[![Logo](https://www.paloaltonetworks.com/wp-content/uploads/2021/07/PANW_Parent.png)](https://www.paloaltonetworks.com/)  
[![Unit42 Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/unit42-logo-white.svg)](https://unit42.paloaltonetworks.com/)  
Menu

* [Tools](https://unit42.paloaltonetworks.com/tools/)
* [ATOMs](https://unit42.paloaltonetworks.com/atoms/)
* [Security Consulting](https://www.paloaltonetworks.com/unit42)
* [About Us](https://unit42.paloaltonetworks.com/about-unit-42/)
* [**Under Attack?**](https://start.paloaltonetworks.com/contact-unit42.html)
* [Threat Research Center](https://unit42.paloaltonetworks.com "Threat Research")
* [Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/ "Threat Research")
* [Malware](https://unit42.paloaltonetworks.com/category/malware/ "Malware")  
  [Malware](https://unit42.paloaltonetworks.com/category/malware/)

# Off the Beaten Path: Recent Unusual Malware

![Clock Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-clock.svg) 15 min read  
Related Products  
[![Advanced WildFire icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Advanced WildFire](https://unit42.paloaltonetworks.com/product-category/advanced-wildfire/ "Advanced WildFire")[![Cloud-Delivered Security Services icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Cloud-Delivered Security Services](https://unit42.paloaltonetworks.com/product-category/cloud-delivered-security-services/ "Cloud-Delivered Security Services")[![Cortex icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/cortex_RGB_logo_Icon_Color.png)Cortex](https://unit42.paloaltonetworks.com/product-category/cortex/ "Cortex")[![Cortex XDR icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/cortex_RGB_logo_Icon_Color.png)Cortex XDR](https://unit42.paloaltonetworks.com/product-category/cortex-xdr/ "Cortex XDR")[![Cortex XSIAM icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/cortex_RGB_logo_Icon_Color.png)Cortex XSIAM](https://unit42.paloaltonetworks.com/product-category/cortex-xsiam/ "Cortex XSIAM")[![Unit 42 Incident Response icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/unit42_RGB_logo_Icon_Color.png)Unit 42 Incident Response](https://unit42.paloaltonetworks.com/product-category/unit-42-incident-response/ "Unit 42 Incident Response")

* ![Profile Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-profile-grey.svg)  
  By:
  
  * [Dominik Reichel](https://unit42.paloaltonetworks.com/author/dominik-reichel/)

* ![Published Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-calendar-grey.svg)  
  Published:March 14, 2025

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-category.svg)  
  Categories:
  
  * [Malware](https://unit42.paloaltonetworks.com/category/malware/)
  * [Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/)

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-tags-grey.svg)  
  Tags:
  
  * [.NET](https://unit42.paloaltonetworks.com/tag/net/)
  * [Backdoor](https://unit42.paloaltonetworks.com/tag/backdoor/)
  * [C++](https://unit42.paloaltonetworks.com/tag/c/)
  * [Post-exploitation](https://unit42.paloaltonetworks.com/tag/post-exploitation/)
  * [Red teaming tool](https://unit42.paloaltonetworks.com/tag/red-teaming-tool/)

* [![Download Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-download.svg)](https://unit42.paloaltonetworks.com/unusual-malware/?pdf=download&lg=en&_wpnonce=7052973960 "Click here to download")

* [![Print Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-print.svg)](https://unit42.paloaltonetworks.com/unusual-malware/?pdf=print&lg=en&_wpnonce=7052973960 "Click here to print")

Share![Down arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/down-arrow.svg)

* ![Link Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-share-link.svg)
* [![Link Email](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-sms.svg)](mailto:?subject=Off%20the%20Beaten%20Path:%20Recent%20Unusual%20Malware&body=Check%20out%20this%20article%20https%3A%2F%2Funit42.paloaltonetworks.com%2Funusual-malware%2F "Share in email")
* [![Facebook Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-fb-share.svg)](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Funit42.paloaltonetworks.com%2Funusual-malware%2F "Share in Facebook")
* [![LinkedIn Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-linkedin-share.svg)](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Funusual-malware%2F&title=Off%20the%20Beaten%20Path:%20Recent%20Unusual%20Malware "Share in LinkedIn")
* [![Twitter Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-twitter-share.svg)](https://twitter.com/intent/tweet?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Funusual-malware%2F&text=Off%20the%20Beaten%20Path:%20Recent%20Unusual%20Malware "Share in Twitter")
* [![Reddit Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-reddit-share.svg)](https://www.paloaltonetworks.com//www.reddit.com/submit?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Funusual-malware%2F&ts=markdown "Share in Reddit")
* [![Mastodon Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-mastodon-share.svg)](https://mastodon.social/share?text=Off%20the%20Beaten%20Path:%20Recent%20Unusual%20Malware%20https%3A%2F%2Funit42.paloaltonetworks.com%2Funusual-malware%2F "Share in Mastodon")

## Executive Summary

Recently, we discovered several new malware samples with unique characteristics that made attribution and function determination challenging. While many threat actors will strictly use tools released by the offensive security community, we also encounter novel, custom-built malware -- sometimes with new tricks and techniques. This article describes three particularly unusual malware examples we came across last year.

* The first malware sample is a passive Internet Information Services (IIS) backdoor developed in C++/CLI, a programming language very rarely used by malware authors.
* The second sample is a bootkit that uses an unsecured kernel driver to install a [GRUB 2](https://www.gnu.org/software/grub/) bootloader for a rather unusual purpose.
* The third sample is a Windows implant of a cross-platform post-exploitation framework developed in C++.

Although the last example is a red team tool that doesn't use any novel methods, we believe it is worth reviewing due to significant deviation from other post-exploitation frameworks we've seen during the past year.

Palo Alto Networks customers are better protected from these malware samples through [Advanced WildFire](https://www.paloaltonetworks.com/network-security/advanced-wildfire), with its different memory analysis features.

Cortex [XDR](https://docs-cortex.paloaltonetworks.com/p/XDR) and [XSIAM](https://docs-cortex.paloaltonetworks.com/p/XSIAM) are designed to prevent the execution of known malicious malware, and also prevent the execution of unknown malware using Behavioral Threat Protection and machine learning based on the Local Analysis module.

If you think you might have been compromised or have an urgent matter, contact the [Unit 42 Incident Response team](https://start.paloaltonetworks.com/contact-unit42.html).

| **Related Unit 42 Topics** | [**Malware**](https://unit42.paloaltonetworks.com/category/malware/), **[Backdoor](https://unit42.paloaltonetworks.com/tag/backdoor/)** |
|----------------------------|-----------------------------------------------------------------------------------------------------------------------------------------|

## Example 1: C++/CLI IIS Backdoor

The [C++/CLI programming language](https://learn.microsoft.com/en-us/cpp/dotnet/dotnet-programming-with-cpp-cli-visual-cpp) is an extension of the C++ programming language that can be used to write mixed-mode .NET applications. These [mixed assemblies](https://learn.microsoft.com/en-us/cpp/dotnet/mixed-native-and-managed-assemblies) can have managed code (C#) and unmanaged code (C++). Analyzing these files is challenging because it can be hard to read their interoperation code in existing .NET decompilers.

This programming language is very rare among malware authors, likely because C++/CLI is poorly documented compared to other languages. One of the first public mentions of a malware sample coded in C++/CLI was a module of a toolkit that [Positive Technologies described in 2018](https://habr.com/ru/companies/pt/articles/432172/). However, this module and all other C++/CLI malware we have come across so far is not as complex as this particular IIS backdoor.

We found two versions of this passive IIS malware uploaded to VirusTotal, both submitted from Thailand. The later version, compiled on May 9, 2023, differs from the earlier one, compiled on April 28, 2023, in its approach to handling external commands. It uses a custom cmd.exe wrapper tool, as opposed to the earlier version which uses just the cmd.exe tool. This change was likely implemented to create less monitorable activity, as spawning cmd.exe directly from an IIS process could raise suspicion. These samples have been [referred to as "Detele" \[PDF\]](https://github.com/PwCUK-CTO/labscon-2024-knowledge-iis-power/blob/main/LABScon-2024_Knowledge_IIS_power.pdf) during a presentation by John Southworth at the LABScon conference in 2024.

