[![Logo](https://www.paloaltonetworks.com/wp-content/uploads/2021/07/PANW_Parent.png)](https://www.paloaltonetworks.com/)  
[![Unit42 Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/unit42-logo-white.svg)](https://unit42.paloaltonetworks.com/)  
Menu

* [Tools](https://unit42.paloaltonetworks.com/tools/)
* [ATOMs](https://unit42.paloaltonetworks.com/atoms/)
* [Security Consulting](https://www.paloaltonetworks.com/unit42)
* [About Us](https://unit42.paloaltonetworks.com/about-unit-42/)
* [**Under Attack?**](https://start.paloaltonetworks.com/contact-unit42.html)  
  English
* [English](https://unit42.paloaltonetworks.com/unit42-rig-ek-one-year-later-from-ransomware-to-coin-miners-and-information-stealers/)
* [Japanese](https://unit42.paloaltonetworks.com/ja/unit42-rig-ek-one-year-later-from-ransomware-to-coin-miners-and-information-stealers/)
* [Threat Research Center](https://unit42.paloaltonetworks.com "Threat Research")
* [Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/ "Threat Research")
* [Malware](https://unit42.paloaltonetworks.com/category/malware/ "Malware")  
  [Malware](https://unit42.paloaltonetworks.com/category/malware/)

# Rig EK One Year Later: From Ransomware to Coin Miners and Information Stealers

![Clock Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-clock.svg) 7 min read  
Related Products  
[![Advanced Threat Prevention icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Advanced Threat Prevention](https://unit42.paloaltonetworks.com/product-category/advanced-threat-prevention/ "Advanced Threat Prevention")[![Advanced URL Filtering icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Advanced URL Filtering](https://unit42.paloaltonetworks.com/product-category/advanced-url-filtering/ "Advanced URL Filtering")[![Next-Generation Firewall icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Next-Generation Firewall](https://unit42.paloaltonetworks.com/product-category/next-generation-firewall/ "Next-Generation Firewall")

* ![Profile Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-profile-grey.svg)  
  By:
  
  * [Brad Duncan](https://unit42.paloaltonetworks.com/author/brad-duncan/)

* ![Published Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-calendar-grey.svg)  
  Published:February 26, 2018

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-category.svg)  
  Categories:
  
  * [Cybercrime](https://unit42.paloaltonetworks.com/category/cybercrime/)
  * [Malware](https://unit42.paloaltonetworks.com/category/malware/)
  * [Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/)

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-tags-grey.svg)  
  Tags:
  
  * [Cryptocurrency mining](https://unit42.paloaltonetworks.com/tag/cryptocurrency-mining/)
  * [Information stealer](https://unit42.paloaltonetworks.com/tag/information-stealer/)
  * [Rig Exploit Kit](https://unit42.paloaltonetworks.com/tag/rig-exploit-kit/)

* [![Download Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-download.svg)](https://unit42.paloaltonetworks.com/unit42-rig-ek-one-year-later-from-ransomware-to-coin-miners-and-information-stealers/?pdf=download&lg=en&_wpnonce=40dbae5d0f "Click here to download")

* [![Print Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-print.svg)](https://unit42.paloaltonetworks.com/unit42-rig-ek-one-year-later-from-ransomware-to-coin-miners-and-information-stealers/?pdf=print&lg=en&_wpnonce=40dbae5d0f "Click here to print")

Share![Down arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/down-arrow.svg)

* ![Link Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-share-link.svg)
* [![Link Email](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-sms.svg)](mailto:?subject=Rig%20EK%20One%20Year%20Later:%20From%20Ransomware%20to%20Coin%20Miners%20and%20Information%20Stealers&body=Check%20out%20this%20article%20https%3A%2F%2Funit42.paloaltonetworks.com%2Funit42-rig-ek-one-year-later-from-ransomware-to-coin-miners-and-information-stealers%2F "Share in email")
* [![Facebook Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-fb-share.svg)](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Funit42.paloaltonetworks.com%2Funit42-rig-ek-one-year-later-from-ransomware-to-coin-miners-and-information-stealers%2F "Share in Facebook")
* [![LinkedIn Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-linkedin-share.svg)](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Funit42-rig-ek-one-year-later-from-ransomware-to-coin-miners-and-information-stealers%2F&title=Rig%20EK%20One%20Year%20Later:%20From%20Ransomware%20to%20Coin%20Miners%20and%20Information%20Stealers "Share in LinkedIn")
* [![Twitter Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-twitter-share.svg)](https://twitter.com/intent/tweet?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Funit42-rig-ek-one-year-later-from-ransomware-to-coin-miners-and-information-stealers%2F&text=Rig%20EK%20One%20Year%20Later:%20From%20Ransomware%20to%20Coin%20Miners%20and%20Information%20Stealers "Share in Twitter")
* [![Reddit Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-reddit-share.svg)](https://www.paloaltonetworks.com//www.reddit.com/submit?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Funit42-rig-ek-one-year-later-from-ransomware-to-coin-miners-and-information-stealers%2F&ts=markdown "Share in Reddit")
* [![Mastodon Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-mastodon-share.svg)](https://mastodon.social/share?text=Rig%20EK%20One%20Year%20Later:%20From%20Ransomware%20to%20Coin%20Miners%20and%20Information%20Stealers%20https%3A%2F%2Funit42.paloaltonetworks.com%2Funit42-rig-ek-one-year-later-from-ransomware-to-coin-miners-and-information-stealers%2F "Share in Mastodon")
  What a difference a year makes! As the dominant exploit kit (EK) in our current threat landscape, [Rig EK](https://blog.paloaltonetworks.com/tag/rig-exploit-kit/) has gone through significant changes. How much has Rig EK changed? In order to find out, we compared activity levels, malware payloads, and network traffic characteristics from January of 2017 with January of 2018. The contrast is striking.

