[![Logo](https://www.paloaltonetworks.com/wp-content/uploads/2021/07/PANW_Parent.png)](https://www.paloaltonetworks.com/)  
[![Unit42 Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/unit42-logo-white.svg)](https://unit42.paloaltonetworks.com/)  
Menu

* [Tools](https://unit42.paloaltonetworks.com/tools/)
* [ATOMs](https://unit42.paloaltonetworks.com/atoms/)
* [Security Consulting](https://www.paloaltonetworks.com/unit42)
* [About Us](https://unit42.paloaltonetworks.com/about-unit-42/)
* [**Under Attack?**](https://start.paloaltonetworks.com/contact-unit42.html)  
  English
* [English](https://unit42.paloaltonetworks.com/volt-typhoon-threat-brief/)
* [Japanese](https://unit42.paloaltonetworks.com/ja/volt-typhoon-threat-brief/)
* [Threat Research Center](https://unit42.paloaltonetworks.com "Threat Research")
* [High Profile Threats](https://unit42.paloaltonetworks.com/category/top-cyberthreats/ "High Profile Threats")
* [Nation-State Cyberattacks](https://unit42.paloaltonetworks.com/category/nation-state-cyberattacks/ "Nation-State Cyberattacks")  
  [Nation-State Cyberattacks](https://unit42.paloaltonetworks.com/category/nation-state-cyberattacks/)

# Threat Brief: Attacks on Critical Infrastructure Attributed to Insidious Taurus (Volt Typhoon)

![Clock Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-clock.svg) 9 min read  
Related Products  
[![Advanced DNS Security icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Advanced DNS Security](https://unit42.paloaltonetworks.com/product-category/advanced-dns-security/ "Advanced DNS Security")[![Advanced Threat Prevention icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Advanced Threat Prevention](https://unit42.paloaltonetworks.com/product-category/advanced-threat-prevention/ "Advanced Threat Prevention")[![Advanced URL Filtering icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Advanced URL Filtering](https://unit42.paloaltonetworks.com/product-category/advanced-url-filtering/ "Advanced URL Filtering")[![Cloud-Delivered Security Services icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Cloud-Delivered Security Services](https://unit42.paloaltonetworks.com/product-category/cloud-delivered-security-services/ "Cloud-Delivered Security Services")[![Cortex XDR icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/cortex_RGB_logo_Icon_Color.png)Cortex XDR](https://unit42.paloaltonetworks.com/product-category/cortex-xdr/ "Cortex XDR")[![Cortex Xpanse icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/cortex_RGB_logo_Icon_Color.png)Cortex Xpanse](https://unit42.paloaltonetworks.com/product-category/cortex-xpanse/ "Cortex Xpanse")[![Cortex XSIAM icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/cortex_RGB_logo_Icon_Color.png)Cortex XSIAM](https://unit42.paloaltonetworks.com/product-category/cortex-xsiam/ "Cortex XSIAM")[![Cortex XSOAR icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/cortex_RGB_logo_Icon_Color.png)Cortex XSOAR](https://unit42.paloaltonetworks.com/product-category/cortex-xsoar/ "Cortex XSOAR")[![Next-Generation Firewall icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Next-Generation Firewall](https://unit42.paloaltonetworks.com/product-category/next-generation-firewall/ "Next-Generation Firewall")[![Prisma Access icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/prisma_RGB_logo_Icon_Color.png)Prisma Access](https://unit42.paloaltonetworks.com/product-category/prisma-access/ "Prisma Access")[![Prisma Cloud icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/prisma_RGB_logo_Icon_Color.png)Prisma Cloud](https://unit42.paloaltonetworks.com/product-category/prisma-cloud/ "Prisma Cloud")

* ![Profile Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-profile-grey.svg)  
  By:
  
  * [Unit 42](https://unit42.paloaltonetworks.com/author/unit42/)

* ![Published Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-calendar-grey.svg)  
  Published:February 14, 2024

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-category.svg)  
  Categories:
  
  * [High Profile Threats](https://unit42.paloaltonetworks.com/category/top-cyberthreats/)
  * [Nation-State Cyberattacks](https://unit42.paloaltonetworks.com/category/nation-state-cyberattacks/)

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-tags-grey.svg)  
  Tags:
  
  * [BRONZE SILHOUETTE](https://unit42.paloaltonetworks.com/tag/bronze-silhouette/)
  * [China](https://unit42.paloaltonetworks.com/tag/china/)
  * [Dev-0391](https://unit42.paloaltonetworks.com/tag/dev-0391/)
  * [Insidious Taurus](https://unit42.paloaltonetworks.com/tag/insidious-taurus/)
  * [UNC3236](https://unit42.paloaltonetworks.com/tag/unc3236/)
  * [Vanguard Panda](https://unit42.paloaltonetworks.com/tag/vanguard-panda/)
  * [Volt Typhoon](https://unit42.paloaltonetworks.com/tag/volt-typhoon/)

* [![Download Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-download.svg)](https://unit42.paloaltonetworks.com/volt-typhoon-threat-brief/?pdf=download&lg=en&_wpnonce=7052973960 "Click here to download")

* [![Print Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-print.svg)](https://unit42.paloaltonetworks.com/volt-typhoon-threat-brief/?pdf=print&lg=en&_wpnonce=7052973960 "Click here to print")

Share![Down arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/down-arrow.svg)

* ![Link Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-share-link.svg)
* [![Link Email](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-sms.svg)](<mailto:?subject=Threat%20Brief:%20Attacks%20on%20Critical%20Infrastructure%20Attributed%20to%20Insidious%20Taurus%20(Volt%20Typhoon)&body=Check%20out%20this%20article%20https%3A%2F%2Funit42.paloaltonetworks.com%2Fvolt-typhoon-threat-brief%2F> "Share in email")
* [![Facebook Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-fb-share.svg)](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Funit42.paloaltonetworks.com%2Fvolt-typhoon-threat-brief%2F "Share in Facebook")
* [![LinkedIn Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-linkedin-share.svg)](<https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fvolt-typhoon-threat-brief%2F&title=Threat%20Brief:%20Attacks%20on%20Critical%20Infrastructure%20Attributed%20to%20Insidious%20Taurus%20(Volt%20Typhoon)> "Share in LinkedIn")
* [![Twitter Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-twitter-share.svg)](<https://twitter.com/intent/tweet?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fvolt-typhoon-threat-brief%2F&text=Threat%20Brief:%20Attacks%20on%20Critical%20Infrastructure%20Attributed%20to%20Insidious%20Taurus%20(Volt%20Typhoon)> "Share in Twitter")
* [![Reddit Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-reddit-share.svg)](https://www.paloaltonetworks.com//www.reddit.com/submit?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fvolt-typhoon-threat-brief%2F&ts=markdown "Share in Reddit")
* [![Mastodon Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-mastodon-share.svg)](<https://mastodon.social/share?text=Threat%20Brief:%20Attacks%20on%20Critical%20Infrastructure%20Attributed%20to%20Insidious%20Taurus%20(Volt%20Typhoon)%20https%3A%2F%2Funit42.paloaltonetworks.com%2Fvolt-typhoon-threat-brief%2F> "Share in Mastodon")

