[![Logo](https://www.paloaltonetworks.com/wp-content/uploads/2021/07/PANW_Parent.png)](https://www.paloaltonetworks.com/)  
[![Unit42 Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/unit42-logo-white.svg)](https://unit42.paloaltonetworks.com/)  
Menu

* [Tools](https://unit42.paloaltonetworks.com/tools/)
* [ATOMs](https://unit42.paloaltonetworks.com/atoms/)
* [Security Consulting](https://www.paloaltonetworks.com/unit42)
* [About Us](https://unit42.paloaltonetworks.com/about-unit-42/)
* [**Under Attack?**](https://start.paloaltonetworks.com/contact-unit42.html)  
  English
* [English](https://unit42.paloaltonetworks.com/vatet-pyxie-defray777/)
* [Japanese](https://unit42.paloaltonetworks.com/ja/vatet-pyxie-defray777/)
* [Threat Research Center](https://unit42.paloaltonetworks.com "Threat Research")
* [Threat Actor Groups](https://unit42.paloaltonetworks.com/category/threat-actor-groups/ "Threat Actor Groups")
* [Ransomware](https://unit42.paloaltonetworks.com/category/ransomware/ "Ransomware")  
  [Ransomware](https://unit42.paloaltonetworks.com/category/ransomware/)

# When Threat Actors Fly Under the Radar: Vatet, PyXie and Defray777

![Clock Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-clock.svg) 26 min read  
Related Products  
[![Managed Threat Hunting icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/unit42_RGB_logo_Icon_Color.png)Managed Threat Hunting](https://unit42.paloaltonetworks.com/product-category/managed-threat-hunting/ "Managed Threat Hunting")[![Unit 42 Incident Response icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/unit42_RGB_logo_Icon_Color.png)Unit 42 Incident Response](https://unit42.paloaltonetworks.com/product-category/unit-42-incident-response/ "Unit 42 Incident Response")

* ![Profile Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-profile-grey.svg)  
  By:
  
  * [Ryan Tracey](https://unit42.paloaltonetworks.com/author/ryan-tracey/)
  * [Drew Schmitt](https://unit42.paloaltonetworks.com/author/drew-schmitt/)

* ![Published Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-calendar-grey.svg)  
  Published:November 6, 2020

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-category.svg)  
  Categories:
  
  * [Malware](https://unit42.paloaltonetworks.com/category/malware/)
  * [Ransomware](https://unit42.paloaltonetworks.com/category/ransomware/)
  * [Threat Actor Groups](https://unit42.paloaltonetworks.com/category/threat-actor-groups/)

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-tags-grey.svg)  
  Tags:
  
  * [Defray777](https://unit42.paloaltonetworks.com/tag/defray777/)
  * [Prying Libra](https://unit42.paloaltonetworks.com/tag/prying-libra/)
  * [PyXie](https://unit42.paloaltonetworks.com/tag/pyxie/)
  * [Vatet](https://unit42.paloaltonetworks.com/tag/vatet/)

* [![Download Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-download.svg)](https://unit42.paloaltonetworks.com/vatet-pyxie-defray777/?pdf=download&lg=en&_wpnonce=92524fc9d4 "Click here to download")

* [![Print Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-print.svg)](https://unit42.paloaltonetworks.com/vatet-pyxie-defray777/?pdf=print&lg=en&_wpnonce=92524fc9d4 "Click here to print")

Share![Down arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/down-arrow.svg)

* ![Link Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-share-link.svg)
* [![Link Email](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-sms.svg)](mailto:?subject=When%20Threat%20Actors%20Fly%20Under%20the%20Radar:%20Vatet,%20PyXie%20and%20Defray777&body=Check%20out%20this%20article%20https%3A%2F%2Funit42.paloaltonetworks.com%2Fvatet-pyxie-defray777%2F "Share in email")
* [![Facebook Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-fb-share.svg)](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Funit42.paloaltonetworks.com%2Fvatet-pyxie-defray777%2F "Share in Facebook")
* [![LinkedIn Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-linkedin-share.svg)](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fvatet-pyxie-defray777%2F&title=When%20Threat%20Actors%20Fly%20Under%20the%20Radar:%20Vatet,%20PyXie%20and%20Defray777 "Share in LinkedIn")
* [![Twitter Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-twitter-share.svg)](https://twitter.com/intent/tweet?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fvatet-pyxie-defray777%2F&text=When%20Threat%20Actors%20Fly%20Under%20the%20Radar:%20Vatet,%20PyXie%20and%20Defray777 "Share in Twitter")
* [![Reddit Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-reddit-share.svg)](https://www.paloaltonetworks.com//www.reddit.com/submit?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fvatet-pyxie-defray777%2F&ts=markdown "Share in Reddit")
* [![Mastodon Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-mastodon-share.svg)](https://mastodon.social/share?text=When%20Threat%20Actors%20Fly%20Under%20the%20Radar:%20Vatet,%20PyXie%20and%20Defray777%20https%3A%2F%2Funit42.paloaltonetworks.com%2Fvatet-pyxie-defray777%2F "Share in Mastodon")

## Last, but Not Least: Defray777

Defray777 is an elusive family of ransomware also known as [Ransom X](https://www.bleepingcomputer.com/news/security/new-ransom-x-ransomware-used-in-texas-txdot-cyberattack/) and [RansomExx](https://www.bleepingcomputer.com/news/security/montreals-stm-public-transport-system-hit-by-ransomware-attack/?_hsenc=p2ANqtz--TMeD-DcOlE_JbE5-1DKkStefcr1qAFppJIfTyGcye3y_Z5SsaryNC0zrBu7qu5iPsiwx0&utm_campaign=Ad%20hoc%20social%20posts%20&utm_content=143516149&utm_medium=social&utm_source=twitter&hss_channel=tw-29175108). Although it has recently been covered in the news as a new family, it has been in use since at least 2018 and is responsible for a number of high-profile ransomware incidents -- as detailed in the articles we linked to.