### **Technical Analysis of the C++/CLI IIS Backdoor**

The two samples of this passive IIS malware were compiled with different Visual C++/CLI compiler versions and also differ slightly in functionality.

* The newer and bigger assembly (SHA256 hash: 15db49717a9e9c1e26f5b1745870b028e0133d430ec14d52884cec28ccd3c8ab) is internally named proxyxml\_v4 (described as version 2). This newer sample uses more AMSI/ETW patching and has a different implementation for the non-self-contained command-line features.
* The slightly older one (SHA256 hash: 8571a354b5cdd9ec3735b84fa207e72c7aea1ab82ea2e4ffea1373335b3e88f4) is named IISShellModule (described as version 1).

The author created the backdoor as an IIS module that uses the exported function RegisterModule to register itself for RQ\_SEND\_RESPONSE event notifications. Therefore, whenever the IIS server sends an HTTP response, it will call the backdoor's registered OnSendResponse method. For callback traffic, the backdoor's OnSendResponse method filters on the incoming HTTP request having the following attributes before calling its event handler:

* Request type: HTTP POST
* Request header field and value: X-ZA-Product : AbJc123!@#45!!
* Request header field and value: X-ZA-Platform : \<any\>

The custom HTTP request header field named X-ZA-Product is internally reassigned to PWD\_HEADER, and its value AbJc123!@#45!! is reassigned as PWD\_VALUE. This PWD\_VALUE is encrypted using AES with a key of AQJBdmin!@#45!@## (internally called KEY) and the result is Base64-encoded.

The other HTTP request header field named X-ZA-Platform is processed by the malware as CMD\_HEADER, and the CMD\_VALUE represents the actual command data. This CMD\_VALUE is also encrypted using AES with the same KEY as the PWD\_VALUE and the result is also Base64-encoded.

The backdoor has an event handler that processes the data from X-ZA-Platform to parse the included commands. Figure 1 shows the event handler code that processes the implemented commands.
![Screenshot of many lines of code in an editor with syntax color-coded for visibility. There are 39 lines in total and they include comments, commands and more.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/03/word-image-160227-138652-1.png) Figure 1. IIS backdoor event handler as shown by [dnSpyEx](https://github.com/dnSpyEx/dnSpy).

At first, the handler patches [AMSI](https://learn.microsoft.com/en-us/windows/win32/amsi/antimalware-scan-interface-portal) and [ETW](https://learn.microsoft.com/en-us/windows-hardware/drivers/devtest/event-tracing-for-windows--etw-) routines for the current process ([copied and pasted](https://github.com/Hagrid29/RemotePatcher/blob/main/RemotePatcher/RemotePatcher.cpp) from GitHub). Afterwards, the handler utilizes the X-ZA-Platform command data to extract the specific commands and corresponding data for each implemented command feature.

Table 1 shows the list of available commands in version 2 of this malware.

|-------------|--------------------------|---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| **Command** | **Internal Term**        | **Description**                                                                                                                                                                                                                                                                                                                                                                                                     |
| 2           | -                        | Reply with a test HTTP request.                                                                                                                                                                                                                                                                                                                                                                                     |
| 3 / 4 / 5   | ProcessCmdOperation      | Write the embedded cmd.exe wrapper application (internally termed BackendIPCServer) to %PUBLIC%\\VC\_REDIST\_CONFIG\_X64.TXT and create a process for it.  Redirect any command-line commands from the C2 server to this wrapper app via a named pipe \\.\\pipe\\pipename\_isudbvvws and also return the result via the pipe.                                                                                     |
| 6           | OnUploadNewFile          | Create an empty file with a given file (absolute path) if not already present.                                                                                                                                                                                                                                                                                                                                      |
| 7           | OnUploadFileData         | Write data to a given file (absolute path).  Most likely used in combination with OnUploadNewFile.                                                                                                                                                                                                                                                                                                            |
| 8           | OnDownloadNewFile        | Checks the file size of a given file (absolute path).                                                                                                                                                                                                                                                                                                                                                               |
| 9           | OnDownloadFileData       | Return data of a given file (absolute path).  Most likely used in combination with OnDownloadNewFile.                                                                                                                                                                                                                                                                                                         |
| 10          | OnUploadMemoryData       | Create a memory buffer and write the given shellcode, .NET assembly or PowerShell code to it.  The shellcode is used in exec\_builtin\_cmd\_inject, the .NET assembly in exec\_builtin\_cmd\_net and the PowerShell code in exec\_builtin\_cmd\_pscript.                                                                                                                                                               |
| 14          | -                        | This is the self-contained command line in contrast to the external command line via the wrapper app.  This contains sub-values listed below.                                                                                                                                                                                                                                                                 |
| 14 - 0      | exec\_builtin\_cmd\_pwd     | Return the current directory path.                                                                                                                                                                                                                                                                                                                                                                                  |
| 14 - 1      | exec\_builtin\_cmd\_ls      | Return the names, sizes, types and last modified times of all files in the current directory.                                                                                                                                                                                                                                                                                                                       |
| 14 - 2      | exec\_builtin\_cmd\_cat     | Return the data of a given file (absolute path).                                                                                                                                                                                                                                                                                                                                                                    |
| 14 - 3      | exec\_builtin\_cmd\_rm      | Remove a given file (absolute path).                                                                                                                                                                                                                                                                                                                                                                                |
| 14 - 4      | exec\_builtin\_cmd\_process | Get names, PIDs, architectures and users of all running processes.                                                                                                                                                                                                                                                                                                                                                  |
| 14 - 5      | exec\_builtin\_cmd\_sysinfo | Get detailed system information such as:  \* Current username \* IIS information (major/minor version) \* Windows OS information \* Product name \* Major/minor version \* Build number \* Platform ID \* Architecture \* Current time and time zone \* External IP address (api.ipify\[.\]org) \* Internal IP address \* Gateway IP address \* DNS addresses \* ARP table data \* Adapter addresses \* Environment variables |
| 14 - 6      | exec\_builtin\_cmd\_exec    | Create a process of a given file (absolute path).                                                                                                                                                                                                                                                                                                                                                                   |
| 14 - 7      | exec\_builtin\_cmd\_ps      | Execute a given PowerShell code in its own run space.                                                                                                                                                                                                                                                                                                                                                               |
| 14 - 8      | exec\_builtin\_cmd\_pscript | Execute a given PowerShell code from the memory buffer from OnUploadMemoryData in its own run space.                                                                                                                                                                                                                                                                                                                |
| 14 - 9      | exec\_builtin\_cmd\_net     | The first option creates a new process, patches AMSI/ETW, creates a buffer in the process and reflectively loads the assembly from OnUploadMemoryData.  The second option executes the assembly from OnUploadMemoryData in the current process via CLR hosting (CLRCreateInstance, ...).                                                                                                                      |
| 14 - 10     | exec\_builtin\_cmd\_inject  | Inject the shellcode from OnUploadMemoryData into a new (remote thread injection), existing (remote thread injection) or the current process (new thread).                                                                                                                                                                                                                                                          |

Table 1. Implemented commands in malware version 2.

The wrapper application (SHA256 hash: a28d0550524996ca63f26cb19f4b4d82019a1be24490343e9b916d2750162cda) used in ProcessCmdOperation is embedded in the .rdata section.

To load an assembly into a new process as part of the exec\_builtin\_cmd\_net command, a small embedded loader DLL (SHA256 hash: aa2d46665ea230e856689c614edcd9d932d9edad0083bf89c903299d148634a2), also embedded in the .rdata section, is loaded into the process that in turn reflectively loads the assembly.

The returned result of each command (which can also be debug information in case of an error) is then AES-encrypted and Base64-encoded.