## Executive Summary

Insidious Taurus (aka Volt Typhoon) is identified by U.S. government agencies and international government partners as People's Republic of China (PRC) state-sponsored cyber actors. This group focuses on pre-positioning themselves within U.S. critical infrastructure IT networks, likely in preparation for disruptive or destructive cyberattacks in the event of a major crisis or conflict with the United States. During a hearing on Jan. 31, 2024, FBI director Christopher Wray told the U.S. House Select Committee on the Strategic Competition Between the United States and the Chinese Communist Party that Volt Typhoon was "the defining threat of our generation."

The U.S. government, in collaboration with international government allies, has published two Joint Cybersecurity Advisories (CSA) about this activity. They published the first Joint [CSA](https://media.defense.gov/2023/May/24/2003229517/-1/-1/0/CSA_Living_off_the_Land.PDF) on May 24, 2023. They published the second Joint [CSA](https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-038a) on Feb. 7, 2024.

The first CSA discusses the group's use of small office/home office (SOHO) network devices as intermediate infrastructure to obscure their activity. It also describes the use of living-off-the-land techniques and the use of built-in network administration tools to perform objectives, as means of hiding their activity. Palo Alto Networks was credited for providing input on the activity as part of the first CSA.

The second CSA discussed a wider set of techniques used by this group. These techniques include performing extensive pre-compromise reconnaissance, the exploitation of known or zero-day vulnerabilities in public-facing network appliances to gain initial access, and a focus on gaining administrator credentials within a victim environment.

The U.S. Department of Justice published a press release on Jan. 31 stating that a court-authorized operation has disrupted a botnet of hundreds of U.S.-based SOHO devices infected with the KV-botnet. The KV-botnet has been used by multiple different threat actors, including Insidious Taurus.

The vast majority of the devices included in the botnet were routers that were vulnerable because they were no longer supported through their manufacturer's security patches or other software updates. Threat actor groups chain together compromised devices within this botnet to form a covert data transfer network.

Despite the disruption of the KV-botnet, Insidious Taurus remains an ongoing threat and cyberattacks targeting critical infrastructure warrant special attention. Unit 42 will continue to update this threat brief as more information becomes available.

Palo Alto Networks customers are better protected from Insidious Taurus through the following:

* [Next-Generation Firewall](https://docs.paloaltonetworks.com/ngfw) with the [Advanced Threat Prevention](https://docs.paloaltonetworks.com/advanced-threat-prevention/administration) security subscription can help block the attacks with Threat Prevention signatures.
* [Advanced Threat Prevention](https://docs.paloaltonetworks.com/advanced-threat-prevention/administration) has an inbuilt machine learning-based detection that can detect exploits in real time.
* [Advanced URL Filtering](https://docs.paloaltonetworks.com/advanced-url-filtering/administration) and [DNS Security](https://docs.paloaltonetworks.com/dns-security) identify known IPs and domains associated with this group as malicious.
* [Cortex XSOAR](https://docs-cortex.paloaltonetworks.com/p/XSOAR) can automate workflows for data enrichment, indicators of compromise (IoC) hunting and remediation actions to reduce manual work and speed up the patching process.
* [Cortex XDR](https://docs-cortex.paloaltonetworks.com/p/XDR) and [XSIAM](https://docs-cortex.paloaltonetworks.com/p/XSIAM) agent helps protect against the techniques executed by this threat actor using Behavioral Threat Protection and its multiple security modules. Cortex Analytics has multiple detection models covering the techniques, with additional relevant coverage by the Identity Analytics module.
* [Cortex Xpanse](https://docs-cortex.paloaltonetworks.com/p/XPANSE) is able to detect a wide range of internet-exposed SOHO devices.
* [Prisma Cloud](https://docs.paloaltonetworks.com/prisma/prisma-cloud) agents have detection for all known Insidious Taurus malware samples listed within [WildFire](https://docs.paloaltonetworks.com/wildfire).
* [Prisma Access](https://www.paloaltonetworks.com/sase/access) has detection for all known Insidious Taurus malware samples within WildFire and all related threat signatures will be detectable at services turnup.

Organizations can engage the [Unit 42 Incident Response](https://start.paloaltonetworks.com/contact-unit42.html) team for specific assistance with this threat and others.

|                                                        **Threat Group Discussed**                                                         |                                                               **Also Known As**                                                               |
| [Insidious](https://unit42.paloaltonetworks.com/tag/insidious-taurus/)[Taurus](https://unit42.paloaltonetworks.com/tag/insidious-taurus/) | [Volt Typhoon](https://unit42.paloaltonetworks.com/tag/volt-typhoon/)****, Voltzite, BRONZE SILHOUETTE, Vanguard Panda, UNC3236, Dev-0391**** |
|-------------------------------------------------------------------------------------------------------------------------------------------|-----------------------------------------------------------------------------------------------------------------------------------------------|

## Adversary Attack Methodology

In late 2021, Unit 42 observed a threat actor (now identified as Insidious Taurus) using a then-undisclosed Zoho ManageEngine ADSelfService Plus vulnerability ([CVE-2021-40539](https://nvd.nist.gov/vuln/detail/cve-2021-40539)) for initial access. While performing incident response activities, Unit 42 identified a connection to a network-attached storage (NAS) server with FTP running. We found a sample of SockDetour in the trash of that NAS.

SockDetour is a custom backdoor used to maintain persistence, designed to serve as a backup backdoor in case a threat actor's primary one is removed. The tactics and techniques used during this event aligned with what Microsoft then called DEV-0391, which is now known as Volt Typhoon.

Insidious Taurus also uses one rarely used malware family, EarthWorm, as well as custom versions of open-source tools Impacket and Fast Reverse Proxy. Employment of these tools further underscores our assessment of the attackers' technical skill and their focus on remaining undetected.