Defray777 runs entirely in memory, which is why there have been so few publicly discussed samples to date. In several recent incidents, Defray777 was loaded into memory and executed by Cobalt Strike, which was delivered by the Vatet loader.

During our research, we discovered multiple decryptors for this ransomware family, going back as early as 2018. Reviewing decryptors from 2018 until present shows that there has been consistency in the ransomware's encryption and decryption methodology, as well as the use of [Themida](https://www.oreans.com/themida.php) for packing their decryptors. Table 10 shows a list of Defray777 decryptors discovered in [AutoFocus](https://www.paloaltonetworks.com/cortex/autofocus), with a list of organizations that suffered ransomware attacks. This shows that Defray777 has been consistently active since 2018.

|------------|-------------------------------------------|
| **Date**   | **Victim**                                |
| 12/7/2018  | Education Organization                    |
| 2/4/2019   | Healthcare Organization                   |
| 3/1/2019   | Technology Organization                   |
| 3/15/2019  | Education Organization                    |
| 8/8/2019   | Healthcare Organization                   |
| 8/25/2019  | Education Organization                    |
| 8/28/2019  | Transportation and Logistics Organization |
| 9/3/2019   | Legal Organization                        |
| 9/6/2019   | Education Organization                    |
| 9/26/2019  | Healthcare Organization                   |
| 10/30/2019 | Government Organization                   |
| 11/1/2019  | Healthcare Organization                   |
| 2/4/2020   | Technology Organization                   |
| 2/10/2020  | Government Organization                   |
| 3/16/2020  | Food Organization                         |
| 10/17/2020 | Finance Organization                      |

*Table 10. Defray777 ransomware attacks listed by date and victim.*
![Messages from the Defray777 decryptor. These messages include: "Click OK to start decryption. You will be informed when all files will be recovered." And "All files are successfully decrypted. Have a nice day!"](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/11/word-image-34.png) Figure 21. Defray777 decryptor.

We have examined several recent Defray777 samples, including one sample that was obtained directly from memory during a recent incident. Our in-depth analysis resulted in the findings outlined below.

#### **Decrypted Strings**

The string decryption process is the same as we saw with PyXie. The following strings were decrypted from a recent Defray777 sample:

|-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| Already active \[%s\]  +%u (%u) files done \[%s\] \[%u KB/s\] Started (PID: %u; Workers: %u; AES-%s) \[%s\] Complete (+%u (%u) files done) \[%s\] Work time: %d:%02d:%02d Unable to get computer name CryptoGuard kernel32.dll ConvertStringSecurityDescriptorToSecurityDescriptorW advapi32.dll IsWow64Process SystemDrive KiUserExceptionDispatcher |

*Table 11. Defray777 encrypted strings.*

#### **Prioritizing Defray777 on the Impacted System**

While deep diving on a recovered Defray777 sample, we found that Defray777 exhibits the following notable characteristics regarding the prioritization of threads and processes:

* During execution, the ransomware uses SetProcessPriorityBoost to prioritize the threads of the Defray777 process.
* Defray777 additionally focuses on creating and prioritizing threads for encryption by calling SetThreadAffinityMask and SetThreadPriorityBoost.
* Defray777 uses multithreading to improve ransomware performance.

![Defray777 focuses on creating and prioritizing threads for encryption by calling SetThreadAffinityMask and SetThreadPriorityBoost, as shown here.](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/11/word-image-35.png) Figure 22. Prioritization of Defray777 threads during execution.

#### **Killing "Undesirable" Processes**

As part of the execution workflow, Defray777 creates threads that will be responsible for the killing of processes that the threat actors deem to be "undesirable." The execution continues by getting a listing of processes using CreateToolhelp32Snapshot before iterating through all active processes (with the exception of itself) and killing all "undesirable" processes. Defray777 specifically targets process that can be opened with the desired access of SYNCHRONIZE | PROCESS\_QUERY\_INFORMATION | PROCESS\_VM\_WRITE | PROCESS\_VM\_READ | PROCESS\_VM\_OPERATION | PROCESS\_CREATE\_THREAD.

Defray777 excludes all processes that contain the system file path in their full image path. Additionally, the ransomware will exclude the following processes from being killed during execution:

|----------------|--------------|
| powershell.exe | rundll32.exe |
| wefault.exe    | explorer.exe |
| vmnat.exe      |              |

*Table 12. Excluded processes.*

#### **Stopping System Services**

During execution, Defray777 stops the following services from running:

|--------------------------------|---------------------------------|----------------------------------|-----------------------------------|
| Acronis VSS Provider           | MSExchangeADTopology            | MSSQLSERVER                      | SQLAgent$PRACTTICEMGT             |
| AcronisAgent                   | MSExchangeAntispamUpdate        | MSSQLServerADHelper              | SQLAgent$PROD                     |
| AcronixAgent                   | MSExchangeEdgeSync              | MSSQLServerADHelper100           | SQLAgent$PROFXENGAGEMENT          |
| AcrSch2Svc                     | MSExchangeES                    | MSSQLServerOLAPService           | SQLAgent$SBSMONITORING            |
| Antivirus                      | MSExchangeFBA                   | MySQL57                          | SQLAgent$SHAREPOINT               |
| ARSM                           | MSExchangeFDS                   | MySQL80                          | SQLAgent$SOPHOS                   |
| AVP                            | MSExchangeIS                    | NetMsmqActivator                 | SQLAgent$SQL\_2008                 |
| BackupExecAgentAccelerator     | MSExchangeMailboxAssistants     | nginx                            | SQLAgent$SQLEXPRESS               |
| BackupExecAgentBrowser         | MSExchangeMailboxReplication    | ntrtscan                         | SQLAgent$SYSTEM\_BGC               |
| BackupExecDeviceMediaService   | MSExchangeMailSubmission        | OracleClientCache80              | SQLAgent$TPS                      |
| BackupExecJobEngine            | MSExchangeMGMT                  | OracleServiceXE                  | SQLAgent$TPSAMA                   |
| BackupExecManagementService    | MSExchangeMTA                   | OracleXETNSListener              | SQLAgent$VEEAMSQL2008R2           |
| BackupExecRPCService           | MSExchangeProtectedServiceHost  | PDVFSService                     | SQLAgent$VEEAMSQL2012             |
| BackupExecVSSProvider          | MSExchangeRepl                  | POP3Svc                          | SQLBrowser                        |
| bedbg                          | MSExchangeRPC                   | ReportServer                     | SQLsafe Backup Service            |
| DbxSvc                         | MSExchangeSA                    | ReportServer$SQL\_2008            | SQLsafe Filter Service            |
| DCAgent                        | MSExchangeSearch                | ReportServer$SYSTEM\_BGC          | SQLSafeOLRService                 |
| EhttpSrv                       | MSExchangeServiceHost           | ReportServer$TPS                 | SQLSERVERAGENT                    |
| ekrn                           | MSExchangeSRS                   | ReportServer$TPSAMA              | SQLTELEMETRY                      |
| Enterprise Client Service      | MSExchangeThrottling            | RESvc                            | SQLTELEMETRY$ECWDB2               |
| EPSecurityService              | MSExchangeTransport             | sacsvr                           | SQLWriter                         |
| EPUpdateService                | MSExchangeTransportLogSearch    | SamSs                            | SstpSvc                           |
| EraserSvc11710                 | msftesql$PROD                   | SAVAdminService                  | svcGenericHost                    |
| EsgShKernel                    | MSOLAP$SQL\_2008                 | SAVService                       | swi\_filter                        |
| ESHASRV                        | MSOLAP$SYSTEM\_BGC               | SDRSVC                           | swi\_service                       |
| FA\_Scheduler                   | MSOLAP$TPS                      | SepMasterService                 | swi\_update                        |
| IISAdmin                       | MSOLAP$TPSAMA                   | ShMonitor                        | swi\_update\_64                     |
| IMAP4Svc                       | MSSQL$BKUPEXEC                  | Smcinst                          | Symantec System Recovery          |
| KAVFS                          | MSSQL$ECWDB2                    | SmcService                       | TmCCSF                            |
| KAVFSGT                        | MSSQL$PRACTICEMGT               | SMTPSvc                          | tmlisten                          |
| kavfsslp                       | MSSQL$PRACTTICEBGC              | SNAC                             | TrueKey                           |
| klnagent                       | MSSQL$PROD                      | SntpService                      | TrueKeyScheduler                  |
| macmnsvc                       | MSSQL$PROFXENGAGEMENT           | Sophos Agent                     | TrueKeyServiceHelper              |
| masvc                          | MSSQL$SBSMONITORING             | Sophos AutoUpdate Service        | UI0Detect                         |
| MBAMService                    | MSSQL$SHAREPOINT                | Sophos Clean Service             | Veeam Backup Catalog Data Service |
| MBEndpointAgent                | MSSQL$SOPHOS                    | Sophos Device Control Service    | VeeamBackupSvc                    |
| McAfeeEngineService            | MSSQL$SQL\_2008                  | Sophos File Scanner Service      | VeeamBrokerSvc                    |
| McAfeeFramework                | MSSQL$SQLEXPRESS                | Sophos Health Service            | VeeamCatalogSvc                   |
| McAfeeFrameworkMcAfeeFramework | MSSQL$SYSTEM\_BGC                | Sophos MCS Agent                 | VeeamCloudSvc                     |
| McShield                       | MSSQL$TPS                       | Sophos MCS Client                | VeeamDeploymentService            |
| McTaskManager                  | MSSQL$TPSAMA                    | Sophos Message Router            | VeeamDeploySvc                    |
| mfefire                        | MSSQL$VEEAMSQL2008R2            | Sophos Safestore Service         | VeeamEnterpriseManagerSvc         |
| mfemms                         | MSSQL$VEEAMSQL2012              | Sophos System Protection Service | VeeamHvIntegrationSvc             |
| mfevtp                         | MSSQLFDLauncher                 | Sophos Web Control Service       | VeeamMountSvc                     |
| MMS                            | MSSQLFDLauncher$PROFXENGAGEMENT | sophossps                        | VeeamNFSSvc                       |
| MongoDB                        | MSSQLFDLauncher$SBSMONITORING   | SQL Backups                      | VeeamRESTSvc                      |
| mozyprobackup                  | MSSQLFDLauncher$SHAREPOINT      | SQLAgent$BKUPEXEC                | VeeamTransportSvc                 |
| MsDtsServer                    | MSSQLFDLauncher$SQL\_2008        | SQLAgent$CITRIX\_METAFRAME        | W3Svc                             |
| MsDtsServer100                 | MSSQLFDLauncher$SYSTEM\_BGC      | SQLAgent$CXDB                    | wbengine                          |
| MsDtsServer110                 | MSSQLFDLauncher$TPS             | SQLAgent$ECWDB2                  | WRSVC                             |
| MSExchangeAB                   | MSSQLFDLauncher$TPSAMA          | SQLAgent$PRACTTICEBGC            | Zoolz 2 Service                   |