Activity Levels: A Dramatic Drop  
Since 2017, Rig EK has remained the most significant player in the EK market, and it still accounts for the vast majority of EK traffic we currently discover. However, overall EK activity dramatically declined during 2017. We already reported a [significant decline in Rig EK](https://blog.paloaltonetworks.com/2017/06/unit42-decline-rig-exploit-kit/) that began in April 2017. By the fourth quarter of 2017, [overall EK activity levels fell even further](https://www.proofpoint.com/sites/default/files/pfpt-us-tr-q417-threat-report-180117.pdf), declining 31 percent from the previous quarter.  
But how dramatic is the change from January 2017 compared with January 2018?  
An easy way to gauge Rig EK activity is to search [AutoFocus](https://www.paloaltonetworks.com/products/secure-the-network/subscriptions/autofocus) for items tagged [RigEKFlashContainer](https://autofocus.paloaltonetworks.com/#/tag/Unit42.RigEKFlashContainer) seen through web traffic over port 80. In this search we omitted various anomalies such as results associated with malware samples submitted to places like VirusTotal or VirusSign. Using these criteria, we compared January of 2017 with January of 2018. For January 2017, we verified 812 sessions with hits on RigEKFlashContainer. In January 2018, using the same search criteria, we found only 65 sessions. That represents a 92 percent decrease in Rig EK from January 2017 to January 2018.

![RigEK1](https://unit42.paloaltonetworks.com/wp-content/uploads/2018/02/RigEK1.png) *Figure 1: Hits on Rig EK in January 2017 versus January 2018.*

We have [already discussed some reasons](https://blog.paloaltonetworks.com/2017/06/unit42-decline-rig-exploit-kit/) for this decline. Ultimately, the aftermath of criminal arrests combined with on-going vendor efforts to fortify browsers and browser-based applications have resulted in [a cumulative effect devastating to EK developers](https://threatpost.com/where-have-all-the-exploit-kits-gone/124241/). Criminal groups have shifted their efforts to other types of exploits [like those targeting Microsoft Office vulnerabilities](https://securingtomorrow.mcafee.com/mcafee-labs/analyzing-microsoft-office-zero-day-exploit-cve-2017-11826-memory-corruption-vulnerability/). And criminals have also turned their focus to social engineering schemes.  
**Payloads: From Ransomware to Coin Miners \& Info Stealers** In January of 2017, Rig EK was primarily used to send different types of ransomware. The [Afraidgate](https://blog.paloaltonetworks.com/2016/04/afraidgate-major-exploit-kit-campaign-swaps-locky-ransomware-for-cryptxxx/) campaign used Rig EK to distribute Locky ransomware. The [EITest](https://blog.paloaltonetworks.com/2016/10/unit42-eitest-campaign-evolution-angler-ek-neutrino-rig/) campaign used Rig EK to distribute CrytoMix, CryptoShield and Spora ransomware. The [pseudo-Darkleech](https://blog.paloaltonetworks.com/2016/03/unit42-campaign-evolution-darkleech-to-pseudo-darkleech-and-beyond/) campaign used Rig EK to distribute Cerber ransomware. [Appendix A](#appendixa) lists 39 reports documenting Rig EK used by various campaigns. 36 of these examples involve ransomware (the other three were Dreambot, Madness DDoS botnet malware, and NanoCore RAT).  
How dramatic is the change in payloads distributed through Rig EK in January 2018 compared to January 2017? In general terms, ransomware is nearly out, while cryptocurrency miners (coin miners) and information stealers are in.  
None of the ransomware we saw being distributed using Rig EK in January 2017 was being distributed in 2018. Cerber, CryptoMix, CryptoShield, Locky, and Spora are no longer active. In some cases, their development has forked into newer variants now distributed on a much smaller scale, such as a Cerber variant called [Mangiber](https://www.bleepingcomputer.com/news/security/goodbye-cerber-hello-magniber-ransomware/).  
Similarly, none of the campaigns we saw pushing ransomware in January 2017 were doing so in January 2018. The Afraidgate and pseudo-Darkleech campaigns [disappeared by May 2017](https://blog.paloaltonetworks.com/2017/06/unit42-decline-rig-exploit-kit/). Criminals behind the EITest campaign are still active, but they stopped using Rig EK and have turned to social engineering methods like fake browser plugins and tech support scams.  
In January 2018, Rig EK was used by at least three identifiable campaigns: [Fobos](https://malwarebreakdown.com/2017/08/16/fobos-campaign-using-rig-ek-to-drop-bunitu-trojan/), [Ngay](https://www.nao-sec.org/2017/12/survey-of-ngay-campaign.html), and [Seamless](https://umbrella.cisco.com/blog/2017/03/29/seamless-campaign-delivers-ramnit-via-rig-ek/).  
Fobos has used Rig EK to distribute the [Bunitu proxy Trojan](https://blog.malwarebytes.com/threat-analysis/2015/07/revisiting-the-bunitu-trojan/). Ngay has distributed coin miners and information stealing malware. Seamless has mainly distributed an information stealing Trojan named Ramnit.  
Researchers have [already reported](https://blog.malwarebytes.com/threat-analysis/2018/01/rig-exploit-kit-campaign-gets-deep-into-crypto-craze/) the Ngay campaign distributing coin mining malware using Rig EK, but we have also seen Ngay using Rig EK to distribute the Remcos remote access tool (RAT). Ngay was [first documented in December 2017](https://www.nao-sec.org/2017/12/survey-of-ngay-campaign.html). Since that time, it pushed Monero (XMR) coin mining malware. However, by January 19th, [Ngay was pushing the Remcos remote access tool (RAT)](https://malware-traffic-analysis.net/2018/01/19/index.html). Remcos RAT also has a keylogging component that steals information.  
Except for four days in January 2018, Seamless continued to push the Ramnit banking Trojan, and the campaign has been using Rig EK to distribute Ramnit [since March 2017](https://umbrella.cisco.com/blog/2017/03/29/seamless-campaign-delivers-ramnit-via-rig-ek/). Ramnit is a banking Trojan [that also behaves like an information stealer](https://www.bleepingcomputer.com/news/security/malvertising-campaign-on-adult-sites-spreads-ramnit-trojan/) by retrieving passwords from browsers and other applications on the infected Windows host.  
One small anomaly we saw with the Seamless campaign in January 2018 was from the 26th through the 29th. During that four day window, Seamless used Rig EK to push [GandCrab ransomware](https://www.scmagazineuk.com/gandcrab-blends-old-and-new-threat-resources-as-ransomware-evolves/article/741017/), then it went back to pushing Ramnit.  
Unfortunately, due to the way Rig EK encrypts its payload, we cannot use AutoFocus to identify Rig EK payloads. [Appendix B](#appendixb) lists 20 publicly-available reports in January 2018 that document Rig EK used by various campaigns to push information stealers like Ramnit and Remcos RAT, coin miners, and GandCrab ransomware.  
The most interesting aspect of Rig EK payloads is the rise of coin mining malware. While we cannot use AutoFocus to find Rig EK payloads, we can certainly use it to find various coin mining malware. Using AutoFocus to search for various coin miners in January 2017 returned 2,368 unique samples. For January 2018, AutoFocus shows 65,512 samples using the same search criteria. That represents a 2,766 percent increase in coin miner samples from January 2017 to January 2018.