Exploiting vulnerabilities in internet-facing devices is a known initial access vector for Insidious Taurus. They are believed to have the capability to identify and develop their own zero-day exploits while also taking advantage or publically disclosed vulnerabilities and exploits.

Once initial access has been achieved, a common attribute of attacks is the need to generate as little malicious activity as possible to evade detection and blocking by protection software. Getting caught at all, let alone quickly, precludes operational success.

Insidious Taurus actors take multiple steps to avoid detection, showing an overall technical ability only seen with advanced attackers. One of the ways they do this is by using compromised SOHO devices. Originating attacks from households or small businesses aids attackers because many do not have significant security protections in place.

In addition to requiring manual software updates, SOHO devices are also rarely configured according to best practices by users and they have network management interfaces exposed directly online. Because of these things, many attackers of all motivations -- including botnets -- also recognize and use SOHO devices for malicious activity. This was true for the case Unit 42 worked in late 2021 where a connection led to the identification of the compromised NAS server.

Another common technique Insidious Taurus has used to remain undetected, formerly the sole realm of advanced attackers but now more widely used, is a technique known as [living off the land](https://www.paloaltonetworks.com/cyberpedia/what-are-fileless-malware-attacks). This is when attackers abuse legitimate tools -- often those used by system administrators for legitimate purposes -- for malicious use.

If captured in logs, this activity often looks similar to legitimate network administration use. This includes network enumeration, determining account permissions and even password recovery tools. Because of their widespread legitimate use, these tools are often on allow lists for download and can be difficult to detect when used for malicious activity.

Another way actors can hide their activity when interacting with victim networks, is to carry out their work using direct hands-on keyboard activity vs using scripts to automate activity. By doing so, the attackers can hamper detection efforts again because their activity appears to be expected, human activity rather than a barrage of scripted commands to detect and interdict. For now, this technique remains one only used effectively by advanced attackers due to the required knowledge and skill.

## Interim Guidance

Unit 42 recommends following the guidance provided by CISA in their latest [CSA](https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-038a). This includes the following:

* Hardening the attack surface
* Securing credentials and accounts
* Securing and limiting the use of remote access services
* Implementing network segmentation
* Securing cloud assets
* Being prepared through logging, threat modeling and training

Additionally, Unit 42 recommends increasing detection opportunities to identify [living off the land attacks](https://www.cisa.gov/sites/default/files/2024-02/Joint-Guidance-Identifying-and-Mitigating-LOTL_V3508c.pdf).

## Unit 42 Managed Threat Hunting Queries

The queries below represent a few ways organizations can hunt for activity that could be related to Insidious Taurus. However, the techniques and IoCs being hunted for here may not be unique to Insidious Taurus and any results should be considered in the context of other identified activity.  
// Description: Looks for the netsh PortProxy command being used to enable port forwarding // Ref: https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-144a config case\_sensitive = false |filter action\_process\_image\_name in ("netsh.exe","cmd.exe") |filter action\_process\_image\_command\_line contains "netsh interface portproxy add v4tov4" |fields \_time, agent\_hostname, actor\_effective\_username, actor\_process\_image\_path, action\_process\_image\_command\_line

|---------------|-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| 1 2 3 4 5 6 7 | // Description: Looks for the netsh PortProxy command being used to enable port forwarding // Ref: https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-144a config case\_sensitive = false |filter action\_process\_image\_name in ("netsh.exe","cmd.exe") |filter action\_process\_image\_command\_line contains "netsh interface portproxy add v4tov4" |fields \_time, agent\_hostname, actor\_effective\_username, actor\_process\_image\_path, action\_process\_image\_command\_line |

// Description: Looks for the creation of a PortProxy registry key // Ref: https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-144a config case\_sensitive = false |dataset = xdr\_data |filter event\_type = ENUM.REGISTRY AND (event\_sub\_type in (ENUM.REGISTRY\_CREATE\_KEY, ENUM.REGISTRY\_SET\_VALUE)) |filter action\_registry\_key\_name = "HKEY\_LOCAL\_MACHINE\\SYSTEM\\ControlSet001\\Services\\PortProxy\\v4tov4\\tcp" |fields \_time, agent\_hostname, actor\_effective\_username, actor\_process\_image\_name, actor\_process\_command\_line, event\_type, event\_sub\_type, action\_registry\_key\_name, action\_registry\_data

|-----------------|--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| 1 2 3 4 5 6 7 8 | // Description: Looks for the creation of a PortProxy registry key // Ref: https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-144a config case\_sensitive = false |dataset = xdr\_data |filter event\_type = ENUM.REGISTRY AND (event\_sub\_type in (ENUM.REGISTRY\_CREATE\_KEY, ENUM.REGISTRY\_SET\_VALUE)) |filter action\_registry\_key\_name = "HKEY\_LOCAL\_MACHINE\\SYSTEM\\ControlSet001\\Services\\PortProxy\\v4tov4\\tcp" |fields \_time, agent\_hostname, actor\_effective\_username, actor\_process\_image\_name, actor\_process\_command\_line, event\_type, event\_sub\_type, action\_registry\_key\_name, action\_registry\_data |

// Description: Looks for WMIC information gathering command observed being used by Volt Typhoon // Ref: https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-144a config case\_sensitive = false |dataset = xdr\_data |filter event\_type = ENUM.PROCESS and event\_sub\_type = ENUM.PROCESS\_START |filter action\_process\_image\_name = "wmic.exe" and actor\_process\_image\_name = "cmd.exe" and action\_process\_image\_command\_line contains "path win32\_logicaldisk get caption,filesystem,freespace,size,volumename" |fields \_time,agent\_hostname,actor\_effective\_username,actor\_process\_image\_name,actor\_process\_command\_line,action\_process\_image\_command\_line

|-----------------|---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| 1 2 3 4 5 6 7 8 | // Description: Looks for WMIC information gathering command observed being used by Volt Typhoon // Ref: https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-144a config case\_sensitive = false |dataset = xdr\_data |filter event\_type = ENUM.PROCESS and event\_sub\_type = ENUM.PROCESS\_START |filter action\_process\_image\_name = "wmic.exe" and actor\_process\_image\_name = "cmd.exe" and action\_process\_image\_command\_line contains "path win32\_logicaldisk get caption,filesystem,freespace,size,volumename" |fields \_time,agent\_hostname,actor\_effective\_username,actor\_process\_image\_name,actor\_process\_command\_line,action\_process\_image\_command\_line |

