp://azmwn\[.\]suliparwarda\[.\]com/wp-content/themes/twentyfifteen/logs\[.\]php?c=  
hxxp://bangortalk\[.\]org\[.\]uk/speakers\[.\]php?c=  
hxxp://best2\[.\]thebestconference\[.\]org/ccb/browse\_cat\[.\]php?c=  
hxxp://camco\[.\]com\[.\]pk/Controls/data\[.\]aspx?c=  
hxxp://cbpexbrasilia\[.\]com\[.\]br/wp-content/plugins/wordpress-seo/power\[.\]php?c=  
hxxp://cbpexbrasilia\[.\]com\[.\]br/wp-includes/widgets/work\[.\]php?c=  
hxxp://cgss\[.\]com\[.\]pk/data\[.\]aspx?c=  
hxxp://diplomat\[.\]com\[.\]sa/wp-content/plugins/wordpress-importer/cache\[.\]php?c=  
hxxp://feribschat\[.\]eu/logs\[.\]php?c=  
hxxp://ghanaconsulate\[.\]com\[.\]pk/data\[.\]aspx?c=  
hxxp://magical-energy\[.\]com/css\[.\]aspx?c=  
hxxp://magical-energy\[.\]com/css/css\[.\]aspx?c=  
hxxp://mainandstrand\[.\]com/work\[.\]php?c=  
hxxp://riyadhfoods\[.\]com/css/edu\[.\]aspx?c=  
hxxp://riyadhfoods\[.\]com/jquery-ui/js/jquery\[.\]aspx?c=  
hxxp://school\[.\]suliparwarda\[.\]com/components/com\_akeeba/work\[.\]php?c=  
hxxp://school\[.\]suliparwarda\[.\]com/plugins/editors/codemirror/work\[.\]php?c=  
hxxp://suliparwarda\[.\]com/includes/panda\[.\]php?c=  
hxxp://suliparwarda\[.\]com/layouts/joomla/logs\[.\]php?c=  
hxxp://suliparwarda\[.\]com/wp-content/plugins/entry-views/work\[.\]php?c=  
hxxp://suliparwarda\[.\]com/wp-content/themes/twentyfifteen/work\[.\]php?c=  
hxxp://tmclub\[.\]eu/clubdata\[.\]php?c=  
hxxp://watyanagr\[.\]nfe\[.\]go\[.\]th/e-office/lib/work\[.\]php?c=  
hxxp://watyanagr\[.\]nfe\[.\]go\[.\]th/watyanagr/power\[.\]php?c=  
hxxp://whiver\[.\]in/power\[.\]php?c=  
hxxp://www\[.\]4seasonrentacar\[.\]com/viewsure/data\[.\]aspx?c=  
hxxp://www\[.\]akhtaredanesh\[.\]com/d/file/sym/work\[.\]php?c=  
hxxp://www\[.\]akhtaredanesh\[.\]com/d/oschool/power\[.\]php?c=  
hxxp://www\[.\]arcadecreative\[.\]com/work\[.\]php?c=  
hxxp://www\[.\]armaholic\[.\]com/list\[.\]php?c=  
hxxp://www\[.\]asan-max\[.\]com/files/articles/css\[.\]aspx?c=  
hxxp://www\[.\]asan-max\[.\]com/files/articles/large/css\[.\]aspx?c=  
hxxp://www\[.\]autotrans\[.\]hr/index\[.\]php?c=  
hxxp://www\[.\]dafc\[.\]co\[.\]uk/news\[.\]php?c=  
hxxp://www\[.\]eapa\[.\]org/asphalt\[.\]php?c=  
hxxp://www\[.\]elev8tor\[.\]com/show-work\[.\]php?c=  
hxxp://www\[.\]jdarchs\[.\]com/work\[.\]php?c=  
hxxp://www\[.\]kunkrooann\[.\]com/inc/work\[.\]php?c=  
hxxp://www\[.\]mackellarscreenworks\[.\]com/work\[.\]php?c=  
hxxp://www\[.\]mitegen\[.\]com/mic\_catalog\[.\]php?c=  
hxxp://www\[.\]nigelwhitfield\[.\]com/v2/work\[.\]php?c=  
hxxp://www\[.\]pomegranates\[.\]org/index\[.\]php?c=  
hxxp://www\[.\]ridefox\[.\]com/content\[.\]php?c=  
hxxp://www\[.\]shapingtomorrowsworld\[.\]org/category\[.\]php?c=  
hxxp://www\[.\]vanessajackson\[.\]co\[.\]uk/work\[.\]php?c=  
hxxp://www\[.\]yaran\[.\]co//wp-content/plugins/so-masonry/logs\[.\]php?c=  
hxxp://www\[.\]yaran\[.\]co/wp-includes/widgets/logs\[.\]php?c=  
hxxp://www\[.\]ztm\[.\]waw\[.\]pl/pop\[.\]php?c=  
hxxps://coa\[.\]inducks\[.\]org/publication\[.\]php?c=  
hxxps://mhtevents\[.\]com/account\[.\]php?c=  
hxxps://skepticalscience\[.\]com/graphics\[.\]php?c=  
hxxps://wallpapercase\[.\]com/wp-content/themes/twentyfifteen/logs\[.\]php?c=  
hxxps://wallpapercase\[.\]com/wp-includes/customize/logs\[.\]php?c=  
hxxps://www\[.\]spearhead-training\[.\]com//html/power\[.\]php?c=  
hxxps://www\[.\]spearhead-training\[.\]com/work\[.\]php?c=  
Back to top