![RigEK2](https://unit42.paloaltonetworks.com/wp-content/uploads/2018/02/RigEK2.png) *Figure 2: Coin miner samples in January 2017 versus January 2018.*

This dramatic increase in coin mining malware is reflected in public reporting of Rig EK, and we expect to see more coin mining malware as 2018 progresses.

**Network Traffic: From Domains to IPs** In January 2017, Rig EK continued its well-established practice of domain shadowing for servers hosting the EK. Domain shadowing is used to frequently change domain names in an effort to avoid detection. However, in January 2018, Rig EK no longer uses domain names. Instead, it uses IP addresses to identify it EK servers, a practice that started in June 2017 in response to a coordinated effort [documented by RSA Research](https://www.rsa.com/en-us/blog/2017-06/shadowfall) that took down the associated domain shadowing infrastructure.  
What else is different with Rig EK network traffic?  
Other than IP addresses instead of domain names, Rig EK traffic is relatively unchanged a year later. The URL patterns are somewhat changed, but still recognizably Rig EK. In January 2017, Rig EK URL patterns contained recognizable English words. In January 2018, these English words have been replaced with Base64-encoded strings. See the images below for examples.  
![RigEK3](https://unit42.paloaltonetworks.com/wp-content/uploads/2018/02/RigEK3.png)

*Figure 3: Example of URLs from Rig EK in January 2017.*

![RigEK4](https://unit42.paloaltonetworks.com/wp-content/uploads/2018/02/RigEK4.png)

*Figure 4: Example of URLs from Rig EK in January 2018.*

These URL pattern changes indicate Rig EK is still trying to avoid detection. However, the loss of its domain shadowing infrastructure makes Rig EK at least as identifiable now as it was a year ago.

Conclusion  
When we compare Rig EK in January 2017 with Rig EK in January 2018, the contrast is indeed striking. Rig EK is now distributing a much different selection of malware. Campaigns using Rig EK have mostly forsaken ransomware and now focus more on coin miners. Rig EK is still readily recognizable, but it is a much-reduced presence in our current threat landscape.  
Palo Alto Networks customers remain protected from this threat. Our threat prevention platform applies IP signatures that easily detect current Rig EK URL patterns and enforce protections as necessary. [AutoFocus](https://www.paloaltonetworks.com/products/secure-the-network/subscriptions/autofocus) users can track detected Rig EK activity using the [RigEKFlashContainer](https://autofocus.paloaltonetworks.com/#/tag/Unit42.RigEKFlashContainer) tag.  
We will continue to investigate this activity for applicable indicators to further inform the community and enhance our threat prevention platform.