// Description: Look for attempts to dump NTDS.dit to disk via Ntdsutil IFM command // Ref: https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-144a config case\_sensitive = false |dataset = xdr\_data |filter action\_process\_image\_name = "ntdsutil.exe" AND (action\_process\_image\_command\_line contains "ac i ntds" or action\_process\_image\_command\_line contains "activate instance ntds") and action\_process\_image\_command\_line contains "create full" |fields \_time,agent\_hostname,actor\_effective\_username,actor\_process\_image\_path,action\_process\_image\_command\_line

|---------------|-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| 1 2 3 4 5 6 7 | // Description: Look for attempts to dump NTDS.dit to disk via Ntdsutil IFM command // Ref: https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-144a config case\_sensitive = false |dataset = xdr\_data |filter action\_process\_image\_name = "ntdsutil.exe" AND (action\_process\_image\_command\_line contains "ac i ntds" or action\_process\_image\_command\_line contains "activate instance ntds") and action\_process\_image\_command\_line contains "create full" |fields \_time,agent\_hostname,actor\_effective\_username,actor\_process\_image\_path,action\_process\_image\_command\_line |

// Description: Look for instances of cmd.exe being spawned with arguments consistent with the usage of Impacket's Wmiexec // Ref: https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-144a config case\_sensitive = false |dataset = xdr\_data |filter event\_type = ENUM.PROCESS AND event\_sub\_type = ENUM.PROCESS\_START |filter os\_actor\_process\_image\_name = "wmiprvse.exe" AND action\_process\_image\_name = "cmd.exe" AND action\_process\_image\_command\_line contains """/Q /c \* \\\\\\\\127.0.0.1\\\\ADMIN$\\\\\_\_\* 2\>\&1""" |fields \_time, agent\_hostname, actor\_effective\_username, os\_actor\_process\_image\_name, action\_process\_image\_command\_line

|-----------------|------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| 1 2 3 4 5 6 7 8 | // Description: Look for instances of cmd.exe being spawned with arguments consistent with the usage of Impacket's Wmiexec // Ref: https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-144a config case\_sensitive = false |dataset = xdr\_data |filter event\_type = ENUM.PROCESS AND event\_sub\_type = ENUM.PROCESS\_START |filter os\_actor\_process\_image\_name = "wmiprvse.exe" AND action\_process\_image\_name = "cmd.exe" AND action\_process\_image\_command\_line contains """/Q /c \* \\\\\\\\127.0.0.1\\\\ADMIN$\\\\\_\_\* 2\>\&1""" |fields \_time, agent\_hostname, actor\_effective\_username, os\_actor\_process\_image\_name, action\_process\_image\_command\_line |

// Description: Looks for the execution of binaries matching the Indicators of compromise (IoCs) in the Volt Typhoon CSA report // Ref: https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-144a config case\_sensitive = false |dataset = xdr\_data |filter event\_type = ENUM.PROCESS AND event\_sub\_type = ENUM.PROCESS\_START |filter action\_process\_image\_sha256 in ("f4dd44bc19c19056794d29151a5b1bb76afd502388622e24c863a8494af147dd","ef09b8ff86c276e9b475a6ae6b54f08ed77e09e169f7fc0872eb1d427ee27d31","d6ebde42457fe4b2a927ce53fc36f465f0000da931cfab9b79a36083e914ceca","472ccfb865c81704562ea95870f60c08ef00bcd2ca1d7f09352398c05be5d05d","66a19f7d2547a8a85cee7a62d0b6114fd31afdee090bd43f36b89470238393d7","3c2fe308c0a563e06263bbacf793bbe9b2259d795fcc36b953793a7e499e7f71","41e5181b9553bbe33d91ee204fe1d2ca321ac123f9147bb475c0ed32f9488597","c7fee7a3ffaf0732f42d89c4399cbff219459ae04a81fc6eff7050d53bd69b99","3a9d8bb85fbcfe92bae79d5ab18e4bca9eaf36cea70086e8d1ab85336c83945f","fe95a382b4f879830e2666473d662a24b34fccf34b6b3505ee1b62b32adafa15","ee8df354503a56c62719656fae71b3502acf9f87951c55ffd955feec90a11484") |fields \_time,agent\_hostname,actor\_effective\_username,actor\_process\_image\_path,action\_process\_image\_path,action\_process\_image\_command\_line,action\_process\_image\_sha256

|-----------------|------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| 1 2 3 4 5 6 7 8 | // Description: Looks for the execution of binaries matching the Indicators of compromise (IoCs) in the Volt Typhoon CSA report // Ref: https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-144a config case\_sensitive = false |dataset = xdr\_data |filter event\_type = ENUM.PROCESS AND event\_sub\_type = ENUM.PROCESS\_START |filter action\_process\_image\_sha256 in ("f4dd44bc19c19056794d29151a5b1bb76afd502388622e24c863a8494af147dd","ef09b8ff86c276e9b475a6ae6b54f08ed77e09e169f7fc0872eb1d427ee27d31","d6ebde42457fe4b2a927ce53fc36f465f0000da931cfab9b79a36083e914ceca","472ccfb865c81704562ea95870f60c08ef00bcd2ca1d7f09352398c05be5d05d","66a19f7d2547a8a85cee7a62d0b6114fd31afdee090bd43f36b89470238393d7","3c2fe308c0a563e06263bbacf793bbe9b2259d795fcc36b953793a7e499e7f71","41e5181b9553bbe33d91ee204fe1d2ca321ac123f9147bb475c0ed32f9488597","c7fee7a3ffaf0732f42d89c4399cbff219459ae04a81fc6eff7050d53bd69b99","3a9d8bb85fbcfe92bae79d5ab18e4bca9eaf36cea70086e8d1ab85336c83945f","fe95a382b4f879830e2666473d662a24b34fccf34b6b3505ee1b62b32adafa15","ee8df354503a56c62719656fae71b3502acf9f87951c55ffd955feec90a11484") |fields \_time,agent\_hostname,actor\_effective\_username,actor\_process\_image\_path,action\_process\_image\_path,action\_process\_image\_command\_line,action\_process\_image\_sha256 |