### Tags

* [FIN7](https://unit42.paloaltonetworks.com/tag/fin7/ "FIN7")
* [Lazagne](https://unit42.paloaltonetworks.com/tag/lazagne/ "Lazagne")
* [Meterpreter](https://unit42.paloaltonetworks.com/tag/meterpreter/ "Meterpreter")
* [Mimikatz](https://unit42.paloaltonetworks.com/tag/mimikatz/ "Mimikatz")
* [MuddyWater](https://unit42.paloaltonetworks.com/tag/muddywater/ "MuddyWater")  
  [Threat Research Center](https://unit42.paloaltonetworks.com "Threat Research") [Next: Threat Brief: Why Ransomware Hurts So Much and Is So Hard to Stop](https://unit42.paloaltonetworks.com/threat-brief-ransomware-hurts-much-hard-stop/ "Threat Brief: Why Ransomware Hurts So Much and Is So Hard to Stop")

### Related Articles

* [CL-STA-1062 Targets Southeast Asian Governments and Critical Infrastructure](https://unit42.paloaltonetworks.com/cl-sta-1062-tinyrct-backdoor/ "article - table of contents")
* [Boggy Serpens Threat Assessment](https://unit42.paloaltonetworks.com/boggy-serpens-threat-assessment/ "article - table of contents")
* [Suspected China-Based Espionage Operation Against Military Targets in Southeast Asia](https://unit42.paloaltonetworks.com/espionage-campaign-against-military-targets/ "article - table of contents")

## Related Malware Resources

![Pictorial representation of a magnifying glass illuminating a glowing orange circular digital circuit interface on a dark, high-tech background.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/09/04_Myth-Busting_Overview_1920x900-786x368.jpg)  
[![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/08/Insights-icon-white.svg)Insights](https://unit42.paloaltonetworks.com/category/insights/) September 16, 2026 [#### Atomic macOS (AMOS) Stealer Activity](https://unit42.paloaltonetworks.com/atomic-macos-amos-stealer-activity/)

* [MacOS](https://unit42.paloaltonetworks.com/tag/macos/ "macOS")

* [Threat intelligence](https://unit42.paloaltonetworks.com/tag/threat-intelligence/ "threat intelligence")

* [Unit 42](https://unit42.paloaltonetworks.com/tag/unit-42/ "Unit 42")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/atomic-macos-amos-stealer-activity/ "Atomic macOS (AMOS) Stealer Activity")  
  ![Pictorial representation of post-exploitation identity misuse in SPIFFE/SPIRE. Close-up of a person wearing glasses, with computer code reflected in the lenses.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/09/12_Security-Technology_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) September 10, 2026 [#### The Machine With Many Faces: Post-Exploitation Identity Misuse in SPIFFE/SPIRE](https://unit42.paloaltonetworks.com/kubernetes-spiffe-spire-identity-spoofing/)