*Table 13. Services stopped by Defray777.*

#### **File Encryption**

Based on a recent Defray777 sample recovered from memory, the ransomware will get a listing of all logical drives on the system using a call to GetLogicalDriveStringsW before iterating through each drive to encrypt files using the following process:

* To begin, Defray777 checks for whether the processor feature PF\_XMMI64\_INSTRUCTIONS\_AVAILABLE is present on the impacted system.
  * If enabled, Defray777 knows that SSE2 is supported and more complex mathematical operations are possible.
* Defray777 will also determine if the processor is capable of using AES-NI for improved encryption performance.
* As encryption begins, a ransom note will be created in each directory where files will be encrypted.
  * The name of the ransom note will vary. However, from our research, the ransom notes most commonly contain a combination of exclamation points, the string "README," and a reference to the victim name.
  * Example: !!!_IMPACTED\_Client\_README_!!!.txt
* The file contents will be encrypted using an on-the-fly generated AES key that gets encrypted with RSA-4096 and stored in the file footer in a 512-byte block.
* The encrypted file will be renamed by appending an extension that consists of a unique victim identifier and a randomized eight-digit hexadecimal number.
  * Example: .v1ct1m-1bc461ac

![This recent example of a Defray777 ransom note reads "Inspect this message CLOSELY and contact someone from technical division. Your data is securely ENCRYPTED. CORRECTION names or content of encrypted items (\*.<Redacted>) can make recovering problems. Mail us any encrypted document (smaller than BOOKS) and we would restore it. Affected file SHOULD NOT have sensitive intelligence. The rest of data will be available behind PAYING. We ask you not to contact cops as they will BLOCK your back accounts to inhibit payment. Reach us BUT if you responsible for all business."](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/11/word-image-36.png) Figure 23. Recent example of a Defray777 ransom note.

Specifically, the encryption mechanism consists of the following steps:

* Dynamically generate a 32-byte AES key.
* Encrypt the file with AES-256 in ECB mode using 16-byte blocks.
* Encrypt the AES key with RSA-4096 and append the 0x200 byte cipher text to the end of the encrypted file.

#### **Encryption Exclusions**

During the encryption process, Defray777 aims to encrypt as many files as possible without impacting the system's core functionality. To accomplish this, Defray777 uses a set of excluded folders, files and file extensions that will not be encrypted during execution.

Excluded Folders:

|-----------------------|--------------------------|---------------------|
| \\windows\\system32\\ | \\windows\\syswow64\\    | \\windows\\system\\ |
| \\windows\\winsxs\\   | \\appdata\\roaming\\     | \\appdata\\local\\  |
| \\appdata\\locallow\\ | \\all users\\microsoft\\ | \\inetpub\\logs\\   |
| :\\boot\\             | :\\perflogs\\            | :\\programdata\\    |
| :\\drivers\\          | :\\wsus\\                | :\\efstmpwp\\       |
| :\\$recycle.bin\\     | :\\EFSTMPWP\\            | crypt\_detect        |
| cryptolocker          | ransomware               |                     |

*Table 14. Folders excluded from encryption by Defray777.*

Excluded files:

|--------------|-----------|--------------|--------------|
| iconcache.db | thumbs.db | ransomware   | ransom       |
| debug.txt    | boot.ini  | desktop.ini  | autorun.inf  |
| ntuser.dat   | ntldr     | ntdetect.com | bootfont.bin |
| bootsect.bak |           |              |              |

*Table 15. Files excluded from encryption by Defray777.*

It is also important to note that Defray777 adds the name of the ransom note into the excluded files list.

Excluded extensions:

|-----------|------------|----------|------|----------|
| .ani      | .cab       | .cpl     | .cur | .diagcab |
| .diagpkg  | .dll       | .drv     | .hlp | .icl     |
| .icns     | .ico       | .iso     | .ics | .lnk     |
| .idx      | .mod       | .mpa     | .msc | .msp     |
| .msstyles | .msu       | .nomedia | .ocx | .prf     |
| .rtp      | .scr       | .shs     | .spl | .sys     |
| .theme    | .themepack | .exe     | .bat | .cmd     |
| .url      | .mui       |          |      |          |

*Table 16. Extensions excluded from encryption by Defray777.*

#### **Searching for Unmapped File Shares**

During execution, Defray777 uses WNetOpenEnumW and WNetEnumResourceW to search for file shares that may contain files that could be encrypted. This tactic has been seen amongst other ransomware variants in the wild to encrypt files that are accessible via unmapped file shares.
![During execution, Defray777 uses WNetOpenEnumW and WNetEnumResourceW to search for file shares that may contain files that could be encrypted.](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/11/word-image-37.png) Figure 24. Defray777 enumerating network resources.

#### **Anti-Forensic Measures**

After all files are encrypted on the system, Defray777, like many other ransomware variants, implements common anti-forensics measures to remove as much evidence of the intrusion as possible and make it extremely difficult for the system to be recovered without a backup. Although these commands are common amongst other ransomware variants, Defray777 runs commands post-encryption, which means that when security tools alert or take action against Defray777, the files have already been encrypted.