// Description: Looks for file writes matching the Indicators of compromise (IoCs) in the Volt Typhoon CSA report // Ref: https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-144a config case\_sensitive = false |dataset = xdr\_data |filter event\_type = ENUM.FILE and event\_sub\_type = ENUM.FILE\_WRITE |filter action\_file\_sha256 in ("f4dd44bc19c19056794d29151a5b1bb76afd502388622e24c863a8494af147dd","ef09b8ff86c276e9b475a6ae6b54f08ed77e09e169f7fc0872eb1d427ee27d31","d6ebde42457fe4b2a927ce53fc36f465f0000da931cfab9b79a36083e914ceca","472ccfb865c81704562ea95870f60c08ef00bcd2ca1d7f09352398c05be5d05d","66a19f7d2547a8a85cee7a62d0b6114fd31afdee090bd43f36b89470238393d7","3c2fe308c0a563e06263bbacf793bbe9b2259d795fcc36b953793a7e499e7f71","41e5181b9553bbe33d91ee204fe1d2ca321ac123f9147bb475c0ed32f9488597","c7fee7a3ffaf0732f42d89c4399cbff219459ae04a81fc6eff7050d53bd69b99","3a9d8bb85fbcfe92bae79d5ab18e4bca9eaf36cea70086e8d1ab85336c83945f","fe95a382b4f879830e2666473d662a24b34fccf34b6b3505ee1b62b32adafa15","ee8df354503a56c62719656fae71b3502acf9f87951c55ffd955feec90a11484") |fields \_time, agent\_hostname, actor\_effective\_username, actor\_process\_image\_path, actor\_process\_command\_line, action\_file\_path, action\_file\_sha256

|-----------------|------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| 1 2 3 4 5 6 7 8 | // Description: Looks for file writes matching the Indicators of compromise (IoCs) in the Volt Typhoon CSA report // Ref: https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-144a config case\_sensitive = false |dataset = xdr\_data |filter event\_type = ENUM.FILE and event\_sub\_type = ENUM.FILE\_WRITE |filter action\_file\_sha256 in ("f4dd44bc19c19056794d29151a5b1bb76afd502388622e24c863a8494af147dd","ef09b8ff86c276e9b475a6ae6b54f08ed77e09e169f7fc0872eb1d427ee27d31","d6ebde42457fe4b2a927ce53fc36f465f0000da931cfab9b79a36083e914ceca","472ccfb865c81704562ea95870f60c08ef00bcd2ca1d7f09352398c05be5d05d","66a19f7d2547a8a85cee7a62d0b6114fd31afdee090bd43f36b89470238393d7","3c2fe308c0a563e06263bbacf793bbe9b2259d795fcc36b953793a7e499e7f71","41e5181b9553bbe33d91ee204fe1d2ca321ac123f9147bb475c0ed32f9488597","c7fee7a3ffaf0732f42d89c4399cbff219459ae04a81fc6eff7050d53bd69b99","3a9d8bb85fbcfe92bae79d5ab18e4bca9eaf36cea70086e8d1ab85336c83945f","fe95a382b4f879830e2666473d662a24b34fccf34b6b3505ee1b62b32adafa15","ee8df354503a56c62719656fae71b3502acf9f87951c55ffd955feec90a11484") |fields \_time, agent\_hostname, actor\_effective\_username, actor\_process\_image\_path, actor\_process\_command\_line, action\_file\_path, action\_file\_sha256 |

// Description: Looks for the execution of known Volt Typhoon Fast Reverse Proxy (frp) binaries // Ref: https://www.microsoft.com/en-us/security/blog/2023/05/24/volt-typhoon-targets-us-critical-infrastructure-with-living-off-the-land-techniques/ config case\_sensitive = false |dataset = xdr\_data |filter event\_type = ENUM.PROCESS AND event\_sub\_type = ENUM.PROCESS\_START |filter action\_process\_image\_sha256 in ("baeffeb5fdef2f42a752c65c2d2a52e84fb57efc906d981f89dd518c314e231c","b4f7c5e3f14fb57be8b5f020377b993618b6e3532a4e1eb1eae9976d4130cc74","4b0c4170601d6e922cf23b1caf096bba2fade3dfcf92f0ab895a5f0b9a310349","c0fc29a52ec3202f71f6378d9f7f9a8a3a10eb19acb8765152d758aded98c76d","d6ab36cb58c6c8c3527e788fc9239d8dcc97468b6999cf9ccd8a815c8b4a80af","9dd101caee49c692e5df193b236f8d52a07a2030eed9bd858ed3aaccb406401a","450437d49a7e5530c6fb04df2e56c3ab1553ada3712fab02bd1eeb1f1adbc267","93ce3b6d2a18829c0212542751b309dacbdc8c1d950611efe2319aa715f3a066","7939f67375e6b14dfa45ec70356e91823d12f28bbd84278992b99e0d2c12ace5","389a497f27e1dd7484325e8e02bbdf656d53d5cf2601514e9b8d8974befddf61","c4b185dbca490a7f93bc96eefb9a597684fdf532d5a04aa4d9b4d4b1552c283b","e453e6efc5a002709057d8648dbe9998a49b9a12291dee390bb61c98a58b6e95","6036390a2c81301a23c9452288e39cb34e577483d121711b6ba6230b29a3c9ff","cd69e8a25a07318b153e01bba74a1ae60f8fc28eb3d56078f448461400baa984","17506c2246551d401c43726bdaec800f8d41595d01311cf38a19140ad32da2f4","8fa3e8fdbaa6ab5a9c44720de4514f19182adc0c9c6001c19cf159b79c0ae9c2","d17317e1d5716b09cee904b8463a203dc6900d78ee2053276cc948e4f41c8295","472ccfb865c81704562ea95870f60c08ef00bcd2ca1d7f09352398c05be5d05d","3e9fc13fab3f8d8120bd01604ee50ff65a40121955a4150a6d2c007d34807642") |fields \_time,agent\_hostname,actor\_effective\_username,actor\_process\_image\_path,action\_process\_image\_path,action\_process\_image\_command\_line,action\_process\_image\_sha256