Malware version 1 has a slightly different implementation in functionality. It patches AMSI and ETW routines only in the routine that executes a .NET assembly in a new process and not at the beginning of the command data event handler like in version 2. Also, version 1 does not use an external command-line wrapper application for commands 3-5. Instead, it uses different implementations for these commands as shown in Table 2.

|-------------|---------------------|----------------------------------------------------------------------------------------------------------------|
| **Command** | **Internal Term**   | **Description**                                                                                                |
| 3           | ExecuteCmd          | Execute a given command-line command by spawning a child cmd.exe process and redirecting the result to a pipe. |
| 4           | GetExecutionResult  | Read the command-line command result from the pipe from ExecuteCmd.                                            |
| 5           | StopCmdChildProcess | Terminate the cmd.exe child process and close the pipe from ExecuteCmd.                                        |

Table 2. Different commands in malware version 1 in comparison to version 2.

While using native Windows API functions is not mandatory for C++/CLI applications, this malware extensively uses them for all of its features. Overall, this malware appears to be coded by a seasoned, old-school Windows developer. The author uses the classic [Hungarian notation](https://en.wikipedia.org/wiki/Hungarian_notation) throughout the code. For example the malware uses the following variable names:

* wszExe
* pszArg
* pNetExeBuffer
* dwNetExeBufferSize
* uiBaseAddress
* strCmdValueEncrypted
* g\_hBackendIPCServer
* g\_aryBackendIPCServer

This malware has some inconsistent notations, debug messages and a few typos throughout the code that indicate the malware was not created by someone who speaks English as a first language. For example, the following list shows an excerpt of the debug strings used in the malware:

* \[+\] PID:
* \[-\] Exec Failed.
* \[+\] Inject Succeed
* \[-\] Inject Failed
* \[+\] .Net Exec Succeed
* \[-\] .Net Exec Failed
* \[-\] .Net Exec Timeout (\>20s). Result Maybe Incomplete
* \[-\] Cat File Left Content Failed
* \[-\] Cat File 0 size
* \[-\] Cat File Failed
* \[+\] Detele Succeed
* \[-\] Detele Failed
* unknow

The above list contains misspellings of the words unknown and delete. We also find inconsistent use of tense, where Succeed is present tense, while Failed is past tense. Also using Result Maybe Incomplete, where the proper spelling should be Result May Be Incomplete.

### **Summary of C++/CLI IIS Backdoor**

This passive IIS backdoor written in C++/CLI has numerous functionalities and is likely under active development. All network traffic is encrypted and encoded. Even though it has been professionally created, there appear to be weak spots that facilitate detection and analysis. All (debug) strings are stored in cleartext, making analysis easier. Additionally, the malware uses hard-coded passwords and keys for authentication.

We assess this malware is quite uncommon, because we have not yet discovered any other comparable samples. This rarity indicates the malware could have been used in a targeted attack, especially with its unusual development language and sophisticated nature. However, we cannot yet attribute this malware to any known threat actor.

## Example 2: A Dixie-Playing Bootkit

What started as an analysis of a possible new implant from the [Equation Group](https://www.cfr.org/cyber-operations/equation-group) turned out to be one of the most peculiar threats we saw in 2024 in terms of its behavior.

At a first glance, the sample looked similar to previous malware attributed to the Equation Group. This sample has the typical exported function name dll\_u, it uses multiple API functions from msvcrt.dll, and it abuses a third-party driver to gain access to kernel-mode. All these characteristics have been seen in [EquationDrug](https://malpedia.caad.fkie.fraunhofer.de/details/win.equationdrug) and [SlingShot](https://malpedia.caad.fkie.fraunhofer.de/actor/slingshot) samples too. Additionally, some security vendors classify this as a new EquationDrug sample.

This sample is also interesting because of its associated VirusTotal submission data. The sample was submitted from Oxford, Mississippi. It was uploaded with the file name w32analytics.dll to VirusTotal from the directory path C:\\Windows\\System32. This at least indicates it's from an actual ITW infection of a real victim, as this directory is reserved for the Windows operating system and commonly abused by malware. Beginning with Windows Vista, administrative privileges are required to write a file to the system32 directory. It indicates that this malware was placed there by an individual with admin privileges or another unidentified related malware that had administrative privileges. We have not found any other similar samples at this time.

This sample was compiled with [MinGW](https://www.mingw-w64.org/) and is signed by the University of Mississippi with an invalid certificate, with the issuer being it@olemiss\[.\]edu. These characteristics have not been seen in any previous samples from the stated threat actor. Finally, the malware's behavior is the main reason the sample most likely has nothing to do with the Equation Group.

### **Technical Analysis of a Dixie-Playing Bootkit**

The sample (SHA256 hash: 950243a133db44e93b764e03c8d06b99310686d010b52b67f4effa57f0d72e04) is a 64-bit DLL and has two exported functions, dll\_u and install.

Invoking the install export deletes any previous installations of the malware and creates a new scheduled task for persistence by using the following command:

* schtasks /create /tn w32analytics /sc ONCE /st 07:00 /ru SYSTEM /tr \\"rundll32 w32analytics.dll,dll\_u\\"

This creates a scheduled task named w32analytics that is set to run once at 7:00 AM under the SYSTEM account. When triggered, this task executes the exported function dll\_u from w32analytics.dll using the rundll32 command.

The dll\_u function first uses [zlib](https://www.zlib.net/) to decompress an embedded payload into memory. The decompressed payload is a 35 MB disk image. This image is a hybrid GRUB 2 bootloader designed to be compatible with both [BIOS](https://en.wikipedia.org/wiki/BIOS) and [UEFI](https://en.wikipedia.org/wiki/UEFI) systems.

The image is made of the following:

* A GRUB 2 master boot record (MBR)
* A BIOS boot partition that is the second stage of a GRUB 2 BIOS bootloader
* An EFI system partition (ESP) that contains the necessary data and files to run on a UEFI system

The threat then installs the bootloader on every physical disk with one of two options depending on the Windows OS version.

For Windows Vista and above, it drops a legitimate signed kernel driver named ampa.sys (SHA256 hash: 01D51DF682136CCE453BB1DA8964073E6BC7297CE4DAE7301C753BB618A69469) to disk, which is embedded in the resource section. The driver is later abused for the installation of the GRUB 2 bootloader disk image.

The installation procedure is as follows:

1. Create the driver file in C:\\Windows\\System32\\ampa.sys
2. Adjust the process token with SeLoadDriverPrivilege privilege
3. Create the driver service in the Windows registry and set the needed values under HKLM\\System\\CurrentControlSet\\Services\\ampa
4. Load the driver with NtLoadDriver
5. Delete the driver service in the registry

The malware installs the driver programmatically by dynamically resolving and executing the following API functions:

* NtLoadDriver
* NtUnloadDriver
* RtlInitAnsiString
* RtlAnsiStringToUnicodeString
* RtlFreeUnicodeString
* LookupPrivilegeValueA
* OpenProcessToken
* AdjustTokenPrivileges
* RegOpenKeyExA
* RegCloseKey
* RegCreateKeyExA
* RegDeleteKeyA
* RegQueryValueExA
* RegSetValueExA

Now that the driver is loaded into kernel space, it abuses its write dispatch routine to write the bootloader into the first sector of each disk with the help of the drivers' symbolic link \\\\.\\wowrt\\DR\\DISK%u.

When the malware is executed on a Windows version earlier than Vista, it uses the \\.\\PhysicalDrive%u symbolic link to install the bootloader.

After the bootloader is installed, it again creates the driver service in the registry to unload the driver from kernel space with NtUnloadDriver. When the driver is unloaded, it additionally overwrites the driver file on disk with zero bytes before it finally deletes it with DeleteFile.

Figure 2 shows the driver deletion routine.
![Screenshot from IDA Pro of a few lines of code. Delete\_driver at the top is highlighted in yellow.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/03/word-image-162970-138652-2.png) Figure 2. Kernel driver deletion procedure as shown by [IDA Pro's decompiler](https://hex-rays.com/decompiler).

Finally, the malware tries to get SeShutdownPrivilege token rights to force a system reboot with the ExitWindowsEx function to trigger the bootloader execution.

When rebooted, the GRUB 2 bootloader shows an image and periodically plays [Dixie](<https://en.wikipedia.org/wiki/Dixie_(song)>) through the PC speaker. This behavior could indicate that the malware is an offensive prank. Notably, patching a system with this customized GRUB 2 bootloader image of the malware only works on certain disk configurations.