Appendix A

Rig EK examples in January 2017:  
2017-01-01 - [pseudo-Darkleech campaign Rig EK sends Cerber ransomware](https://malware-traffic-analysis.net/2017/01/01/index.html)  
2017-01-02 - [pseudo-Darkleech campaign Rig EK sends Cerber ransomware](https://malware-traffic-analysis.net/2017/01/02/index.html)  
2017-01-03 - [pseudo-Darkleech campaign Rig EK sends Cerber ransomware](https://malware-traffic-analysis.net/2017/01/03/index2.html)  
2017-01-04 - [pseudo-Darkleech campaign Rig EK sends Cerber ransomware](https://malware-traffic-analysis.net/2017/01/04/index.html)  
2017-01-05 - [pseudo-Darkleech campaign Rig EK sends Cerber ransomware](https://malware-traffic-analysis.net/2017/01/05/index.html)  
2017-01-06 - [pseudo-Darkleech campaign Rig EK sends Cerber ransomware](https://malware-traffic-analysis.net/2017/01/06/index.html)  
2017-01-09 - [pseudo-Darkleech campaign Rig EK sends Cerber ransomware](https://malware-traffic-analysis.net/2017/01/09/index3.html)  
2017-01-09 - [unspecified campaign Rig EK sends NanoCore RAT and other malware](https://malwarebreakdown.com/2017/01/09/bosstds-redirected-host-to-rig-v-exploit-kit-at-92-53-120-207/)  
2017-01-10 - [EITest campaign Rig EK sends CryptoMix ransomware](https://malware-traffic-analysis.net/2017/01/10/index.html)  
2017-01-11 - [pseudo-Darkleech campaign sends Cerber ransomware and EITest campaign Rig EK sends CryptoMix ransomware](https://malware-traffic-analysis.net/2017/01/11/index2.html)  
2017-01-12 - [EITest campaign Rig EK sends CryptoMix ransomware](https://malware-traffic-analysis.net/2017/01/12/index.html)  
2017-01-12 - [pseudo-Darkleech campaign Rig EK sends Cerber ransomware](https://www.broadanalysis.com/2017/01/12/rig-v-exploit-kit-via-pseudodarkleech-from-81-177-139-122-delivers-cerber-ransomware/)  
2017-01-13 [- EITest campaign Rig EK sends CryptoMix ransomware](https://malware-traffic-analysis.net/2017/01/13/index.html)  
2017-01-13 - [pseudo-Darkleech campaign Rig EK sends Cerber ransomware](https://malware-traffic-analysis.net/2017/01/13/index2.html)  
2017-01-13 - [Afraidgate campaign Rig EK sends Locky ransomware](https://malware-traffic-analysis.net/2017/01/13/index3.html)  
2017-01-14 - [Afraidgate campaign Rig EK sends Godzilla loader for Locky ransomware](https://malwarebreakdown.com/2017/01/14/afraidgate-at-178-62-242-179-leads-to-rig-v-ek-at-92-53-120-233-downloader-drops-locky-ransomware-osiris/)  
2017-01-15 - [EITest campaign Rig EK sends CryptoMix ransomware](https://malwarebreakdown.com/2017/01/15/eitest-leads-to-rig-v-ek-at-92-53-120-233-drops-cryptomix/)  
2017-01-15 - [pseudo-Darkleech campaign Rig EK sends Cerber ransomware](https://zerophagemalware.com/2017/01/19/rig-v-via-pseudodarkleech-delivers-cerber/)  
2017-01-17 - [EITest campaign Rig EK sends Spora ransomware](https://malware-traffic-analysis.net/2017/01/17/index2.html)  
2017-01-18 - [pseudo-Darkleech campaign Rig EK sends Madness DDoS botnet malware](https://malware-traffic-analysis.net/2017/01/18/index.html)  
2017-01-18 - [pseudo-Darkleech campaign Rig EK sends Cerber ransomware](https://malware-traffic-analysis.net/2017/01/18/index2.html)  
2017-01-19 - [EITest campaign Rig EK sends Cerber ransomware](https://malware-traffic-analysis.net/2017/01/19/index.html)  
2017-01-19 - [pseudo-Darkleech campaign Rig EK sends Cerber ransomware](https://malware-traffic-analysis.net/2017/01/19/index2.html)  
2017-01-19 - [pseudo-Darkleech campaign Rig EK sends Cerber ransomware](https://zerophagemalware.com/2017/01/19/rig-v-via-pseudodarkleech-delivers-cerber/)  
2017-01-20 - [EITest campaign Rig EK sends Cerber ransomware](https://malware-traffic-analysis.net/2017/01/20/index.html)  
2017-01-21 - [unspecified campaign Rig EK sends Spora ransomware](https://malwarebreakdown.com/2017/01/21/iframe-points-to-rig-v-ek-at-93-158-215-169-ek-drops-spora-ransomware/)  
2017-01-22 - [pseudo-Darkleech campaign Rig EK sends Cerber ransomware](https://www.broadanalysis.com/2017/01/22/rig-v-exploit-kit-via-pseudodarkleech-from-109-234-35-244-delivers-cerber-ransomware/)  
2017-01-23 - [EITest campaign Rig EK sends CryptoMix ransomware](https://malware-traffic-analysis.net/2017/01/23/index.html)  
2017-01-24 - [pseudo-Darkleech campaign Rig EK sends Cerber ransomware](https://malware-traffic-analysis.net/2017/01/24/index.html)  
2017-01-24 - [EITest campaign Rig EK sends CryptoMix ransomware](https://malware-traffic-analysis.net/2017/01/24/index2.html)  
2017-01-25 - [pseudo-Darkleech campaign Rig EK sends Cerber ransomware](https://zerophagemalware.com/2017/01/25/rig-v-via-pseudodarkleech-delivers-cerber-2/)  
2017-01-26 - [Afraidgate campaign Rig EK sends Godzilla Loader and Locky ransomware](https://malware-traffic-analysis.net/2017/01/26/index.html)  
2017-01-26 - [pseudo-Darkleech campaign Rig EK sends Cerber ransomware](https://malware-traffic-analysis.net/2017/01/26/index2.html)  
2017-01-27 - [Afraidgate campaign Rig EK sends Locky ransomware or Madness DDos botnet malware](https://malware-traffic-analysis.net/2017/01/27/index2.html)  
2017-01-29 - [unspecified campaign Rig EK sends Dreambot](https://malwarebreakdown.com/2017/01/29/rig-v-at-194-87-144-170-post-infection-traffic-triggers-et-rules-for-tor-module-download-and-ursnif-variant-cnc-beacon/)  
2017-01-30 - [Afraidgate campaign Rig EK sends Locky ransomware](https://malware-traffic-analysis.net/2017/01/30/index.html)  
2017-01-30 - [pseudo-Darkleech campaign Rig EK sends Cerber ransomware](https://zerophagemalware.com/2017/01/30/rig-via-pseudodarkleech-delivers-cerber-ransomware/)  
2017-01-31 - [EITest campaign Rig EK sends CryptoShield ransomware (update to CryptoMix ransomware)](https://malware-traffic-analysis.net/2017/01/31/index2.html)  
2017-01-31 - [EITest campaign Rig EK sends CryptoShield ransomware](https://www.broadanalysis.com/2017/01/31/rig-exploit-kit-via-the-eitest-delivers-cryptoshield-ransomware/)