Commands executed by Defray777:

|---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| cipher.exe /w:\[DRIVE\] fsutil.exe usn deletejournal /D \[DRIVE\] wbadmin.exe delete catalog -quiet bcdedit.exe /set {default} recoveryenabled no bcdedit.exe /set {default} bootstatuspolicy ignoreallfailures schtasks.exe /Change /TN "\\Microsoft\\Windows\\SystemRestore\\SR" /disable wevtutil.exe cl Application wevtutil.exe cl System wevtutil.exe cl Setup wevtutil.exe cl Security wevtutil.exe sl Security /e:false |

*Table 17. Anti-forensic commands executed by Defray777.*

Registry keys modified:

|--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| \\Software\\Microsoft\\Windows NT\\CurrentVersion\\SystemRestore\\DisableConfig  \\Software\\Microsoft\\Windows NT\\CurrentVersion\\SystemRestore\\DisableSR \\SOFTWARE\\Policies\\Microsoft\\Windows NT\\SystemRestore\\DisableSR \\SOFTWARE\\Policies\\Microsoft\\Windows NT\\SystemRestore\\DisableConfig |

*Table 18. Registry Keys Modified by Defray777.*

#### **Defray777's Port to Linux**

During the course of our research, we found that Defray777 ransomware has been ported over to Linux. Before Defray777, ransomware that impacted both Windows and Linux operating systems was limited to being written in Java or scripting languages such as Python. These ransomware variants would be considered cross-functional since they were written in a single language that must be installed and supported by both operating systems. Defray777's port to Linux ensures that the ransomware has standalone executables for each platform with no external dependencies.

A ZIP archive was uploaded to a public malware repository on Oct. 17, 2020 that contained a Windows executable that was identified as a Defray777 decryptor. Additionally included in this ZIP archive was an ELF binary named decryptor64. Analysis of this binary determined it to be another Defray777 decryptor that had been ported to Linux.

Armed with the idea that there may be Linux versions of Defray777 in the wild, we began hunting in AutoFocus and quickly uncovered an ELF version of the ransomware encryptor.

Reviewing this sample further indicated that it was uploaded in August 2020. As of early October 2020, there appear to be zero detections by antivirus (AV) in VirusTotal for the Linux version of Defray777.

A deeper review of the Linux and Windows variants of Defray777 determined that the encryption and decryption processes used were nearly identical. In fact, by generating our own RSA key pair and modifying the binaries, we were able to confirm that the encryptors and decryptors for both operating systems were interchangeable.

Unlike the Windows versions, the developers didn't seem to put any effort into protecting the Linux samples. To our surprise, the binaries we analyzed still had their symbols intact, which made reversing them quite a bit easier.
![Unlike the Windows versions, the developers didn't seem to put any effort into protecting the Linux samples. The binaries we analyzed still had their symbols intact, which made reversing them quite a bit easier.](https://unit42.paloaltonetworks.com/wp-content/uploads/2020/11/word-image-38.png) Figure 25. Named functions listing from ELF version of Defray777.

One of the biggest differences between the Windows and Linux variants is the logic that determines which files to encrypt. The Windows version will recurse the file system and encrypt anything that isn't explicitly excluded. In contrast, the Linux variant will only encrypt directories specified in a command line argument.

Continue reading: [Linking Vatet, PyXie and Defray777](https://unit42.paloaltonetworks.com/vatet-pyxie-defray777/4)
Back to top

### Tags

* [Defray777](https://unit42.paloaltonetworks.com/tag/defray777/ "Defray777")
* [Prying Libra](https://unit42.paloaltonetworks.com/tag/prying-libra/ "Prying Libra")
* [PyXie](https://unit42.paloaltonetworks.com/tag/pyxie/ "PyXie")
* [Vatet](https://unit42.paloaltonetworks.com/tag/vatet/ "Vatet")  
  [Threat Research Center](https://unit42.paloaltonetworks.com "Threat Research") [Next: Windows XP, Server 2003 Source Code Leak Leaves IoT, OT Devices Vulnerable](https://unit42.paloaltonetworks.com/windows-xp-server-2003-source-code-leak/ "Windows XP, Server 2003 Source Code Leak Leaves IoT, OT Devices Vulnerable")

### Table of Contents

* 

### Related Articles

* [Why LaZagne Makes D-Bus API Vigilance Crucial](https://unit42.paloaltonetworks.com/lazagne-leverages-d-bus/ "article - table of contents")
* [Ransomware Threat Assessments: A Companion to the 2021 Unit 42 Ransomware Threat Report](https://unit42.paloaltonetworks.com/ransomware-threat-assessments/ "article - table of contents")

## Related Resources

![Pictorial representation of a magnifying glass illuminating a glowing orange circular digital circuit interface on a dark, high-tech background.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/09/04_Myth-Busting_Overview_1920x900-786x368.jpg)  
[![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/08/Insights-icon-white.svg)Insights](https://unit42.paloaltonetworks.com/category/insights/) September 16, 2026 [#### Atomic macOS (AMOS) Stealer Activity](https://unit42.paloaltonetworks.com/atomic-macos-amos-stealer-activity/)

* [MacOS](https://unit42.paloaltonetworks.com/tag/macos/ "macOS")

* [Threat intelligence](https://unit42.paloaltonetworks.com/tag/threat-intelligence/ "threat intelligence")

* [Unit 42](https://unit42.paloaltonetworks.com/tag/unit-42/ "Unit 42")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/atomic-macos-amos-stealer-activity/ "Atomic macOS (AMOS) Stealer Activity")  
  ![Pictorial representation of post-exploitation identity misuse in SPIFFE/SPIRE. Close-up of a person wearing glasses, with computer code reflected in the lenses.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/09/12_Security-Technology_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) September 10, 2026 [#### The Machine With Many Faces: Post-Exploitation Identity Misuse in SPIFFE/SPIRE](https://unit42.paloaltonetworks.com/kubernetes-spiffe-spire-identity-spoofing/)