We performed multiple tests on various Windows 10 virtual machines (VM) using both BIOS and UEFI firmware options during installation. Table 3 shows the results of execution on those test VMs along their corresponding partition configurations and firmware versions.

|-----------------------------------------------------------------------------------------------------------------|----------------------------------------------|--------------------------|--------------------------|---------------------------------|
| **Partition structure (first partition on the left and last partition on the right, visually divided by "|")** | **Firmware option used during installation** | **BIOS boot successful** | **UEFI boot successful** | **UEFI Secure boot successful** |
| | ESP (100 MB) | Windows (60 GB, NTFS) | System Recovery (550 MB) |                                         | UEFI                                         | No                       | No                       | No                              |
| | System Reserved (50 MB, NTFS) | Windows (60 GB, NTFS) | System Recovery (550 MB) |                        | BIOS                                         | Yes                      | Yes                      | No                              |
| | Empty partition (1 GB, NTFS) | ESP (100 MB) | Windows (59 GB, NTFS) |                                     | UEFI (with custom partition structure)       | Yes                      | Yes                      | Yes                             |

Table 3. Test results of malware executed on different Windows 10 systems.

This code was found in the GRUB 2 image extracted from its configuration file:  
function load\_video { if \[ x$feature\_all\_video\_module = xy \]; then insmod all\_video else insmod efi\_gop insmod efi\_uga insmod ieee1275\_fb insmod vbe insmod vga insmod video\_bochs insmod video\_cirrus fi } set linux\_gfx\_mode= export linux\_gfx\_mode load\_video insmod gfxterm insmod png terminal\_output gfxterm background\_image /image.png echo sleep 60 play /dixie.play configfile /grub2/grub.cfg

|----------------------------------------------------------------------------|------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 | function load\_video { if \[ x$feature\_all\_video\_module = xy \]; then insmod all\_video else insmod efi\_gop insmod efi\_uga insmod ieee1275\_fb insmod vbe insmod vga insmod video\_bochs insmod video\_cirrus fi } set linux\_gfx\_mode= export linux\_gfx\_mode load\_video insmod gfxterm insmod png terminal\_output gfxterm background\_image /image.png echo sleep 60 play /dixie.play configfile /grub2/grub.cfg |

The function load\_video checks the availability of all video modules. If no video modules are available, it loads specified video modules.

The commands set linux\_gfx\_mode= and export linux\_gfx\_mode set and export the variable for the Linux graphics mode, while the load\_video function call loads video modules. Modules for the graphics terminal and PNG images are loaded through insmod gfxterm and insmod png respectively.

The output of the terminal is set to the graphics terminal through the command terminal\_output gfxterm. An image is set as a background image for the GRUB menu using the command background\_image /image.png. The GRUB menu is paused for 60 seconds using the commands echo and sleep 60. The Dixie audio file is played during this pause using the command play /dixie.play. Lastly, the location of the main GRUB configuration file is specified through the command configfile /grub2/grub.cfg.

### **Summary of a Dixie-Playing Bootkit**

To our knowledge, this is the first malware that installs a GRUB 2 bootloader. While having a few characteristics of previous Equation Group samples, we do not believe this malware is connected to this threat actor. We believe this malware is a PoC created by somebody from the University of Mississippi and they might have dropped it on a campus computer.

While the abused third-party driver was later also [found to be vulnerable](https://www.loldrivers.io/drivers/ea0e7351-b65c-4c5a-9863-83b9d5efcec3) by Northwave Cyber Security, this malware merely abused it to write the bootloader to disk, because this driver is also unsecured. There is no exploit used, but it rather abuses the driver's unsecured write dispatch routine. The usual term "bring your own vulnerable driver" (BYOVD) wouldn't really fit in this case.

## Example 3: A Red Team Framework Named ProjectGeass

This stood out from the various red team tools we came across in 2024 because it seems to be a new multi-platform post-exploitation framework written from scratch and still in development. This malware is named ProjectGeass and is a self-described beacon Windows sample. The term beacon commonly describes the agent of a post-exploitation toolkit.

This sample was submitted to VirusTotal from Singapore as the only file from that source.

This ProjectGeass sample was developed in C++ and contains several debug messages and artifacts with some indicators of other beacons for Android and Unix/Linux. The sample has the [OpenSSL](https://github.com/openssl/openssl) and [Boost.Asio](https://github.com/boostorg/asio) libraries statically linked, making it quite large at 6 MB.

Interestingly this tool uses the term "maneuver" for the execution of third-party files, indicating that this framework could have been used for a red team/blue team test.

### **Technical Analysis of a Red Team Framework Named ProjectGeass**

The ProjectGeass beacon sample is a 64-bit Windows executable (SHA256 hash: cca5df85920dd2bdaaa2abc152383c9a1391a3e1c4217382a9b0fce5a83d6e0b) that was compiled on Oct. 31, 2023, with Microsoft Visual Studio C++. It has multiple project paths left as debug artifacts, giving a good impression of the inner structure of the project:  
D:\\source\\repos\\ProjectGeass\\beacon\\CommandExecute\\CommandExecuteWindows.cpp D:\\source\\repos\\ProjectGeass\\beacon\\Config\\AppConfigurator.cpp D:\\source\\repos\\ProjectGeass\\beacon\\EndpointInformation\\EndpointInfoCollectorBase.cpp D:\\source\\repos\\ProjectGeass\\beacon\\EndpointInformation\\EndpointInfoCollectorOnWindows.cpp D:\\source\\repos\\ProjectGeass\\beacon\\ExecuteThirdPartyFiles\\ExecuteThirdPartyFilesBase.h D:\\source\\repos\\ProjectGeass\\beacon\\ExecuteThirdPartyFiles\\ExecuteThirdPartyFilesOnWindows.cpp D:\\source\\repos\\ProjectGeass\\beacon\\FileManager\\FilesManagerCommon.h D:\\source\\repos\\ProjectGeass\\beacon\\FileManager\\DownloadFileManager.cpp D:\\source\\repos\\ProjectGeass\\beacon\\FileManager\\FileManager.cpp D:\\source\\repos\\ProjectGeass\\beacon\\FileManager\\UploadFileManager.cpp D:\\source\\repos\\ProjectGeass\\beacon\\KeyLogger\\KeyLoggerImpl.cpp D:\\source\\repos\\ProjectGeass\\beacon\\ListDirectory\\ListDirectoryCrossPlatform.cpp D:\\source\\repos\\ProjectGeass\\beacon\\Network\\Packet.cpp D:\\source\\repos\\ProjectGeass\\beacon\\Network\\TCPClient.cpp D:\\source\\repos\\ProjectGeass\\beacon\\Network\\TCPSession.cpp D:\\source\\repos\\ProjectGeass\\beacon\\Online\\OnlineAndHeartbeat.cpp D:\\source\\repos\\ProjectGeass\\beacon\\ProcessManage\\ProcessManageOnWindows.cpp D:\\source\\repos\\ProjectGeass\\beacon\\ListDirectory\\ListDirectoryBase.h D:\\source\\repos\\ProjectGeass\\beacon\\CommandExecute\\CommandExecuteBase.h D:\\source\\repos\\ProjectGeass\\beacon\\ProcessManage\\ProcessManageBase.h D:\\source\\repos\\ProjectGeass\\beacon\\TaskManage\\TaskHandler.cpp D:\\source\\repos\\ProjectGeass\\beacon\\TaskManage\\TaskProcessor.cpp