Appendix B

Rig EK examples in January 2018:  
2018-01-01 - [Seamless campaign Rig EK sends Ramnit banking Trojan](https://twitter.com/nao_sec/status/947831499021099010)  
2018-01-09 - [Rig EK campaign gets deep into crypto craze](https://blog.malwarebytes.com/threat-analysis/2018/01/rig-exploit-kit-campaign-gets-deep-into-crypto-craze/)  
2018-01-09 [- Seamless campaign Rig EK sends Ramnit banking Trojan](https://twitter.com/nao_sec/status/949660753228742657)  
2018-01-09 - [Ngay campaign Rig EK sends Smoke Loader for Monero coin miner](https://twitter.com/nao_sec/status/950690187272634369)  
2018-01-09 - [Seamless campaign Rig EK sends Ramnit banking Trojan](https://traffic.moe/2018/01/09/index.html)  
2018-01-09 - [Seamless campaign Rig EK sends Ramnit banking Trojan](https://malware-traffic-analysis.net/2018/01/09/index2.html)  
2018-01-11 - [Ngay campaign Rig EK sends Smoke Loader for Monero coin miner](https://malware-traffic-analysis.net/2018/01/11/index.html)  
2018-01-12 [- Ngay campaign Rig EK sends Smoke Loader for Monero coin miner](https://malware-traffic-analysis.net/2018/01/19/index.html)  
2018-01-14 - [Ngay campaign Rig EK sends Monero coin miner](https://malware-traffic-analysis.net/2018/01/19/index.html)  
2018-01-14 - [Seamless campaign Rig EK sends Ramnit banking Trojan](https://twitter.com/nao_sec/status/952561329885163520)  
2018-01-15 - [Ngay campaign Rig EK sends Monero coin miner](https://twitter.com/MrHazum/status/952891526396465152)  
2018-01-15 - [Seamless campaign Rig EK sends Ramnit banking Trojan](https://twitter.com/MrHazum/status/952857024181784576)  
2018-01-16 - [Seamless campaign Rig EK sends Ramnit banking Trojan](https://malwarebreakdown.com/2018/01/16/rig-exploit-kit-delivers-ramnit-banking-trojan-via-seamless-malvertising-campaign/)  
2018-01-17 - [Seamless campaign Rig EK sends Ramnit banking Trojan](https://www.vkremez.com/2018/01/lets-learn-dissect-rig-exploit-kit-anti.html)  
2018-01-19 - [Ngay campaign Rig EK sends Remcos RAT](https://malware-traffic-analysis.net/2018/01/19/index.html)  
2018-01-25 - [Seamless campaign Rig EK sends Ramnit banking Trojan](https://traffic.moe/2018/01/25/index.html)  
2018-01-26 - [Seamless campaign Rig EK sends GandCrab ransomware](https://traffic.moe/2018/01/26/index.html)  
2018-01-29 - [Three days of Seamless campaign Rig EK pushing GandCrab ransomware](https://www.malware-traffic-analysis.net/2018/01/29/index.html)  
2018-01-30 - [Seamless campaign Rig EK sends Ramnit banking Trojan](https://traffic.moe/2018/01/26/index.html)  
2018-01-31 - [Fobos campaign Rig EK sends Bunitu proxy trojan](https://traffic.moe/2018/01/31/index.html)  
Back to top

### Tags

* [Cryptocurrency mining](https://unit42.paloaltonetworks.com/tag/cryptocurrency-mining/ "Cryptocurrency mining")
* [Information stealer](https://unit42.paloaltonetworks.com/tag/information-stealer/ "information stealer")
* [Rig Exploit Kit](https://unit42.paloaltonetworks.com/tag/rig-exploit-kit/ "Rig Exploit Kit")  
  [Threat Research Center](https://unit42.paloaltonetworks.com "Threat Research") [Next: Threat Brief: A Declining Rig Exploit Kit Hops on the Coinmining Bandwagon](https://unit42.paloaltonetworks.com/threat-brief-declining-rig-exploit-kit-hops-coinmining-bandwagon/ "Threat Brief: A Declining Rig Exploit Kit Hops on the Coinmining Bandwagon")

### Related Articles

* [Diving Into Glupteba's UEFI Bootkit](https://unit42.paloaltonetworks.com/glupteba-malware-uefi-bootkit/ "article - table of contents")
* [Recent Trends in Internet Threats: Common Industries Impersonated in Phishing Attacks, Web Skimmer Analysis and More](https://unit42.paloaltonetworks.com/internet-threats-late-2022/ "article - table of contents")
* [Spike in LokiBot Activity During Final Week of 2022](https://unit42.paloaltonetworks.com/lokibot-spike-analysis/ "article - table of contents")

## Related Resources

![Pictorial representation of post-exploitation identity misuse in SPIFFE/SPIRE. Close-up of a person wearing glasses, with computer code reflected in the lenses.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/09/12_Security-Technology_Category_1920x900-786x368.jpg)  
[![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) September 10, 2026 [#### The Machine With Many Faces: Post-Exploitation Identity Misuse in SPIFFE/SPIRE](https://unit42.paloaltonetworks.com/kubernetes-spiffe-spire-identity-spoofing/)

* [API](https://unit42.paloaltonetworks.com/tag/api/ "API")

* [Cryptographic](https://unit42.paloaltonetworks.com/tag/cryptographic/ "cryptographic")