|-----------------|--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| 1 2 3 4 5 6 7 8 | // Description: Looks for the execution of known Volt Typhoon Fast Reverse Proxy (frp) binaries // Ref: https://www.microsoft.com/en-us/security/blog/2023/05/24/volt-typhoon-targets-us-critical-infrastructure-with-living-off-the-land-techniques/ config case\_sensitive = false |dataset = xdr\_data |filter event\_type = ENUM.PROCESS AND event\_sub\_type = ENUM.PROCESS\_START |filter action\_process\_image\_sha256 in ("baeffeb5fdef2f42a752c65c2d2a52e84fb57efc906d981f89dd518c314e231c","b4f7c5e3f14fb57be8b5f020377b993618b6e3532a4e1eb1eae9976d4130cc74","4b0c4170601d6e922cf23b1caf096bba2fade3dfcf92f0ab895a5f0b9a310349","c0fc29a52ec3202f71f6378d9f7f9a8a3a10eb19acb8765152d758aded98c76d","d6ab36cb58c6c8c3527e788fc9239d8dcc97468b6999cf9ccd8a815c8b4a80af","9dd101caee49c692e5df193b236f8d52a07a2030eed9bd858ed3aaccb406401a","450437d49a7e5530c6fb04df2e56c3ab1553ada3712fab02bd1eeb1f1adbc267","93ce3b6d2a18829c0212542751b309dacbdc8c1d950611efe2319aa715f3a066","7939f67375e6b14dfa45ec70356e91823d12f28bbd84278992b99e0d2c12ace5","389a497f27e1dd7484325e8e02bbdf656d53d5cf2601514e9b8d8974befddf61","c4b185dbca490a7f93bc96eefb9a597684fdf532d5a04aa4d9b4d4b1552c283b","e453e6efc5a002709057d8648dbe9998a49b9a12291dee390bb61c98a58b6e95","6036390a2c81301a23c9452288e39cb34e577483d121711b6ba6230b29a3c9ff","cd69e8a25a07318b153e01bba74a1ae60f8fc28eb3d56078f448461400baa984","17506c2246551d401c43726bdaec800f8d41595d01311cf38a19140ad32da2f4","8fa3e8fdbaa6ab5a9c44720de4514f19182adc0c9c6001c19cf159b79c0ae9c2","d17317e1d5716b09cee904b8463a203dc6900d78ee2053276cc948e4f41c8295","472ccfb865c81704562ea95870f60c08ef00bcd2ca1d7f09352398c05be5d05d","3e9fc13fab3f8d8120bd01604ee50ff65a40121955a4150a6d2c007d34807642") |fields \_time,agent\_hostname,actor\_effective\_username,actor\_process\_image\_path,action\_process\_image\_path,action\_process\_image\_command\_line,action\_process\_image\_sha256 |

## Conclusion

Based on the available public information, Unit 42 assesses Insidious Taurus as a top tier, sophisticated APT. We concur with the attribution made in both Joint Cyber Security Advisories that this activity is associated with a PRC state-sponsored actor.

As activity from Insidious Taurus is challenging to detect, we agree with the CSA's recommendations to focus on a few key areas. This includes mitigation activities such as updating any internet facing device like SOHO equipment or virtual private networks (VPNs), as threat actors use these devices as part of a botnet or as an initial access vector.

These recommendations also include strengthening the use of multifactor authentication. And finally, it includes prioritizing sufficient logging, which can be especially important for detecting activity within an environment that could be indicative of living off the land techniques. Additional detailed guidance on actions to take can be found in the latest Joint [CSA](https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-038a).

Palo Alto Networks customers are better protected through our products, as listed below. We will update this threat brief as more relevant information becomes available.

## Palo Alto Networks Product Protections for Insidious Taurus

Palo Alto Networks customers can leverage a variety of product protections and updates designed to identify and defend against this threat.

If you think you may have been compromised or have an urgent matter, get in touch with the [Unit 42 Incident Response team](https://start.paloaltonetworks.com/contact-unit42.html) or call:

* North America Toll-Free: 866.486.4842 (866.4.UNIT42)
* EMEA: +31.20.299.3130
* APAC: +65.6983.8730
* Japan: +81.50.1790.0200

Palo Alto Networks is offering a [no-cost, no-obligation emergency bundle](https://start.paloaltonetworks.com/legacy-vpn-exploit-defense.html) for organizations to help identify and mitigate any exposure to Insidious Taurus's use of exploits that target vulnerabilities in various networking gear, including an Attack Surface Assessment and a Prisma Access 90-day license.

This offer is promotional and subject to availability. Due to the rapidly changing nature of this vulnerability, Palo Alto Networks reserves the right to update this offer.

### Next-Generation Firewalls and Prisma Access With Advanced Threat Prevention

The Next-Generation Firewall with the Advanced Threat Prevention security subscription can help block the attacks via the following Threat Prevention signatures: [91676](https://threatvault.paloaltonetworks.com/?query=91676), [92734](https://threatvault.paloaltonetworks.com/?query=92734), [91362](https://threatvault.paloaltonetworks.com/?query=91362), [90829](https://threatvault.paloaltonetworks.com/?query=90829), [91363](https://threatvault.paloaltonetworks.com/?query=91363), [86360](https://threatvault.paloaltonetworks.com/?query=86360), [90926](https://threatvault.paloaltonetworks.com/?query=90926), [90952](https://threatvault.paloaltonetworks.com/?query=90952), [90972](https://threatvault.paloaltonetworks.com/?query=90972), [90851](https://threatvault.paloaltonetworks.com/?query=90851), [83202](https://threatvault.paloaltonetworks.com/?query=83202), [85739](https://threatvault.paloaltonetworks.com/?query=85739).

Advanced Threat Prevention provides inline machine learning that can help detect vulnerability exploits in real time.

### Prisma Access

All known Insidious Taurus malware samples within [WildFire](https://www.paloaltonetworks.com/products/secure-the-network/wildfire)and all related threat signatures will be detectable by [Prisma Access](https://docs.paloaltonetworks.com/prisma/prisma-access) at services turnup.

Prisma Access is a centralized cloud-delivered security service that uses a Zero Trust Strategy. It enforces the principles of least privilege and continuous trust verification to not only limit access to users based on need, but also to continually monitor changes in application workloads. It also monitors user behavior using cutting-edge machine learning and artificial intelligence to deliver best in breed alerts and mitigation. This establishes protection beyond initial access and can help limit or prevent impact to operations in the case of attempted compromise.

The environment is automatically updated and protected with the latest inline machine learning-powered threat prevention technologies, such as WildFire, Advanced URL Filtering, Advanced Threat Prevention and more. Prisma Access provides a continuous and dynamic security inspection ecosystem that can stop even zero-day threats.

By using machine learning-based detection, Prisma Access is able to provide detection and response to zero-day threats in real time, preventing even some of the most complex attacks that exist in the security landscape today.

Prisma Access also offers advanced DLP protection to protect access and data integrity to all applications and data-based workloads across a customer organization.