* [API](https://unit42.paloaltonetworks.com/tag/api/ "API")

* [Cryptographic](https://unit42.paloaltonetworks.com/tag/cryptographic/ "cryptographic")

* [JSON](https://unit42.paloaltonetworks.com/tag/json/ "JSON")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/kubernetes-spiffe-spire-identity-spoofing/ "The Machine With Many Faces: Post-Exploitation Identity Misuse in SPIFFE/SPIRE")  
  ![Pictorial representation of a pay-per-install threat group campaign prodiving infection service for spreading malware. A close-up of a computer circuit board with a central microchip is depicted. Red digital data streams in the form of glowing binary numbers and arrows appear to flow in and out of the chip, symbolizing data processing and transfer. The scene is illuminated with a futuristic blue and red glow.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/09/04_Malware_Category_1920x900-6-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) September 9, 2026 [#### Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure](https://unit42.paloaltonetworks.com/ppi-network-malware-campaign-analysis/)

* [ARKTunnel](https://unit42.paloaltonetworks.com/tag/arktunnel/ "ARKTunnel")

* [C2](https://unit42.paloaltonetworks.com/tag/c2/ "C2")

* [CL-CRI-1171](https://unit42.paloaltonetworks.com/tag/cl-cri-1171/ "CL-CRI-1171")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ppi-network-malware-campaign-analysis/ "Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure")  
  ![Pictorial representation of attackers using AI tools to target Latin American organizations. A vibrant cityscape with silhouettes of numerous people walking along a bustling street. The scene is illuminated by bright urban lights and digital-like particles, creating a dynamic and futuristic atmosphere.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/09/AdobeStock_768915868-2-1-786x373.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) September 3, 2026 [#### Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America](https://unit42.paloaltonetworks.com/ai-tool-use-targeting-latam-orgs/)

* [Agentic AI](https://unit42.paloaltonetworks.com/tag/agentic-ai/ "Agentic AI")

* [ChatGPT](https://unit42.paloaltonetworks.com/tag/chatgpt/ "ChatGPT")

* [CL-CRI-1131](https://unit42.paloaltonetworks.com/tag/cl-cri-1131/ "CL-CRI-1131")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ai-tool-use-targeting-latam-orgs/ "Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America")  
  ![Pictorial representation of vishing campaigns in Microsoft Teams. A digital image of a skull formed by blue binary code on a black background, with scattered ones and zeros and digital noise, symbolizes how stealthy prompt injection attacks can exploit AI logic to bypass security controls.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/01_Malware_Category_1920x900-5-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 31, 2026 [#### Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams](https://unit42.paloaltonetworks.com/spring-ring-voice-phishing-campaigns/)

* [Cloaked Ursa](https://unit42.paloaltonetworks.com/tag/cloaked-ursa/ "Cloaked Ursa")

* [Entra ID](https://unit42.paloaltonetworks.com/tag/entra-id/ "Entra ID")

* [Microsoft Teams](https://unit42.paloaltonetworks.com/tag/microsoft-teams/ "Microsoft Teams")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/spring-ring-voice-phishing-campaigns/ "Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams")  
  ![Pictorial representation of AI-enabled malware. A vibrant digital interface displaying various icons and graphs, resembling a futuristic network or data analysis dashboard. The scene is illuminated with glowing lights and patterns.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/AdobeStock_1270203474-2-1-786x368.png)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 25, 2026 [#### The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution](https://unit42.paloaltonetworks.com/ai-enabled-malware-analysis/)

* [Backdoor](https://unit42.paloaltonetworks.com/tag/backdoor/ "backdoor")

* [Bitcoin](https://unit42.paloaltonetworks.com/tag/bitcoin/ "Bitcoin")

* [DLL hijacking](https://unit42.paloaltonetworks.com/tag/dll-hijacking/ "DLL hijacking")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ai-enabled-malware-analysis/ "The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution")  
  ![Pictorial representation of identity abuse through trusted communication channels. Close-up view of a digital screen displaying a glitched and pixelated image of a skull-like shape.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/02_Malware_Category_1920x900-2-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 20, 2026 [#### Identity Abuse Through Trusted Communication Channels](https://unit42.paloaltonetworks.com/communication-channel-identity-risks/)