* [JSON](https://unit42.paloaltonetworks.com/tag/json/ "JSON")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/kubernetes-spiffe-spire-identity-spoofing/ "The Machine With Many Faces: Post-Exploitation Identity Misuse in SPIFFE/SPIRE")  
  ![Pictorial representation of a pay-per-install threat group campaign prodiving infection service for spreading malware. A close-up of a computer circuit board with a central microchip is depicted. Red digital data streams in the form of glowing binary numbers and arrows appear to flow in and out of the chip, symbolizing data processing and transfer. The scene is illuminated with a futuristic blue and red glow.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/09/04_Malware_Category_1920x900-6-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) September 9, 2026 [#### Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure](https://unit42.paloaltonetworks.com/ppi-network-malware-campaign-analysis/)

* [ARKTunnel](https://unit42.paloaltonetworks.com/tag/arktunnel/ "ARKTunnel")

* [C2](https://unit42.paloaltonetworks.com/tag/c2/ "C2")

* [CL-CRI-1171](https://unit42.paloaltonetworks.com/tag/cl-cri-1171/ "CL-CRI-1171")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ppi-network-malware-campaign-analysis/ "Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure")  
  ![Pictorial representation of attackers using AI tools to target Latin American organizations. A vibrant cityscape with silhouettes of numerous people walking along a bustling street. The scene is illuminated by bright urban lights and digital-like particles, creating a dynamic and futuristic atmosphere.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/09/AdobeStock_768915868-2-1-786x373.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) September 3, 2026 [#### Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America](https://unit42.paloaltonetworks.com/ai-tool-use-targeting-latam-orgs/)

* [Agentic AI](https://unit42.paloaltonetworks.com/tag/agentic-ai/ "Agentic AI")

* [ChatGPT](https://unit42.paloaltonetworks.com/tag/chatgpt/ "ChatGPT")

* [CL-CRI-1131](https://unit42.paloaltonetworks.com/tag/cl-cri-1131/ "CL-CRI-1131")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ai-tool-use-targeting-latam-orgs/ "Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America")  
  ![Pictorial representation of vishing campaigns in Microsoft Teams. A digital image of a skull formed by blue binary code on a black background, with scattered ones and zeros and digital noise, symbolizes how stealthy prompt injection attacks can exploit AI logic to bypass security controls.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/01_Malware_Category_1920x900-5-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 31, 2026 [#### Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams](https://unit42.paloaltonetworks.com/spring-ring-voice-phishing-campaigns/)

* [Cloaked Ursa](https://unit42.paloaltonetworks.com/tag/cloaked-ursa/ "Cloaked Ursa")

* [Entra ID](https://unit42.paloaltonetworks.com/tag/entra-id/ "Entra ID")

* [Microsoft Teams](https://unit42.paloaltonetworks.com/tag/microsoft-teams/ "Microsoft Teams")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/spring-ring-voice-phishing-campaigns/ "Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams")  
  ![Pictorial representation of AI-enabled malware. A vibrant digital interface displaying various icons and graphs, resembling a futuristic network or data analysis dashboard. The scene is illuminated with glowing lights and patterns.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/AdobeStock_1270203474-2-1-786x368.png)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 25, 2026 [#### The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution](https://unit42.paloaltonetworks.com/ai-enabled-malware-analysis/)

* [Backdoor](https://unit42.paloaltonetworks.com/tag/backdoor/ "backdoor")

* [Bitcoin](https://unit42.paloaltonetworks.com/tag/bitcoin/ "Bitcoin")

* [DLL hijacking](https://unit42.paloaltonetworks.com/tag/dll-hijacking/ "DLL hijacking")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ai-enabled-malware-analysis/ "The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution")  
  ![Pictorial representation of identity abuse through trusted communication channels. Close-up view of a digital screen displaying a glitched and pixelated image of a skull-like shape.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/02_Malware_Category_1920x900-2-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 20, 2026 [#### Identity Abuse Through Trusted Communication Channels](https://unit42.paloaltonetworks.com/communication-channel-identity-risks/)

* [Authentication](https://unit42.paloaltonetworks.com/tag/authentication/ "authentication")

* [Identity theft](https://unit42.paloaltonetworks.com/tag/identity-theft/ "identity theft")

* [Malware](https://unit42.paloaltonetworks.com/tag/malware/ "malware")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/communication-channel-identity-risks/ "Identity Abuse Through Trusted Communication Channels")  
  ![Pictorial representation of Kimwolf botnet malware family. Digital screen with a warning sign reading "Malware." The background features lines of computer code and graphics, creating a sense of cybersecurity threat.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/07_Malware_Category_1920x900-3-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 11, 2026 [#### Kimwolf v7: An Evolution of the Kimwolf Botnet](https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/)

* [Android APK](https://unit42.paloaltonetworks.com/tag/android-apk/ "Android APK")

* [Ethereum](https://unit42.paloaltonetworks.com/tag/ethereum/ "Ethereum")

* [HTTP](https://unit42.paloaltonetworks.com/tag/http/ "HTTP")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/ "Kimwolf v7: An Evolution of the Kimwolf Botnet")  
  ![Pictorial representatiom pf Aeternum's blockchain C2. A close-up of a computer circuit board with a central microchip is depicted. Red digital data streams in the form of glowing binary numbers and arrows appear to flow in and out of the chip. The scene is illuminated with a futuristic blue and red glow.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/04_Malware_Category_1920x900-4-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 10, 2026 [#### The Permanent Threat: Analyzing Aeternum's Blockchain-Based C2 Operations and Communications](https://unit42.paloaltonetworks.com/aeternum-blockchain-c2-analysis/)

* [Aeternum](https://unit42.paloaltonetworks.com/tag/aeternum/ "Aeternum")