### Cortex XSOAR

[Cortex XSOAR](https://docs-cortex.paloaltonetworks.com/p/XSOAR) can automate workflows for data enrichment, IoC hunting and remediation actions to reduce manual work and speed up the patching process.

### Cortex XDR and XSIAM

[Cortex XDR](https://docs-cortex.paloaltonetworks.com/p/XDR) and [XSIAM](https://docs-cortex.paloaltonetworks.com/p/XSIAM) agent helps protect against the techniques executed by this threat actor using Behavioral Threat Protection and its multiple security modules.

Cortex Analytics has multiple detection models covering the techniques, with additional relevant coverage by the Identity Analytics module.

### Cortex Xpanse

[Cortex Xpanse](https://docs-cortex.paloaltonetworks.com/p/XPANSE) is able to detect a wide range of internet-exposed SOHO devices including those manufactured by Cisco, NETGEAR, D-Link, ASUS, H3C, Xiaomi, MikroTik, and more with over 20 different individual rules available.

### Cloud-Delivered Security Services for Next-Generation Firewall

Advanced URL Filtering and DNS Security identify known IPs and domains associated with this group as malicious.

### Prisma Cloud

All known Insidious Taurus malware samples listed within [WildFire](https://www.paloaltonetworks.com/products/secure-the-network/wildfire)will be detectable by [Prisma Cloud](https://www.paloaltonetworks.com/prisma/cloud) agents.

Prisma Cloud continuously monitors for malicious traffic. By integrating the threat intelligence data from WildFire, Prisma Cloud agents are able to detect and protect cloud virtual machines, container and serverless runtime environments from the execution of malicious runtime operations originating from our customers' cloud environments.

## Additional Resources

* [Joint Cybersecurity Advisory: People's Republic of China State-Sponsored Cyber Actor Living off the Land to Evade Detection](https://media.defense.gov/2023/May/24/2003229517/-1/-1/0/CSA_Living_off_the_Land.PDF) \[PDF\] -- Cybersecurity and Infrastructure Security Agency (CISA)
* [Volt Typhoon targets US critical infrastructure with living-off-the-land techniques](https://www.microsoft.com/en-us/security/blog/2023/05/24/volt-typhoon-targets-us-critical-infrastructure-with-living-off-the-land-techniques/) -- Microsoft Threat Intelligence
* [PRC State-Sponsored Actors Compromise and Maintain Persistent Access to U.S. Critical Infrastructure](https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-038a) -- Cybersecurity and Infrastructure Security Agency (CISA)
* [Identifying and Mitigating Living Off the Land Technique](https://www.cisa.gov/sites/default/files/2024-02/Joint-Guidance-Identifying-and-Mitigating-LOTL_V3508c.pdf)s \[PDF\] -- Cybersecurity and Infrastructure Security Agency (CISA)
* [U.S. government disrupts botnet People's Republic of China used to conceal hacking of critical infrastructure](https://www.justice.gov/usao-sdtx/pr/us-government-disrupts-botnet-peoples-republic-china-used-conceal-hacking-critical) -- U.S. Attorney's Office, Southern District of Texas
* [KV-Botnet: Don't Call It A Comeback](https://blog.lumen.com/kv-botnet-dont-call-it-a-comeback/) -- Black Lotus Labs, Lumen
* [Secure by Design Alert: Security Design Improvements for SOHO Device Manufacturers](https://www.cisa.gov/resources-tools/resources/secure-design-alert-security-design-improvements-soho-device-manufacturers) -- Resources, Cybersecurity and Infrastructure Security Agency (CISA)
* [Routers Roasting On An Open Firewall: The KV-Botnet Investigation](https://blog.lumen.com/routers-roasting-on-an-open-firewall-the-kv-botnet-investigation/) -- Black Lotus Labs, Lumen
* [MAR-10448362-1.v1 Volt Typhoon](https://www.cisa.gov/news-events/analysis-reports/ar24-038a) -- Analysis Report, Cybersecurity and Infrastructure Security Agency (CISA)
* [Volt Typhoon Compromises 30% of Cisco RV320/325 Devices in 37 Days](https://securityscorecard.com/blog/threat-intelligence-research-volt-typhoon/) -- SecurityScorecard

*Updated May 26, 2023, at 3:27 p.m. PT.*

*Updated Feb. 14, 2024, at 2:25 p.m. PT.*

*Updated Feb. 20, 2024, at 11:27 a.m. PT to add promotional offer.*
Back to top

### Tags

* [BRONZE SILHOUETTE](https://unit42.paloaltonetworks.com/tag/bronze-silhouette/ "BRONZE SILHOUETTE")
* [China](https://unit42.paloaltonetworks.com/tag/china/ "China")
* [Dev-0391](https://unit42.paloaltonetworks.com/tag/dev-0391/ "Dev-0391")
* [Insidious Taurus](https://unit42.paloaltonetworks.com/tag/insidious-taurus/ "Insidious Taurus")
* [UNC3236](https://unit42.paloaltonetworks.com/tag/unc3236/ "UNC3236")
* [Vanguard Panda](https://unit42.paloaltonetworks.com/tag/vanguard-panda/ "Vanguard Panda")
* [Volt Typhoon](https://unit42.paloaltonetworks.com/tag/volt-typhoon/ "Volt Typhoon")  
  [Threat Research Center](https://unit42.paloaltonetworks.com "Threat Research") [Next: New Vulnerability in QNAP QTS Firmware: CVE-2023-50358](https://unit42.paloaltonetworks.com/qnap-qts-firmware-cve-2023-50358/ "New Vulnerability in QNAP QTS Firmware: CVE-2023-50358")

### Table of Contents

* 

### Related Articles

* [Phantom Taurus: A New Chinese Nexus APT and the Discovery of the NET-STAR Malware Suite](https://unit42.paloaltonetworks.com/phantom-taurus/ "article - table of contents")
* [Threat Actor Groups Tracked by Palo Alto Networks Unit 42 (Updated Aug. 1, 2025)](https://unit42.paloaltonetworks.com/threat-actor-groups-tracked-by-palo-alto-networks-unit-42/ "article - table of contents")
* [Squidoor: Suspected Chinese Threat Actor's Backdoor Targets Global Organizations](https://unit42.paloaltonetworks.com/advanced-backdoor-squidoor/ "article - table of contents")