* [API](https://unit42.paloaltonetworks.com/tag/api/ "API")

* [Cryptographic](https://unit42.paloaltonetworks.com/tag/cryptographic/ "cryptographic")

* [JSON](https://unit42.paloaltonetworks.com/tag/json/ "JSON")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/kubernetes-spiffe-spire-identity-spoofing/ "The Machine With Many Faces: Post-Exploitation Identity Misuse in SPIFFE/SPIRE")  
  ![Pictorial representation of a pay-per-install threat group campaign prodiving infection service for spreading malware. A close-up of a computer circuit board with a central microchip is depicted. Red digital data streams in the form of glowing binary numbers and arrows appear to flow in and out of the chip, symbolizing data processing and transfer. The scene is illuminated with a futuristic blue and red glow.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/09/04_Malware_Category_1920x900-6-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) September 9, 2026 [#### Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure](https://unit42.paloaltonetworks.com/ppi-network-malware-campaign-analysis/)

* [ARKTunnel](https://unit42.paloaltonetworks.com/tag/arktunnel/ "ARKTunnel")

* [C2](https://unit42.paloaltonetworks.com/tag/c2/ "C2")

* [CL-CRI-1171](https://unit42.paloaltonetworks.com/tag/cl-cri-1171/ "CL-CRI-1171")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ppi-network-malware-campaign-analysis/ "Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure")  
  ![Pictorial representation of attackers using AI tools to target Latin American organizations. A vibrant cityscape with silhouettes of numerous people walking along a bustling street. The scene is illuminated by bright urban lights and digital-like particles, creating a dynamic and futuristic atmosphere.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/09/AdobeStock_768915868-2-1-786x373.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) September 3, 2026 [#### Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America](https://unit42.paloaltonetworks.com/ai-tool-use-targeting-latam-orgs/)

* [Agentic AI](https://unit42.paloaltonetworks.com/tag/agentic-ai/ "Agentic AI")

* [ChatGPT](https://unit42.paloaltonetworks.com/tag/chatgpt/ "ChatGPT")

* [CL-CRI-1131](https://unit42.paloaltonetworks.com/tag/cl-cri-1131/ "CL-CRI-1131")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ai-tool-use-targeting-latam-orgs/ "Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America")  
  ![Pictorial representation of vishing campaigns in Microsoft Teams. A digital image of a skull formed by blue binary code on a black background, with scattered ones and zeros and digital noise, symbolizes how stealthy prompt injection attacks can exploit AI logic to bypass security controls.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/01_Malware_Category_1920x900-5-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 31, 2026 [#### Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams](https://unit42.paloaltonetworks.com/spring-ring-voice-phishing-campaigns/)

* [Cloaked Ursa](https://unit42.paloaltonetworks.com/tag/cloaked-ursa/ "Cloaked Ursa")

* [Entra ID](https://unit42.paloaltonetworks.com/tag/entra-id/ "Entra ID")

* [Microsoft Teams](https://unit42.paloaltonetworks.com/tag/microsoft-teams/ "Microsoft Teams")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/spring-ring-voice-phishing-campaigns/ "Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams")  
  ![Pictorial representation of AI-enabled malware. A vibrant digital interface displaying various icons and graphs, resembling a futuristic network or data analysis dashboard. The scene is illuminated with glowing lights and patterns.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/AdobeStock_1270203474-2-1-786x368.png)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 25, 2026 [#### The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution](https://unit42.paloaltonetworks.com/ai-enabled-malware-analysis/)

* [Backdoor](https://unit42.paloaltonetworks.com/tag/backdoor/ "backdoor")

* [Bitcoin](https://unit42.paloaltonetworks.com/tag/bitcoin/ "Bitcoin")

* [DLL hijacking](https://unit42.paloaltonetworks.com/tag/dll-hijacking/ "DLL hijacking")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ai-enabled-malware-analysis/ "The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution")  
  ![Pictorial representation of identity abuse through trusted communication channels. Close-up view of a digital screen displaying a glitched and pixelated image of a skull-like shape.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/02_Malware_Category_1920x900-2-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 20, 2026 [#### Identity Abuse Through Trusted Communication Channels](https://unit42.paloaltonetworks.com/communication-channel-identity-risks/)

* [Authentication](https://unit42.paloaltonetworks.com/tag/authentication/ "authentication")

* [Identity theft](https://unit42.paloaltonetworks.com/tag/identity-theft/ "identity theft")

* [Malware](https://unit42.paloaltonetworks.com/tag/malware/ "malware")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/communication-channel-identity-risks/ "Identity Abuse Through Trusted Communication Channels")  
  ![Pictorial representation of Kimwolf botnet malware family. Digital screen with a warning sign reading "Malware." The background features lines of computer code and graphics, creating a sense of cybersecurity threat.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/07_Malware_Category_1920x900-3-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 11, 2026 [#### Kimwolf v7: An Evolution of the Kimwolf Botnet](https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/)

* [Android APK](https://unit42.paloaltonetworks.com/tag/android-apk/ "Android APK")

* [Ethereum](https://unit42.paloaltonetworks.com/tag/ethereum/ "Ethereum")