* [Infection chain](https://unit42.paloaltonetworks.com/tag/infection-chain/ "infection chain")

* [JSON](https://unit42.paloaltonetworks.com/tag/json/ "JSON")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/aeternum-blockchain-c2-analysis/ "The Permanent Threat: Analyzing Aeternum’s Blockchain-Based C2 Operations and Communications")  
  ![Pictorial representation of ChainDrop, a self-propagating npm worm. An artistic depiction of a digital workspace featuring an open laptop with a red virus on the screen.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/03_Malware_Category_1920x900-7-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)High Profile Threats](https://unit42.paloaltonetworks.com/category/top-cyberthreats/) August 6, 2026 [#### ChainDrop: Inside a Self-Propagating npm Worm](https://unit42.paloaltonetworks.com/chaindrop-npm-worm-analysis/)

* [Blockchain](https://unit42.paloaltonetworks.com/tag/blockchain/ "blockchain")

* [ChainDrop](https://unit42.paloaltonetworks.com/tag/chaindrop/ "ChainDrop")

* [Claude code](https://unit42.paloaltonetworks.com/tag/claude-code/ "Claude code")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/chaindrop-npm-worm-analysis/ "ChainDrop: Inside a Self-Propagating npm Worm")  
  ![Pictorial representation of Token-jacking. A person types on a laptop with multiple digital interface elements projected, including an "AI" icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/AdobeStock_1246251272-2-786x369.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 6, 2026 [#### Token Jacking: Cybercriminals Could Be Stealing Your AI Resources](https://unit42.paloaltonetworks.com/ai-token-jacking/)

* [AI API](https://unit42.paloaltonetworks.com/tag/ai-api/ "AI API")

* [AI gateway](https://unit42.paloaltonetworks.com/tag/ai-gateway/ "AI gateway")

* [API keys](https://unit42.paloaltonetworks.com/tag/api-keys/ "API keys")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ai-token-jacking/ "Token Jacking: Cybercriminals Could Be Stealing Your AI Resources")

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)  
  ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg) ![Enlarged Image]()  
  ![Newsletter](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/unit42-footer-subscribe-desktop.png)  
  ![UNIT 42 Small Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/palo-alto-logo-small.svg) Get updates from Unit 42

## Peace of mind comes from staying ahead of threats. Subscribe today.

Your Email

Subscribe for email updates to all Unit 42 threat research.  
By submitting this form, you agree to our [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use "Terms of Use") and acknowledge our [Privacy Statement.](https://www.paloaltonetworks.com/legal-notices/privacy "Privacy Statement")

This site is protected by reCAPTCHA and the Google [Privacy Policy](https://policies.google.com/privacy) and [Terms of Service](https://policies.google.com/terms) apply.

Invalid captcha!
Subscribe ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg) ![loader](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-loader.svg)  
{#footer} Products and Services

* [AI-Powered Network Security Platform](https://www.paloaltonetworks.com/network-security)

* [Secure AI by Design](https://www.paloaltonetworks.com/ai-security)

* [Prisma AIRS](https://www.paloaltonetworks.com/ai-security/prisma-airs)

* [AI Access Security](https://www.paloaltonetworks.com/sase/ai-access-security)

* [Cloud Delivered Security Services](https://www.paloaltonetworks.com/network-security/security-subscriptions)

* [Advanced Threat Prevention](https://www.paloaltonetworks.com/network-security/advanced-threat-prevention)

* [Advanced URL Filtering](https://www.paloaltonetworks.com/network-security/advanced-url-filtering)

* [Advanced WildFire](https://www.paloaltonetworks.com/network-security/advanced-wildfire)

* [Advanced DNS Security](https://www.paloaltonetworks.com/network-security/advanced-dns-security)

* [Enterprise Data Loss Prevention](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention)

* [Enterprise IoT Security](https://www.paloaltonetworks.com/network-security/enterprise-device-security)

* [Medical IoT Security](https://www.paloaltonetworks.com/network-security/medical-device-security)

* [Industrial OT Security](https://www.paloaltonetworks.com/network-security/ot-security-solution)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security)

* [Next-Generation Firewalls](https://www.paloaltonetworks.com/network-security/next-generation-firewall)

* [Hardware Firewalls](https://www.paloaltonetworks.com/network-security/hardware-firewall-innovations)

* [Software Firewalls](https://www.paloaltonetworks.com/network-security/software-firewalls)

* [Strata Cloud Manager](https://www.paloaltonetworks.com/network-security/strata-cloud-manager)

* [SD-WAN for NGFW](https://www.paloaltonetworks.com/network-security/sd-wan-subscription)

* [PAN-OS](https://www.paloaltonetworks.com/network-security/pan-os)

* [Panorama](https://www.paloaltonetworks.com/network-security/panorama)

* [Secure Access Service Edge](https://www.paloaltonetworks.com/sase)

* [Prisma SASE](https://www.paloaltonetworks.com/sase)

* [Application Acceleration](https://www.paloaltonetworks.com/sase/app-acceleration)

* [Autonomous Digital Experience Management](https://www.paloaltonetworks.com/sase/adem)

* [Enterprise DLP](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention)

* [Prisma Access](https://www.paloaltonetworks.com/sase/access)

* [Prisma Browser](https://www.paloaltonetworks.com/sase/prisma-browser)

* [Prisma SD-WAN](https://www.paloaltonetworks.com/sase/sd-wan)

* [Remote Browser Isolation](https://www.paloaltonetworks.com/sase/remote-browser-isolation)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security)

* [AI-Driven Security Operations Platform](https://www.paloaltonetworks.com/cortex)

* [Cloud Security](https://www.paloaltonetworks.com/cortex/cloud)