|----------------------------------------------------------|----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 | D:\\source\\repos\\ProjectGeass\\beacon\\CommandExecute\\CommandExecuteWindows.cpp D:\\source\\repos\\ProjectGeass\\beacon\\Config\\AppConfigurator.cpp D:\\source\\repos\\ProjectGeass\\beacon\\EndpointInformation\\EndpointInfoCollectorBase.cpp D:\\source\\repos\\ProjectGeass\\beacon\\EndpointInformation\\EndpointInfoCollectorOnWindows.cpp D:\\source\\repos\\ProjectGeass\\beacon\\ExecuteThirdPartyFiles\\ExecuteThirdPartyFilesBase.h D:\\source\\repos\\ProjectGeass\\beacon\\ExecuteThirdPartyFiles\\ExecuteThirdPartyFilesOnWindows.cpp D:\\source\\repos\\ProjectGeass\\beacon\\FileManager\\FilesManagerCommon.h D:\\source\\repos\\ProjectGeass\\beacon\\FileManager\\DownloadFileManager.cpp D:\\source\\repos\\ProjectGeass\\beacon\\FileManager\\FileManager.cpp D:\\source\\repos\\ProjectGeass\\beacon\\FileManager\\UploadFileManager.cpp D:\\source\\repos\\ProjectGeass\\beacon\\KeyLogger\\KeyLoggerImpl.cpp D:\\source\\repos\\ProjectGeass\\beacon\\ListDirectory\\ListDirectoryCrossPlatform.cpp D:\\source\\repos\\ProjectGeass\\beacon\\Network\\Packet.cpp D:\\source\\repos\\ProjectGeass\\beacon\\Network\\TCPClient.cpp D:\\source\\repos\\ProjectGeass\\beacon\\Network\\TCPSession.cpp D:\\source\\repos\\ProjectGeass\\beacon\\Online\\OnlineAndHeartbeat.cpp D:\\source\\repos\\ProjectGeass\\beacon\\ProcessManage\\ProcessManageOnWindows.cpp D:\\source\\repos\\ProjectGeass\\beacon\\ListDirectory\\ListDirectoryBase.h D:\\source\\repos\\ProjectGeass\\beacon\\CommandExecute\\CommandExecuteBase.h D:\\source\\repos\\ProjectGeass\\beacon\\ProcessManage\\ProcessManageBase.h D:\\source\\repos\\ProjectGeass\\beacon\\TaskManage\\TaskHandler.cpp D:\\source\\repos\\ProjectGeass\\beacon\\TaskManage\\TaskProcessor.cpp |

We can use a tool like [SusanRTTI](https://github.com/nccgroup/SusanRTTI) and [GraphWiz](https://www.graphviz.org) to visualize the C++ Run-time type information (RTTI) to get a better understanding of the code structure. Figure 3 shows an excerpt of the class inheritances in this ProjectGeass sample.
![Diagram of classes with blue arrows pointing from a first series to a second series and finally a third series. The classes include KeyLoggerCtrlOnWindows in the first series, ListDiskInformationBase in the second series, and ProcessKillerInterface in the third, among many others.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/03/word-image-165419-138652-3.png) Figure 3. ProjectGeass class inheritances based on the C++ RTTI information.

As noted in Figure 3, the authors named multiple classes Windows or OnWindows, which implies there are other classes with the same purpose but for different operating systems. This ProjectGeass sample also contains a class named ListDirectoryCrossPlatform that hints at support for other platforms. Also, as part of the endpoint collection routines, this sample tries to figure out if the platform it's executed on is Windows, Android, Unix or Linux. All these indicators suggest that ProjectGeass is a multi-platform post-exploitation framework supporting multiple operating systems.

The ProjectGeass beacon has the following features:

* File upload/download
* Execute Windows commands
* Get/set heartbeat data
* Sleep time adjustment
* Enumerate processes
* Start/stop keylogger
* Process listing/termination
* File manager (e.g., create/list/rename/delete directories, files, attributes)
* Receive and execute payloads
* Get endpoint information (e.g., network, disk, user)

While most strings are stored in cleartext, some are encrypted with a simple XOR-based algorithm with each string having its own key. Table 4 shows the decrypted strings with their connected features.

|-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------|------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| **Decrypted Strings**                                                                                                                                                       | **Used To**                                                                                                                                                                                                                              |
| "cmd.exe /C"                                                                                                                                                                | Create a process from pipe data as part of the self-contained commands feature                                                                                                                                                           |
| "Administrators"                                                                                                                                                            | Get network user information as part of the endpoint information collection feature                                                                                                                                                      |
| "ROOT\\CIMV2", "SELECT UUID FROM Win32\_ComputerSystemProduct", "WQL", "UUID"                                                                                                | Get OS information as part of the endpoint information collection feature                                                                                                                                                                |
| "S-1-5-18"                                                                                                                                                                  | Process token adjustment                                                                                                                                                                                                                 |
| "The operating system is: %WINDOWS\_LONG%", "winbrand.dll", "BrandingFormatString"                                                                                           | Used to get the Windows version string (described here: [How to tell the "real" version of Windows your app is running on?](https://dennisbabkin.com/blog/?t=how-to-tell-the-real-version-of-windows-your-app-is-running-on#ver_string)) |
| "MyWindowClass"                                                                                                                                                             | Dummy window for the keylogger                                                                                                                                                                                                           |
| "ROOT\\SecurityCenter", "SELECT \* FROM AntiVirusProduct", "DisplayName"                                                                                                    | Endpoint antivirus information collection via WMI                                                                                                                                                                                        |
| "http", "ipv4.renfei.net", "GET / HTTP/1.0", "Host: ipv4.renfei.net", "Accept: text/plain", "Connection: close", "Invalid response", "Response returned with status code: " | Get an external IP address as part of the endpoint network information collection                                                                                                                                                        |
| "SOFTWARE\\Microsoft\\Cryptography", "MachineGuid"                                                                                                                          | Cryptographic related information                                                                                                                                                                                                        |

Table 4. Decrypted strings and their purposes.

The configuration data is located in the .data section and is RC4-encrypted. This data is implemented as a structure with the decryption key in cleartext (F5g3dsriT05L5RuTfHZlJX4dJfOVRJIsWjLC) followed by the encrypted configuration data.

Table 5 shows the decrypted configuration data.

|--------------------|-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| **Information**    | **Decrypted Data**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| Server address     | 10.4.7\[.\]149                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| Server port        | 7515                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| Server certificate | -----BEGIN CERTIFICATE-----  MIID6zCCAlOgAwIBAgIQOIFwtYsC2Pu4YtNz3mOGBzANBgkqhkiG9w0BAQsFADAO MQwwCgYDVQQDEwNucGQwHhcNMjMxMDI2MDYyNTA4WhcNMzMxMDI3MDYyNTA4WjAO MQwwCgYDVQQDEwNucGQwggGiMA0GCSqGSIb3DQEBAQUAA4IBjwAwggGKAoIBgQC/ j31oOFSGU7Vb/cpv39AMxFBewosWGOAmg+qtSBsz1o0gj/nLKuGquYgYCvfzla4B sLOpbk32Zh32KtOnq+vvQ4d/iK2yFLc6hWD24hGsNQ1uIyFPbnmQ+Xu6hJ9SNv5m WUIo9sxNQCobBS1dEl/n7FN9nX/XGO2ydBRPMJ9ppyrGjY7a9deITgNcqajgUJuW OTq2m4D7T2O8Lgon28tLf5ETiJIrnw+RH+ezt7jiF5oqd+W6hVSmtk57RQHD/u+h bA9u+j6J45gtikeD70kibZ4X3fzv3UNRSj93ubCx/i+H2MdKbvhDULjo83cLlhqj iHZp3wfRO4GeG9i96HANCr7w5o3Cw37fDBYGDJs9KUFeqKAeKLM5xTlh4+A4m+aF herWmRuX6sQnQSkifPdF44gymbYQTs+pWFSwNsoS6jZ+X5kX3Ddr/B07uOqPqaGZ olSjwzGqIB2cOgb7/RotLb7W9dvhhwKlmX11BdQpD0daRPYeXLcuXaS4Fp9nV40C AwEAAaNFMEMwDgYDVR0PAQH/BAQDAgIEMBIGA1UdEwEB/wQIMAYBAf8CAQAwHQYD VR0OBBYEFBSvya4X86b9540iQiX5x+0eGqWqMA0GCSqGSIb3DQEBCwUAA4IBgQAT zWrz+ZfpSpsydRW1LRtCx1FCh6bGlRCJZokiETh4l9G526X413SsUccIhJ5ykbIE vCQPZbhixiUloLCczFUvT2Ey1h5zvABE9ah1iB1CAYzukrS4/TXrkLIBa+UazjIG NKS2favWTH1rv719dh4/YvgatNAXi7TA66k9ji57ojf2DgIzwEV0Sk16seeWqqGs eeHATMkx05kvUTdsdKO4ElzsX4qsfIIzPEe18mL4x0sns40o05b1oMnGFYXtbYV8 4sOB4GfubU+PQBOBzYI1U7RZip+OpHgLTntLLSrbyemKklhcivlTLmI4Vg4uWZw1 pMcd9IQieNWLmesJS8FKDxf9BT0PXrAstNKZ8nx3BZqy3KkdC9CHI9DKDuIqilV2 gMxncdDuTdGV1mgfUrW92fjO08DerfyMv7xhIKTpBYjkek+Y09oVC1OnSC3lVc6I SfelPFioCvBF0lpevtlR/L61Q0qIxOk+o41infeZGS1QmBmE6gvlbtH1C9yZ/RQ= -----END CERTIFICATE----- |
| Proxy address      | -                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| Proxy port         | -                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| Proxy username     | -                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| Proxy password     | -                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| Project ID         | 1726486365509521408                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |
| Mutex ID           | 1726489580380622848                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |
| Online time point  | -                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| Sleep duration     | -                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| Verify certificate | 1 (True)                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |

Table 5. Decrypted beacon configuration data.