* [Authentication](https://unit42.paloaltonetworks.com/tag/authentication/ "authentication")

* [Identity theft](https://unit42.paloaltonetworks.com/tag/identity-theft/ "identity theft")

* [Malware](https://unit42.paloaltonetworks.com/tag/malware/ "malware")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/communication-channel-identity-risks/ "Identity Abuse Through Trusted Communication Channels")  
  ![Pictorial representation of Kimwolf botnet malware family. Digital screen with a warning sign reading "Malware." The background features lines of computer code and graphics, creating a sense of cybersecurity threat.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/07_Malware_Category_1920x900-3-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 11, 2026 [#### Kimwolf v7: An Evolution of the Kimwolf Botnet](https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/)

* [Android APK](https://unit42.paloaltonetworks.com/tag/android-apk/ "Android APK")

* [Ethereum](https://unit42.paloaltonetworks.com/tag/ethereum/ "Ethereum")

* [HTTP](https://unit42.paloaltonetworks.com/tag/http/ "HTTP")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/ "Kimwolf v7: An Evolution of the Kimwolf Botnet")  
  ![Pictorial representatiom pf Aeternum's blockchain C2. A close-up of a computer circuit board with a central microchip is depicted. Red digital data streams in the form of glowing binary numbers and arrows appear to flow in and out of the chip. The scene is illuminated with a futuristic blue and red glow.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/04_Malware_Category_1920x900-4-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 10, 2026 [#### The Permanent Threat: Analyzing Aeternum's Blockchain-Based C2 Operations and Communications](https://unit42.paloaltonetworks.com/aeternum-blockchain-c2-analysis/)

* [Aeternum](https://unit42.paloaltonetworks.com/tag/aeternum/ "Aeternum")

* [Infection chain](https://unit42.paloaltonetworks.com/tag/infection-chain/ "infection chain")

* [JSON](https://unit42.paloaltonetworks.com/tag/json/ "JSON")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/aeternum-blockchain-c2-analysis/ "The Permanent Threat: Analyzing Aeternum’s Blockchain-Based C2 Operations and Communications")  
  ![Pictorial representation of ChainDrop, a self-propagating npm worm. An artistic depiction of a digital workspace featuring an open laptop with a red virus on the screen.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/03_Malware_Category_1920x900-7-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)High Profile Threats](https://unit42.paloaltonetworks.com/category/top-cyberthreats/) August 6, 2026 [#### ChainDrop: Inside a Self-Propagating npm Worm](https://unit42.paloaltonetworks.com/chaindrop-npm-worm-analysis/)

* [Blockchain](https://unit42.paloaltonetworks.com/tag/blockchain/ "blockchain")

* [ChainDrop](https://unit42.paloaltonetworks.com/tag/chaindrop/ "ChainDrop")

* [Claude code](https://unit42.paloaltonetworks.com/tag/claude-code/ "Claude code")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/chaindrop-npm-worm-analysis/ "ChainDrop: Inside a Self-Propagating npm Worm")

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)  
  ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg) ![Enlarged Image]()  
  ![Newsletter](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/unit42-footer-subscribe-desktop.png)  
  ![UNIT 42 Small Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/palo-alto-logo-small.svg) Get updates from Unit 42

## Peace of mind comes from staying ahead of threats. Subscribe today.

Your Email

Subscribe for email updates to all Unit 42 threat research.  
By submitting this form, you agree to our [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use "Terms of Use") and acknowledge our [Privacy Statement.](https://www.paloaltonetworks.com/legal-notices/privacy "Privacy Statement")

This site is protected by reCAPTCHA and the Google [Privacy Policy](https://policies.google.com/privacy) and [Terms of Service](https://policies.google.com/terms) apply.