* [HTTP](https://unit42.paloaltonetworks.com/tag/http/ "HTTP")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/ "Kimwolf v7: An Evolution of the Kimwolf Botnet")  
  ![Pictorial representatiom pf Aeternum's blockchain C2. A close-up of a computer circuit board with a central microchip is depicted. Red digital data streams in the form of glowing binary numbers and arrows appear to flow in and out of the chip. The scene is illuminated with a futuristic blue and red glow.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/04_Malware_Category_1920x900-4-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 10, 2026 [#### The Permanent Threat: Analyzing Aeternum's Blockchain-Based C2 Operations and Communications](https://unit42.paloaltonetworks.com/aeternum-blockchain-c2-analysis/)

* [Aeternum](https://unit42.paloaltonetworks.com/tag/aeternum/ "Aeternum")

* [Infection chain](https://unit42.paloaltonetworks.com/tag/infection-chain/ "infection chain")

* [JSON](https://unit42.paloaltonetworks.com/tag/json/ "JSON")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/aeternum-blockchain-c2-analysis/ "The Permanent Threat: Analyzing Aeternum’s Blockchain-Based C2 Operations and Communications")  
  ![Pictorial representation of ChainDrop, a self-propagating npm worm. An artistic depiction of a digital workspace featuring an open laptop with a red virus on the screen.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/03_Malware_Category_1920x900-7-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)High Profile Threats](https://unit42.paloaltonetworks.com/category/top-cyberthreats/) August 6, 2026 [#### ChainDrop: Inside a Self-Propagating npm Worm](https://unit42.paloaltonetworks.com/chaindrop-npm-worm-analysis/)

* [Blockchain](https://unit42.paloaltonetworks.com/tag/blockchain/ "blockchain")

* [ChainDrop](https://unit42.paloaltonetworks.com/tag/chaindrop/ "ChainDrop")

* [Claude code](https://unit42.paloaltonetworks.com/tag/claude-code/ "Claude code")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/chaindrop-npm-worm-analysis/ "ChainDrop: Inside a Self-Propagating npm Worm")

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)  
  ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg) ![Enlarged Image]()  
  ![Newsletter](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/unit42-footer-subscribe-desktop.png)  
  ![UNIT 42 Small Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/palo-alto-logo-small.svg) Get updates from Unit 42

## Peace of mind comes from staying ahead of threats. Subscribe today.

Your Email

Subscribe for email updates to all Unit 42 threat research.  
By submitting this form, you agree to our [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use "Terms of Use") and acknowledge our [Privacy Statement.](https://www.paloaltonetworks.com/legal-notices/privacy "Privacy Statement")

This site is protected by reCAPTCHA and the Google [Privacy Policy](https://policies.google.com/privacy) and [Terms of Service](https://policies.google.com/terms) apply.

Invalid captcha!
Subscribe ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg) ![loader](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-loader.svg)  
{#footer} Products and Services

* [AI-Powered Network Security Platform](https://www.paloaltonetworks.com/network-security)

* [Secure AI by Design](https://www.paloaltonetworks.com/ai-security)

* [Prisma AIRS](https://www.paloaltonetworks.com/ai-security/prisma-airs)

* [AI Access Security](https://www.paloaltonetworks.com/sase/ai-access-security)

* [Cloud Delivered Security Services](https://www.paloaltonetworks.com/network-security/security-subscriptions)

* [Advanced Threat Prevention](https://www.paloaltonetworks.com/network-security/advanced-threat-prevention)

* [Advanced URL Filtering](https://www.paloaltonetworks.com/network-security/advanced-url-filtering)

* [Advanced WildFire](https://www.paloaltonetworks.com/network-security/advanced-wildfire)

* [Advanced DNS Security](https://www.paloaltonetworks.com/network-security/advanced-dns-security)

* [Enterprise Data Loss Prevention](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention)

* [Enterprise IoT Security](https://www.paloaltonetworks.com/network-security/enterprise-device-security)

* [Medical IoT Security](https://www.paloaltonetworks.com/network-security/medical-device-security)

* [Industrial OT Security](https://www.paloaltonetworks.com/network-security/ot-security-solution)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security)

* [Next-Generation Firewalls](https://www.paloaltonetworks.com/network-security/next-generation-firewall)

* [Hardware Firewalls](https://www.paloaltonetworks.com/network-security/hardware-firewall-innovations)

* [Software Firewalls](https://www.paloaltonetworks.com/network-security/software-firewalls)

* [Strata Cloud Manager](https://www.paloaltonetworks.com/network-security/strata-cloud-manager)

* [SD-WAN for NGFW](https://www.paloaltonetworks.com/network-security/sd-wan-subscription)

* [PAN-OS](https://www.paloaltonetworks.com/network-security/pan-os)

* [Panorama](https://www.paloaltonetworks.com/network-security/panorama)

* [Secure Access Service Edge](https://www.paloaltonetworks.com/sase)

* [Prisma SASE](https://www.paloaltonetworks.com/sase)

* [Application Acceleration](https://www.paloaltonetworks.com/sase/app-acceleration)

* [Autonomous Digital Experience Management](https://www.paloaltonetworks.com/sase/adem)

* [Enterprise DLP](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention)

* [Prisma Access](https://www.paloaltonetworks.com/sase/access)

* [Prisma Browser](https://www.paloaltonetworks.com/sase/prisma-browser)

* [Prisma SD-WAN](https://www.paloaltonetworks.com/sase/sd-wan)

* [Remote Browser Isolation](https://www.paloaltonetworks.com/sase/remote-browser-isolation)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security)

* [AI-Driven Security Operations Platform](https://www.paloaltonetworks.com/cortex)

* [Cloud Security](https://www.paloaltonetworks.com/cortex/cloud)

* [Cortex Cloud](https://www.paloaltonetworks.com/cortex/cloud)

* [Application Security](https://www.paloaltonetworks.com/cortex/cloud/application-security)