### **Summary of a Red Team Framework Named ProjectGeass**

ProjectGeass is a post-exploitation framework that appears to have been developed for a professional or commercial purpose. As we have not yet found any other similar samples, this may be a private or non-public project. We cannot attribute it to any known company or organization. Since this malware uses a Chinese site (ipv4.renfei\[.\]net) to check its host's external IP address, the creator might be Chinese. However, that is all conjecture.

## Conclusion

A number of new and interesting types of malware appeared in the past year, each using strategies that had not been reported before. This article reviewed three examples.

The first piece of malware we examined is a passive IIS backdoor that showed indications that attackers used it in targeted attacks. It was also developed in a programming language rarely used for malware, C++/CLI.

The second sample uses a third-party kernel driver to install a GRUB 2 bootloader, which we have not seen before.

The third sample, named ProjectGeass, appears to be a new post-exploitation framework in development. This may have been created for professional or commercial purposes, and possibly developed by a Chinese speaker.

Palo Alto Networks customers are better protected from these malware samples through [Advanced WildFire](https://www.paloaltonetworks.com/network-security/advanced-wildfire), with its different memory analysis features.

Cortex [XDR](https://docs-cortex.paloaltonetworks.com/p/XDR) and [XSIAM](https://docs-cortex.paloaltonetworks.com/p/XSIAM) are designed to prevent the execution of known malicious malware, and also prevent the execution of unknown malware using Behavioral Threat Protection and machine learning based on the Local Analysis module.

If you think you may have been compromised or have an urgent matter, get in touch with the [Unit 42 Incident Response team](https://start.paloaltonetworks.com/contact-unit42.html) or call:

* North America: Toll Free: +1 (866) 486-4842 (866.4.UNIT42)
* UK: +44.20.3743.3660
* Europe and Middle East: +31.20.299.3130
* Asia: +65.6983.8730
* Japan: +81.50.1790.0200
* Australia: +61.2.4062.7950
* India: 00080005045107

Palo Alto Networks has shared these findings with our fellow Cyber Threat Alliance (CTA) members. CTA members use this intelligence to rapidly deploy protections to their customers and to systematically disrupt malicious cyber actors. Learn more about the [Cyber Threat Alliance](https://www.cyberthreatalliance.org).

## Indicators of Compromise

### IIS Backdoor

SHA256 hash: 15db49717a9e9c1e26f5b1745870b028e0133d430ec14d52884cec28ccd3c8ab

* File size: 238,592 bytes
* File name: proxyscrape.dll
* File name internal: proxyxml\_v4.dll
* File type: 64-bit Windows DLL
* Description: Main module version 2

SHA256 hash: aa2d46665ea230e856689c614edcd9d932d9edad0083bf89c903299d148634a2

* File size: 15,360 bytes
* File name: -
* File name internal: ReflectiveDLL.dll
* File type: 64-bit Windows DLL
* Description: Reflective loader embedded in main module version 2

SHA256 hash: a28d0550524996ca63f26cb19f4b4d82019a1be24490343e9b916d2750162cda

* File size: 19,456 bytes
* File name: VC\_REDIST\_CONFIG\_X64.TXT
* File name internal: -
* File type: 64-bit Windows EXE
* Description: Wrapper application for cmd.exe embedded in main module version 2

SHA256 hash: 8571a354b5cdd9ec3735b84fa207e72c7aea1ab82ea2e4ffea1373335b3e88f4

* File size: 191,488 bytes
* File name: proxyxml.dll
* File name internal: IISShellModule.dll
* File type: 64-bit Windows DLL
* Description: Main module version 1

SHA256 hash: 94017628658035206820723763a2a698a4fd7be98fc2c541aad6aa0281ef090e

* File size: 14,848 bytes
* File name: -
* File name internal: ReflectiveDLL.dll
* File type: 64-bit Windows DLL
* Description: Reflective loader embedded in main module version 1

### Bootkit

SHA256 hash: 950243a133db44e93b764e03c8d06b99310686d010b52b67f4effa57f0d72e04

* File size: 6,444,544 bytes
* File name: w32analytics.dll
* File name internal: loader.dll
* File type: 64-bit Windows DLL

### ProjectGeass

SHA256 hash: cca5df85920dd2bdaaa2abc152383c9a1391a3e1c4217382a9b0fce5a83d6e0b

* File size: 6,040,576 bytes
* File name: -
* File name internal: -
* File type: 64-bit Windows EXE
  Back to top

### Tags

* [.NET](https://unit42.paloaltonetworks.com/tag/net/ ".NET")
* [Backdoor](https://unit42.paloaltonetworks.com/tag/backdoor/ "backdoor")
* [C++](https://unit42.paloaltonetworks.com/tag/c/ "C++")
* [Post-exploitation](https://unit42.paloaltonetworks.com/tag/post-exploitation/ "post-exploitation")
* [Red teaming tool](https://unit42.paloaltonetworks.com/tag/red-teaming-tool/ "red teaming tool")  
  [Threat Research Center](https://unit42.paloaltonetworks.com "Threat Research") [Next: Investigating Scam Crypto Investment Platforms Using Pyramid Schemes to Defraud Victims](https://unit42.paloaltonetworks.com/fraud-crypto-platforms-campaign/ "Investigating Scam Crypto Investment Platforms Using Pyramid Schemes to Defraud Victims")

### Table of Contents

* 

### Related Articles

* [The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution](https://unit42.paloaltonetworks.com/ai-enabled-malware-analysis/ "article - table of contents")
* [CL-STA-1062 Targets Southeast Asian Governments and Critical Infrastructure](https://unit42.paloaltonetworks.com/cl-sta-1062-tinyrct-backdoor/ "article - table of contents")
* [Analyzing the Current State of AI Use in Malware](https://unit42.paloaltonetworks.com/ai-use-in-malware/ "article - table of contents")

## Related Malware Resources

![Pictorial representation of attackers using AI tools to target Latin American organizations. A vibrant cityscape with silhouettes of numerous people walking along a bustling street. The scene is illuminated by bright urban lights and digital-like particles, creating a dynamic and futuristic atmosphere.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/09/AdobeStock_768915868-2-1-786x373.jpg)  
[![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) September 3, 2026 [#### Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America](https://unit42.paloaltonetworks.com/ai-tool-use-targeting-latam-orgs/)

* [Agentic AI](https://unit42.paloaltonetworks.com/tag/agentic-ai/ "Agentic AI")

* [ChatGPT](https://unit42.paloaltonetworks.com/tag/chatgpt/ "ChatGPT")

* [CL-CRI-1131](https://unit42.paloaltonetworks.com/tag/cl-cri-1131/ "CL-CRI-1131")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ai-tool-use-targeting-latam-orgs/ "Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America")  
  ![Pictorial representation of vishing campaigns in Microsoft Teams. A digital image of a skull formed by blue binary code on a black background, with scattered ones and zeros and digital noise, symbolizes how stealthy prompt injection attacks can exploit AI logic to bypass security controls.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/01_Malware_Category_1920x900-5-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 31, 2026 [#### Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams](https://unit42.paloaltonetworks.com/spring-ring-voice-phishing-campaigns/)