Invalid captcha!
Subscribe ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg) ![loader](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-loader.svg)  
{#footer} Products and Services

* [AI-Powered Network Security Platform](https://www.paloaltonetworks.com/network-security)

* [Secure AI by Design](https://www.paloaltonetworks.com/ai-security)

* [Prisma AIRS](https://www.paloaltonetworks.com/ai-security/prisma-airs)

* [AI Access Security](https://www.paloaltonetworks.com/sase/ai-access-security)

* [Cloud Delivered Security Services](https://www.paloaltonetworks.com/network-security/security-subscriptions)

* [Advanced Threat Prevention](https://www.paloaltonetworks.com/network-security/advanced-threat-prevention)

* [Advanced URL Filtering](https://www.paloaltonetworks.com/network-security/advanced-url-filtering)

* [Advanced WildFire](https://www.paloaltonetworks.com/network-security/advanced-wildfire)

* [Advanced DNS Security](https://www.paloaltonetworks.com/network-security/advanced-dns-security)

* [Enterprise Data Loss Prevention](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention)

* [Enterprise IoT Security](https://www.paloaltonetworks.com/network-security/enterprise-device-security)

* [Medical IoT Security](https://www.paloaltonetworks.com/network-security/medical-device-security)

* [Industrial OT Security](https://www.paloaltonetworks.com/network-security/ot-security-solution)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security)

* [Next-Generation Firewalls](https://www.paloaltonetworks.com/network-security/next-generation-firewall)

* [Hardware Firewalls](https://www.paloaltonetworks.com/network-security/hardware-firewall-innovations)

* [Software Firewalls](https://www.paloaltonetworks.com/network-security/software-firewalls)

* [Strata Cloud Manager](https://www.paloaltonetworks.com/network-security/strata-cloud-manager)

* [SD-WAN for NGFW](https://www.paloaltonetworks.com/network-security/sd-wan-subscription)

* [PAN-OS](https://www.paloaltonetworks.com/network-security/pan-os)

* [Panorama](https://www.paloaltonetworks.com/network-security/panorama)

* [Secure Access Service Edge](https://www.paloaltonetworks.com/sase)

* [Prisma SASE](https://www.paloaltonetworks.com/sase)

* [Application Acceleration](https://www.paloaltonetworks.com/sase/app-acceleration)

* [Autonomous Digital Experience Management](https://www.paloaltonetworks.com/sase/adem)

* [Enterprise DLP](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention)

* [Prisma Access](https://www.paloaltonetworks.com/sase/access)

* [Prisma Browser](https://www.paloaltonetworks.com/sase/prisma-browser)

* [Prisma SD-WAN](https://www.paloaltonetworks.com/sase/sd-wan)

* [Remote Browser Isolation](https://www.paloaltonetworks.com/sase/remote-browser-isolation)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security)

* [AI-Driven Security Operations Platform](https://www.paloaltonetworks.com/cortex)

* [Cloud Security](https://www.paloaltonetworks.com/cortex/cloud)

* [Cortex Cloud](https://www.paloaltonetworks.com/cortex/cloud)

* [Application Security](https://www.paloaltonetworks.com/cortex/cloud/application-security)

* [Cloud Posture Security](https://www.paloaltonetworks.com/cortex/cloud/cloud-posture-security)

* [Cloud Runtime Security](https://www.paloaltonetworks.com/cortex/cloud/runtime-security)

* [Prisma Cloud](https://www.paloaltonetworks.com/prisma/cloud)

* [AI-Driven SOC](https://www.paloaltonetworks.com/cortex)

* [Cortex XSIAM](https://www.paloaltonetworks.com/cortex/cortex-xsiam)

* [Cortex XDR](https://www.paloaltonetworks.com/cortex/cortex-xdr)

* [Cortex XSOAR](https://www.paloaltonetworks.com/cortex/cortex-xsoar)

* [Cortex Xpanse](https://www.paloaltonetworks.com/cortex/cortex-xpanse)

* [Unit 42 Managed Detection \& Response](https://www.paloaltonetworks.com/content/pan/en_US/cortex/managed-detection-and-response)

* [Managed XSIAM](https://www.paloaltonetworks.com/cortex/managed-xsiam)

* [Next-Generation Identity Security](https://www.paloaltonetworks.com/idira)

* [Privileged Access Management](https://www.paloaltonetworks.com/idira/human/privileged-access-management)

* [Identity and Access Management](https://www.paloaltonetworks.com/idira/human/identity-and-access-management)

* [Endpoint Privilege Manager](https://www.paloaltonetworks.com/idira/human/endpoint-privilege-manager)