* [Cortex Cloud](https://www.paloaltonetworks.com/cortex/cloud)

* [Application Security](https://www.paloaltonetworks.com/cortex/cloud/application-security)

* [Cloud Posture Security](https://www.paloaltonetworks.com/cortex/cloud/cloud-posture-security)

* [Cloud Runtime Security](https://www.paloaltonetworks.com/cortex/cloud/runtime-security)

* [Prisma Cloud](https://www.paloaltonetworks.com/prisma/cloud)

* [AI-Driven SOC](https://www.paloaltonetworks.com/cortex)

* [Cortex XSIAM](https://www.paloaltonetworks.com/cortex/cortex-xsiam)

* [Cortex XDR](https://www.paloaltonetworks.com/cortex/cortex-xdr)

* [Cortex XSOAR](https://www.paloaltonetworks.com/cortex/cortex-xsoar)

* [Cortex Xpanse](https://www.paloaltonetworks.com/cortex/cortex-xpanse)

* [Unit 42 Managed Detection \& Response](https://www.paloaltonetworks.com/cortex/managed-detection-and-response)

* [Managed XSIAM](https://www.paloaltonetworks.com/cortex/managed-xsiam)

* [Next-Generation Identity Security](https://www.paloaltonetworks.com/idira)

* [Privileged Access Management](https://www.paloaltonetworks.com/idira/human/privileged-access-management)

* [Identity and Access Management](https://www.paloaltonetworks.com/idira/human/identity-and-access-management)

* [Endpoint Privilege Manager](https://www.paloaltonetworks.com/idira/human/endpoint-privilege-manager)

* [Identity Governance](https://www.paloaltonetworks.com/idira/human/identity-governance)

* [Workforce Password Management](https://www.paloaltonetworks.com/idira/human/workforce-password-management)

* [Agentic Identities](https://www.paloaltonetworks.com/idira/agentic)

* [Secrets Management](https://www.paloaltonetworks.com/idira/machine/secrets-management)

* [Unified Secrets Governance](https://www.paloaltonetworks.com/idira/machine/unified-secrets-governance)

* [Application Credentials Delivery](https://www.paloaltonetworks.com/idira/machine/application-credentials-delivery)

* [Vendor Privileged Access](https://www.paloaltonetworks.com/idira/human/vendor-privileged-access)

* [Threat Intel and Incident Response Services](https://www.paloaltonetworks.com/unit42)

* [Prepare for Emerging Risks](https://www.paloaltonetworks.com/unit42/frontier-ai-defense)

* [Strengthen Your Defenses](https://www.paloaltonetworks.com/unit42/strengthen-your-defenses)

* [Build Your Security Strategy](https://www.paloaltonetworks.com/unit42/build-your-security-strategy)

* [Understand the Adversary](https://www.paloaltonetworks.com/unit42/threat-intelligence)

* [Respond to a Cyber Attack](https://www.paloaltonetworks.com/unit42/respond)  
  Company

* [About Us](https://www.paloaltonetworks.com/about-us)

* [Careers](https://jobs.paloaltonetworks.com/en/)

* [Contact Us](https://www.paloaltonetworks.com/company/contact-sales)

* [Corporate Responsibility](https://www.paloaltonetworks.com/about-us/corporate-responsibility)

* [Customers](https://www.paloaltonetworks.com/customers)

* [Investor Relations](https://investors.paloaltonetworks.com/)

* [Location](https://www.paloaltonetworks.com/about-us/locations)

* [Newsroom](https://www.paloaltonetworks.com/company/newsroom)  
  Popular Links

* [Blog](https://www.paloaltonetworks.com/blog/)

* [Communities](https://www.paloaltonetworks.com/communities)

* [Content Library](https://www.paloaltonetworks.com/resources)

* [Cyberpedia](https://www.paloaltonetworks.com/cyberpedia)

* [Event Center](https://events.paloaltonetworks.com/)

* [Manage Email Preferences](https://start.paloaltonetworks.com/preference-center)

* [Products A-Z](https://www.paloaltonetworks.com/products/products-a-z)

* [Product Certifications](https://www.paloaltonetworks.com/legal-notices/trust-center/certifications)

* [Report a Vulnerability](https://www.paloaltonetworks.com/security-disclosure)

* [Sitemap](https://www.paloaltonetworks.com/sitemap)

* [Tech Docs](https://docs.paloaltonetworks.com/)

* [Unit 42](https://unit42.paloaltonetworks.com/)

* [Do Not Sell or Share My Personal Information](https://panwedd.exterro.net/portal/dsar.htm?target=panwedd)
  ![Palo Alto Networks Logo](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/pan-logo-dark.svg)

* [Privacy](https://www.paloaltonetworks.com/legal-notices/privacy)

* [Trust Center](https://www.paloaltonetworks.com/legal-notices/trust-center)

* [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use)

* [Documents](https://www.paloaltonetworks.com/legal)

Copyright © 2026 Palo Alto Networks. All Rights Reserved

* [![Youtube](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/youtube-black.svg)](https://www.youtube.com/user/paloaltonetworks)
* [![Podcast](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/icons/podcast.svg)](https://www.paloaltonetworks.com/podcasts/threat-vector)
* [![Facebook](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/facebook-black.svg)](https://www.facebook.com/PaloAltoNetworks/)
* [![LinkedIn](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/linkedin-black.svg)](https://www.linkedin.com/company/palo-alto-networks)
* [![Twitter](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/twitter-x-black.svg)](https://twitter.com/PaloAltoNtwks)
* EN  
  Select your language  
  ![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg) ![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg) ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg)

### Default Heading

Read the article ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg)  
Seekbar

![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg)  
![Volume](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-volume.svg)  
Volume
![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg)