* [Cloud Posture Security](https://www.paloaltonetworks.com/cortex/cloud/cloud-posture-security)

* [Cloud Runtime Security](https://www.paloaltonetworks.com/cortex/cloud/runtime-security)

* [Prisma Cloud](https://www.paloaltonetworks.com/prisma/cloud)

* [AI-Driven SOC](https://www.paloaltonetworks.com/cortex)

* [Cortex XSIAM](https://www.paloaltonetworks.com/cortex/cortex-xsiam)

* [Cortex XDR](https://www.paloaltonetworks.com/cortex/cortex-xdr)

* [Cortex XSOAR](https://www.paloaltonetworks.com/cortex/cortex-xsoar)

* [Cortex Xpanse](https://www.paloaltonetworks.com/cortex/cortex-xpanse)

* [Unit 42 Managed Detection \& Response](https://www.paloaltonetworks.com/unit42/respond/managed-detection-response)

* [Managed XSIAM](https://www.paloaltonetworks.com/cortex/managed-xsiam)

* [Next-Generation Identity Security](https://www.paloaltonetworks.com/idira)

* [Privileged Access Management](https://www.paloaltonetworks.com/idira/human/privileged-access-management)

* [Identity and Access Management](https://www.paloaltonetworks.com/idira/human/identity-and-access-management)

* [Endpoint Privilege Manager](https://www.paloaltonetworks.com/idira/human/endpoint-privilege-manager)

* [Identity Governance](https://www.paloaltonetworks.com/idira/human/identity-governance)

* [Workforce Password Management](https://www.paloaltonetworks.com/idira/human/workforce-password-management)

* [Agentic Identities](https://www.paloaltonetworks.com/idira/agentic)

* [Secrets Management](https://www.paloaltonetworks.com/idira/machine/secrets-management)

* [Unified Secrets Governance](https://www.paloaltonetworks.com/idira/machine/unified-secrets-governance)

* [Application Credentials Delivery](https://www.paloaltonetworks.com/idira/machine/application-credentials-delivery)

* [Vendor Privileged Access](https://www.paloaltonetworks.com/idira/human/vendor-privileged-access)

* [Threat Intel and Incident Response Services](https://www.paloaltonetworks.com/unit42)

* [Prepare for Emerging Risks](https://www.paloaltonetworks.com/unit42/prepare-for-emerging-risks/continuous-frontier-ai-defense)

* [Strengthen Your Defenses](https://www.paloaltonetworks.com/unit42/strengthen-your-defenses)

* [Build Your Security Strategy](https://www.paloaltonetworks.com/unit42/build-your-security-strategy)

* [Understand the Adversary](https://www.paloaltonetworks.com/unit42/threat-intelligence)

* [Respond to a Cyber Attack](https://www.paloaltonetworks.com/unit42/respond)  
  Company

* [About Us](https://www.paloaltonetworks.com/about-us)

* [Careers](https://jobs.paloaltonetworks.com/en/)

* [Contact Us](https://www.paloaltonetworks.com/company/contact-sales)

* [Corporate Responsibility](https://www.paloaltonetworks.com/about-us/corporate-responsibility)

* [Customers](https://www.paloaltonetworks.com/customers)

* [Investor Relations](https://investors.paloaltonetworks.com/)

* [Location](https://www.paloaltonetworks.com/about-us/locations)

* [Newsroom](https://www.paloaltonetworks.com/company/newsroom)  
  Popular Links

* [Blog](https://www.paloaltonetworks.com/blog/)

* [Communities](https://www.paloaltonetworks.com/communities)

* [Content Library](https://www.paloaltonetworks.com/resources)

* [Cyberpedia](https://www.paloaltonetworks.com/cyberpedia)

* [Event Center](https://events.paloaltonetworks.com/)

* [Manage Email Preferences](https://start.paloaltonetworks.com/preference-center)

* [Products A-Z](https://www.paloaltonetworks.com/products/products-a-z)

* [Product Certifications](https://www.paloaltonetworks.com/legal-notices/trust-center/certifications)

* [Report a Vulnerability](https://www.paloaltonetworks.com/security-disclosure)

* [Sitemap](https://www.paloaltonetworks.com/sitemap)

* [Tech Docs](https://docs.paloaltonetworks.com/)

* [Unit 42](https://unit42.paloaltonetworks.com/)

* [Do Not Sell or Share My Personal Information](https://panwedd.exterro.net/portal/dsar.htm?target=panwedd)
  ![Palo Alto Networks Logo](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/pan-logo-dark.svg)

* [Privacy](https://www.paloaltonetworks.com/legal-notices/privacy)

* [Trust Center](https://www.paloaltonetworks.com/legal-notices/trust-center)

* [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use)

* [Documents](https://www.paloaltonetworks.com/legal)

Copyright © 2026 Palo Alto Networks. All Rights Reserved

* [![Youtube](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/youtube-black.svg)](https://www.youtube.com/user/paloaltonetworks)
* [![Podcast](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/icons/podcast.svg)](https://www.paloaltonetworks.com/podcasts/threat-vector)
* [![Facebook](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/facebook-black.svg)](https://www.facebook.com/PaloAltoNetworks/)
* [![LinkedIn](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/linkedin-black.svg)](https://www.linkedin.com/company/palo-alto-networks)
* [![Twitter](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/twitter-x-black.svg)](https://twitter.com/PaloAltoNtwks)
* EN  
  Select your language  
  ![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg) ![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg) ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg)

### Default Heading

Read the article ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg)  
Seekbar

![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg)  
![Volume](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-volume.svg)  
Volume
![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg)