* [Cloaked Ursa](https://unit42.paloaltonetworks.com/tag/cloaked-ursa/ "Cloaked Ursa")

* [Entra ID](https://unit42.paloaltonetworks.com/tag/entra-id/ "Entra ID")

* [Microsoft Teams](https://unit42.paloaltonetworks.com/tag/microsoft-teams/ "Microsoft Teams")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/spring-ring-voice-phishing-campaigns/ "Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams")  
  ![Pictorial representation of AI-enabled malware. A vibrant digital interface displaying various icons and graphs, resembling a futuristic network or data analysis dashboard. The scene is illuminated with glowing lights and patterns.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/AdobeStock_1270203474-2-1-786x368.png)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 25, 2026 [#### The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution](https://unit42.paloaltonetworks.com/ai-enabled-malware-analysis/)

* [Backdoor](https://unit42.paloaltonetworks.com/tag/backdoor/ "backdoor")

* [Bitcoin](https://unit42.paloaltonetworks.com/tag/bitcoin/ "Bitcoin")

* [DLL hijacking](https://unit42.paloaltonetworks.com/tag/dll-hijacking/ "DLL hijacking")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ai-enabled-malware-analysis/ "The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution")  
  ![Pictorial representation of identity abuse through trusted communication channels. Close-up view of a digital screen displaying a glitched and pixelated image of a skull-like shape.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/02_Malware_Category_1920x900-2-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 20, 2026 [#### Identity Abuse Through Trusted Communication Channels](https://unit42.paloaltonetworks.com/communication-channel-identity-risks/)

* [Authentication](https://unit42.paloaltonetworks.com/tag/authentication/ "authentication")

* [Identity theft](https://unit42.paloaltonetworks.com/tag/identity-theft/ "identity theft")

* [Malware](https://unit42.paloaltonetworks.com/tag/malware/ "malware")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/communication-channel-identity-risks/ "Identity Abuse Through Trusted Communication Channels")  
  ![Pictorial representation of Kimwolf botnet malware family. Digital screen with a warning sign reading "Malware." The background features lines of computer code and graphics, creating a sense of cybersecurity threat.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/07_Malware_Category_1920x900-3-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 11, 2026 [#### Kimwolf v7: An Evolution of the Kimwolf Botnet](https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/)

* [Android APK](https://unit42.paloaltonetworks.com/tag/android-apk/ "Android APK")

* [Ethereum](https://unit42.paloaltonetworks.com/tag/ethereum/ "Ethereum")

* [HTTP](https://unit42.paloaltonetworks.com/tag/http/ "HTTP")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/ "Kimwolf v7: An Evolution of the Kimwolf Botnet")  
  ![Pictorial representatiom pf Aeternum's blockchain C2. A close-up of a computer circuit board with a central microchip is depicted. Red digital data streams in the form of glowing binary numbers and arrows appear to flow in and out of the chip. The scene is illuminated with a futuristic blue and red glow.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/04_Malware_Category_1920x900-4-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 10, 2026 [#### The Permanent Threat: Analyzing Aeternum's Blockchain-Based C2 Operations and Communications](https://unit42.paloaltonetworks.com/aeternum-blockchain-c2-analysis/)

* [Aeternum](https://unit42.paloaltonetworks.com/tag/aeternum/ "Aeternum")

* [Infection chain](https://unit42.paloaltonetworks.com/tag/infection-chain/ "infection chain")

* [JSON](https://unit42.paloaltonetworks.com/tag/json/ "JSON")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/aeternum-blockchain-c2-analysis/ "The Permanent Threat: Analyzing Aeternum’s Blockchain-Based C2 Operations and Communications")  
  ![Pictorial representation of ChainDrop, a self-propagating npm worm. An artistic depiction of a digital workspace featuring an open laptop with a red virus on the screen.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/03_Malware_Category_1920x900-7-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)High Profile Threats](https://unit42.paloaltonetworks.com/category/top-cyberthreats/) August 6, 2026 [#### ChainDrop: Inside a Self-Propagating npm Worm](https://unit42.paloaltonetworks.com/chaindrop-npm-worm-analysis/)

* [Blockchain](https://unit42.paloaltonetworks.com/tag/blockchain/ "blockchain")

* [ChainDrop](https://unit42.paloaltonetworks.com/tag/chaindrop/ "ChainDrop")

* [Claude code](https://unit42.paloaltonetworks.com/tag/claude-code/ "Claude code")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/chaindrop-npm-worm-analysis/ "ChainDrop: Inside a Self-Propagating npm Worm")  
  ![Pictorial representation of Token-jacking. A person types on a laptop with multiple digital interface elements projected, including an "AI" icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/AdobeStock_1246251272-2-786x369.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 6, 2026 [#### Token Jacking: Cybercriminals Could Be Stealing Your AI Resources](https://unit42.paloaltonetworks.com/ai-token-jacking/)

* [AI API](https://unit42.paloaltonetworks.com/tag/ai-api/ "AI API")

* [AI gateway](https://unit42.paloaltonetworks.com/tag/ai-gateway/ "AI gateway")

* [API keys](https://unit42.paloaltonetworks.com/tag/api-keys/ "API keys")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ai-token-jacking/ "Token Jacking: Cybercriminals Could Be Stealing Your AI Resources")  
  ![Pictorial representation of malware bypassing DNS and communicating directly to IP addresses. Futuristic digital cityscape with glowing blue and orange geometric structures, resembling skyscrapers.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/07_DNS_Overview_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 4, 2026 [#### Almost Half of Malware Samples Communicate Direct to IP](https://unit42.paloaltonetworks.com/malware-bypass-dns-direct-to-ip/)

* [Command and Control](https://unit42.paloaltonetworks.com/tag/command-and-control/ "Command and Control")

* [D2IP](https://unit42.paloaltonetworks.com/tag/d2ip/ "D2IP")

* [Exfiltration](https://unit42.paloaltonetworks.com/tag/exfiltration/ "exfiltration")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/malware-bypass-dns-direct-to-ip/ "Almost Half of Malware Samples Communicate Direct to IP")  
  ![Pictorial representation of passwordless authentication. East Asian woman examining data on multiple screens in a high-tech environment, surrounded by digital graphics and code.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/07/07_Cloud_cybersecurity_research_Overview_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 3, 2026 [#### Pass the Passkey: A Novel Attack Surface in Passwordless Authentication](https://unit42.paloaltonetworks.com/passwordless-authentication-security-risks/)

* [Google authenticator](https://unit42.paloaltonetworks.com/tag/google-authenticator/ "google authenticator")

* [Google Chrome](https://unit42.paloaltonetworks.com/tag/google-chrome/ "Google Chrome")

* [Google Cloud](https://unit42.paloaltonetworks.com/tag/google-cloud/ "Google Cloud")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/passwordless-authentication-security-risks/ "Pass the Passkey: A Novel Attack Surface in Passwordless Authentication")

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)  
  ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg) ![Enlarged Image]()  
  ![Newsletter](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/unit42-footer-subscribe-desktop.png)  
  ![UNIT 42 Small Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/palo-alto-logo-small.svg) Get updates from Unit 42

## Peace of mind comes from staying ahead of threats. Subscribe today.

Your Email

Subscribe for email updates to all Unit 42 threat research.  
By submitting this form, you agree to our [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use "Terms of Use") and acknowledge our [Privacy Statement.](https://www.paloaltonetworks.com/legal-notices/privacy "Privacy Statement")

This site is protected by reCAPTCHA and the Google [Privacy Policy](https://policies.google.com/privacy) and [Terms of Service](https://policies.google.com/terms) apply.