* [Identity Governance](https://www.paloaltonetworks.com/idira/human/identity-governance)

* [Workforce Password Management](https://www.paloaltonetworks.com/idira/human/workforce-password-management)

* [Agentic Identities](https://www.paloaltonetworks.com/idira/agentic)

* [Secrets Management](https://www.paloaltonetworks.com/idira/machine/secrets-management)

* [Unified Secrets Governance](https://www.paloaltonetworks.com/idira/machine/unified-secrets-governance)

* [Application Credentials Delivery](https://www.paloaltonetworks.com/idira/machine/application-credentials-delivery)

* [Vendor Privileged Access](https://www.paloaltonetworks.com/idira/human/vendor-privileged-access)

* [Threat Intel and Incident Response Services](https://www.paloaltonetworks.com/unit42)

* [Prepare for Emerging Risks](https://www.paloaltonetworks.com/unit42/frontier-ai-defense)

* [Strengthen Your Defenses](https://www.paloaltonetworks.com/unit42/strengthen-your-defenses)

* [Build Your Security Strategy](https://www.paloaltonetworks.com/unit42/build-your-security-strategy)

* [Understand the Adversary](https://www.paloaltonetworks.com/unit42/threat-intelligence)

* [Respond to a Cyber Attack](https://www.paloaltonetworks.com/unit42/respond)  
  Company

* [About Us](https://www.paloaltonetworks.com/about-us)

* [Careers](https://jobs.paloaltonetworks.com/en/)

* [Contact Us](https://www.paloaltonetworks.com/company/contact-sales)

* [Corporate Responsibility](https://www.paloaltonetworks.com/about-us/corporate-responsibility)

* [Customers](https://www.paloaltonetworks.com/customers)

* [Investor Relations](https://investors.paloaltonetworks.com/)

* [Location](https://www.paloaltonetworks.com/about-us/locations)

* [Newsroom](https://www.paloaltonetworks.com/company/newsroom)  
  Popular Links

* [Blog](https://www.paloaltonetworks.com/blog/)

* [Communities](https://www.paloaltonetworks.com/communities)

* [Content Library](https://www.paloaltonetworks.com/resources)

* [Cyberpedia](https://www.paloaltonetworks.com/cyberpedia)

* [Event Center](https://events.paloaltonetworks.com/)

* [Manage Email Preferences](https://start.paloaltonetworks.com/preference-center)

* [Products A-Z](https://www.paloaltonetworks.com/products/products-a-z)

* [Product Certifications](https://www.paloaltonetworks.com/legal-notices/trust-center/certifications)

* [Report a Vulnerability](https://www.paloaltonetworks.com/security-disclosure)

* [Sitemap](https://www.paloaltonetworks.com/sitemap)

* [Tech Docs](https://docs.paloaltonetworks.com/)

* [Unit 42](https://unit42.paloaltonetworks.com/)

* [Do Not Sell or Share My Personal Information](https://panwedd.exterro.net/portal/dsar.htm?target=panwedd)
  ![Palo Alto Networks Logo](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/pan-logo-dark.svg)

* [Privacy](https://www.paloaltonetworks.com/legal-notices/privacy)

* [Trust Center](https://www.paloaltonetworks.com/legal-notices/trust-center)

* [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use)

* [Documents](https://www.paloaltonetworks.com/legal)

Copyright © 2026 Palo Alto Networks. All Rights Reserved

* [![Youtube](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/youtube-black.svg)](https://www.youtube.com/user/paloaltonetworks)
* [![Podcast](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/icons/podcast.svg)](https://www.paloaltonetworks.com/podcasts/threat-vector)
* [![Facebook](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/facebook-black.svg)](https://www.facebook.com/PaloAltoNetworks/)
* [![LinkedIn](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/linkedin-black.svg)](https://www.linkedin.com/company/palo-alto-networks)
* [![Twitter](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/twitter-x-black.svg)](https://twitter.com/PaloAltoNtwks)
* EN  
  Select your language  
  ![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg) ![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg) ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg)

### Default Heading

Read the article ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg)  
Seekbar

![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg)  
![Volume](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-volume.svg)  
Volume
![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg)