Invalid captcha!
Subscribe ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg) ![loader](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-loader.svg)  
{#footer} Products and Services

* [AI-Powered Network Security Platform](https://www.paloaltonetworks.com/network-security)

* [Secure AI by Design](https://www.paloaltonetworks.com/ai-security)

* [Prisma AIRS](https://www.paloaltonetworks.com/ai-security/prisma-airs)

* [AI Access Security](https://www.paloaltonetworks.com/sase/ai-access-security)

* [Cloud Delivered Security Services](https://www.paloaltonetworks.com/network-security/security-subscriptions)

* [Advanced Threat Prevention](https://www.paloaltonetworks.com/network-security/advanced-threat-prevention)

* [Advanced URL Filtering](https://www.paloaltonetworks.com/network-security/advanced-url-filtering)

* [Advanced WildFire](https://www.paloaltonetworks.com/network-security/advanced-wildfire)

* [Advanced DNS Security](https://www.paloaltonetworks.com/network-security/advanced-dns-security)

* [Enterprise Data Loss Prevention](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention)

* [Enterprise IoT Security](https://www.paloaltonetworks.com/network-security/enterprise-device-security)

* [Medical IoT Security](https://www.paloaltonetworks.com/network-security/medical-device-security)

* [Industrial OT Security](https://www.paloaltonetworks.com/network-security/ot-security-solution)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security)

* [Next-Generation Firewalls](https://www.paloaltonetworks.com/network-security/next-generation-firewall)

* [Hardware Firewalls](https://www.paloaltonetworks.com/network-security/hardware-firewall-innovations)

* [Software Firewalls](https://www.paloaltonetworks.com/network-security/software-firewalls)

* [Strata Cloud Manager](https://www.paloaltonetworks.com/network-security/strata-cloud-manager)

* [SD-WAN for NGFW](https://www.paloaltonetworks.com/network-security/sd-wan-subscription)

* [PAN-OS](https://www.paloaltonetworks.com/network-security/pan-os)

* [Panorama](https://www.paloaltonetworks.com/network-security/panorama)

* [Secure Access Service Edge](https://www.paloaltonetworks.com/sase)

* [Prisma SASE](https://www.paloaltonetworks.com/sase)

* [Application Acceleration](https://www.paloaltonetworks.com/sase/app-acceleration)

* [Autonomous Digital Experience Management](https://www.paloaltonetworks.com/sase/adem)

* [Enterprise DLP](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention)

* [Prisma Access](https://www.paloaltonetworks.com/sase/access)

* [Prisma Browser](https://www.paloaltonetworks.com/sase/prisma-browser)

* [Prisma SD-WAN](https://www.paloaltonetworks.com/sase/sd-wan)

* [Remote Browser Isolation](https://www.paloaltonetworks.com/sase/remote-browser-isolation)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security)

* [AI-Driven Security Operations Platform](https://www.paloaltonetworks.com/cortex)

* [Cloud Security](https://www.paloaltonetworks.com/cortex/cloud)

* [Cortex Cloud](https://www.paloaltonetworks.com/cortex/cloud)

* [Application Security](https://www.paloaltonetworks.com/cortex/cloud/application-security)

* [Cloud Posture Security](https://www.paloaltonetworks.com/cortex/cloud/cloud-posture-security)

* [Cloud Runtime Security](https://www.paloaltonetworks.com/cortex/cloud/runtime-security)

* [Prisma Cloud](https://www.paloaltonetworks.com/prisma/cloud)

* [AI-Driven SOC](https://www.paloaltonetworks.com/cortex)

* [Cortex XSIAM](https://www.paloaltonetworks.com/cortex/cortex-xsiam)

* [Cortex XDR](https://www.paloaltonetworks.com/cortex/cortex-xdr)

* [Cortex XSOAR](https://www.paloaltonetworks.com/cortex/cortex-xsoar)

* [Cortex Xpanse](https://www.paloaltonetworks.com/cortex/cortex-xpanse)

* [Unit 42 Managed Detection \& Response](https://www.paloaltonetworks.com/cortex/managed-detection-and-response)

* [Managed XSIAM](https://www.paloaltonetworks.com/cortex/managed-xsiam)

* [Next-Generation Identity Security](https://www.paloaltonetworks.com/idira)

* [Privileged Access Management](https://www.paloaltonetworks.com/idira/human/privileged-access-management)

* [Identity and Access Management](https://www.paloaltonetworks.com/idira/human/identity-and-access-management)

* [Endpoint Privilege Manager](https://www.paloaltonetworks.com/idira/human/endpoint-privilege-manager)

* [Identity Governance](https://www.paloaltonetworks.com/idira/human/identity-governance)

* [Workforce Password Management](https://www.paloaltonetworks.com/idira/human/workforce-password-management)

* [Agentic Identities](https://www.paloaltonetworks.com/idira/agentic)

* [Secrets Management](https://www.paloaltonetworks.com/idira/machine/secrets-management)

* [Unified Secrets Governance](https://www.paloaltonetworks.com/idira/machine/unified-secrets-governance)

* [Application Credentials Delivery](https://www.paloaltonetworks.com/idira/machine/application-credentials-delivery)

* [Vendor Privileged Access](https://www.paloaltonetworks.com/idira/human/vendor-privileged-access)

* [Threat Intel and Incident Response Services](https://www.paloaltonetworks.com/unit42)

* [Proactive Assessments](https://www.paloaltonetworks.com/unit42/assess)

* [Incident Response](https://www.paloaltonetworks.com/unit42/respond)

* [Transform Your Security Strategy](https://www.paloaltonetworks.com/unit42/transform)

* [Discover Threat Intelligence](https://www.paloaltonetworks.com/unit42/threat-intelligence-partners)  
  Company

* [About Us](https://www.paloaltonetworks.com/about-us)

* [Careers](https://jobs.paloaltonetworks.com/en/)

* [Contact Us](https://www.paloaltonetworks.com/company/contact-sales)

* [Corporate Responsibility](https://www.paloaltonetworks.com/about-us/corporate-responsibility)

* [Customers](https://www.paloaltonetworks.com/customers)

* [Investor Relations](https://investors.paloaltonetworks.com/)

* [Location](https://www.paloaltonetworks.com/about-us/locations)

* [Newsroom](https://www.paloaltonetworks.com/company/newsroom)  
  Popular Links

* [Blog](https://www.paloaltonetworks.com/blog/)

* [Communities](https://www.paloaltonetworks.com/communities)

* [Content Library](https://www.paloaltonetworks.com/resources)

* [Cyberpedia](https://www.paloaltonetworks.com/cyberpedia)

* [Event Center](https://events.paloaltonetworks.com/)

* [Manage Email Preferences](https://start.paloaltonetworks.com/preference-center)

* [Products A-Z](https://www.paloaltonetworks.com/products/products-a-z)

* [Product Certifications](https://www.paloaltonetworks.com/legal-notices/trust-center/certifications)

* [Report a Vulnerability](https://www.paloaltonetworks.com/security-disclosure)

* [Sitemap](https://www.paloaltonetworks.com/sitemap)

* [Tech Docs](https://docs.paloaltonetworks.com/)

* [Unit 42](https://unit42.paloaltonetworks.com/)

* [Do Not Sell or Share My Personal Information](https://panwedd.exterro.net/portal/dsar.htm?target=panwedd)
  ![Palo Alto Networks Logo](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/pan-logo-dark.svg)

* [Privacy](https://www.paloaltonetworks.com/legal-notices/privacy)

* [Trust Center](https://www.paloaltonetworks.com/legal-notices/trust-center)

* [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use)

* [Documents](https://www.paloaltonetworks.com/legal)

Copyright © 2026 Palo Alto Networks. All Rights Reserved

* [![Youtube](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/youtube-black.svg)](https://www.youtube.com/user/paloaltonetworks)
* [![Podcast](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/icons/podcast.svg)](https://www.paloaltonetworks.com/podcasts/threat-vector)
* [![Facebook](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/facebook-black.svg)](https://www.facebook.com/PaloAltoNetworks/)
* [![LinkedIn](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/linkedin-black.svg)](https://www.linkedin.com/company/palo-alto-networks)
* [![Twitter](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/twitter-x-black.svg)](https://twitter.com/PaloAltoNtwks)
* EN  
  Select your language  
  ![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg) ![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg) ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg)

### Default Heading

Read the article ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg)  
Seekbar

![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg)  
![Volume](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-volume.svg)  
Volume
![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg)