## Related Nation-State Cyberattacks Resources

![Pictorial representation of the APT Boggy Serpens. An illustrated blue snake is highlighted by a red circle against a night sky. The constellation serpens.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/Boggy-Serpens-1920x900-1-786x368.png)  
[![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) March 16, 2026 [#### Boggy Serpens Threat Assessment](https://unit42.paloaltonetworks.com/boggy-serpens-threat-assessment/)

* [Advanced Persistent Threat](https://unit42.paloaltonetworks.com/tag/advanced-persistent-threat/ "Advanced Persistent Threat")

* [Boggy Serpens](https://unit42.paloaltonetworks.com/tag/boggy-serpens/ "Boggy Serpens")

* [C2](https://unit42.paloaltonetworks.com/tag/c2/ "C2")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/boggy-serpens-threat-assessment/ "Boggy Serpens Threat Assessment")  
  ![A pictorial representation of CL-STA-1087 state-sponsored espionage. An illustration of a glowing red warning icon centered on a detailed blue circuit board background, representing the detection of this persistent campaign targeting Southeast Asian military organizations.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/09_Nation-State-cyberattacks_1920x900-1-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) March 12, 2026 [#### Suspected China-Based Espionage Operation Against Military Targets in Southeast Asia](https://unit42.paloaltonetworks.com/espionage-campaign-against-military-targets/)

* [Advanced Persistent Threat](https://unit42.paloaltonetworks.com/tag/advanced-persistent-threat/ "Advanced Persistent Threat")

* [AppleChris](https://unit42.paloaltonetworks.com/tag/applechris/ "AppleChris")

* [Backdoor](https://unit42.paloaltonetworks.com/tag/backdoor/ "backdoor")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/espionage-campaign-against-military-targets/ "Suspected China-Based Espionage Operation Against Military Targets in Southeast Asia")  
  ![Pictorial representation of the shadow campaigns. Digital graphic showing a networked globe with various data points and connectivity lines, symbolizing global digital communication and information technology.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/02/03_Nation-State-cyberattacks_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/threat-actor-groups.svg)Threat Actor Groups](https://unit42.paloaltonetworks.com/category/threat-actor-groups/) February 5, 2026 [#### The Shadow Campaigns: Uncovering Global Espionage](https://unit42.paloaltonetworks.com/shadow-campaigns-uncovering-global-espionage/)

* [Espionage](https://unit42.paloaltonetworks.com/tag/espionage/ "Espionage")

* [Government](https://unit42.paloaltonetworks.com/tag/government/ "Government")

* [Phishing](https://unit42.paloaltonetworks.com/tag/phishing/ "phishing")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/shadow-campaigns-uncovering-global-espionage/ "The Shadow Campaigns: Uncovering Global Espionage")  
  ![Constellation image representing the constellation schema used by Palo Alto Networks Unit 42 to track nation-state and cybercrime threat actor groups](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/Generic-B-1920x900-1-786x368.png)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/threat-actor-groups.svg)Threat Actor Groups](https://unit42.paloaltonetworks.com/category/threat-actor-groups/) August 1, 2025 [#### Threat Actor Groups Tracked by Palo Alto Networks Unit 42 (Updated Aug. 1, 2025)](https://unit42.paloaltonetworks.com/threat-actor-groups-tracked-by-palo-alto-networks-unit-42/)

* [Academic Serpens](https://unit42.paloaltonetworks.com/tag/academic-serpens/ "Academic Serpens")

* [Agent Serpens](https://unit42.paloaltonetworks.com/tag/agent-serpens/ "Agent Serpens")

* [Agonizing Serpens](https://unit42.paloaltonetworks.com/tag/agonizing-serpens/ "Agonizing Serpens")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/threat-actor-groups-tracked-by-palo-alto-networks-unit-42/ "Threat Actor Groups Tracked by Palo Alto Networks Unit 42 (Updated Aug. 1, 2025)")  
  ![Pictorial representation of Unit 42 threat attribution system. Illustration featuring a white triangle centered within an abstract cosmic background of purple and blue swirls and stars.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/07/Generic-A-1920x900-1-786x368.png)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/threat-actor-groups.svg)Threat Actor Groups](https://unit42.paloaltonetworks.com/category/threat-actor-groups/) July 31, 2025 [#### Introducing Unit 42's Attribution Framework](https://unit42.paloaltonetworks.com/unit-42-attribution-framework/)

* [Advanced Persistent Threat](https://unit42.paloaltonetworks.com/tag/advanced-persistent-threat/ "Advanced Persistent Threat")

* [Bookworm](https://unit42.paloaltonetworks.com/tag/bookworm/ "Bookworm")

* [Nomenclature](https://unit42.paloaltonetworks.com/tag/nomenclature/ "nomenclature")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/unit-42-attribution-framework/ "Introducing Unit 42’s Attribution Framework")  
  ![A representation of a threat group like Jumpy Pisces. Illustrative image featuring two fish and the Pisces constellation superimposed on a stylized, abstract background with flowing purple waves and a starry night sky.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/10/Pisces-NK-A-1920x900-1-786x368.png)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/threat-actor-groups.svg)Threat Actor Groups](https://unit42.paloaltonetworks.com/category/threat-actor-groups/) October 30, 2024 [#### Jumpy Pisces Engages in Play Ransomware](https://unit42.paloaltonetworks.com/north-korean-threat-group-play-ransomware/)

* [North Korea](https://unit42.paloaltonetworks.com/tag/north-korea/ "North Korea")

* [Jumpy Pisces](https://unit42.paloaltonetworks.com/tag/jumpy-pisces/ "Jumpy Pisces")

* [Fiddling Scorpius](https://unit42.paloaltonetworks.com/tag/fiddling-scorpius/ "Fiddling Scorpius")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/north-korean-threat-group-play-ransomware/ "Jumpy Pisces Engages in Play Ransomware")  
  ![Illustrative image featuring two fish and the Pisces constellation superimposed on a stylized, abstract background with flowing purple waves and a starry night sky.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/09/Pisces-NK-A-1920x900-1-786x368.png)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)High Profile Threats](https://unit42.paloaltonetworks.com/category/top-cyberthreats/) September 9, 2024 [#### Threat Assessment: North Korean Threat Groups](https://unit42.paloaltonetworks.com/threat-assessment-north-korean-threat-groups-2024/)

* [North Korea](https://unit42.paloaltonetworks.com/tag/north-korea/ "North Korea")

* [Remote Access Trojan](https://unit42.paloaltonetworks.com/tag/remote-access-trojan/ "Remote Access Trojan")

* [Finance](https://unit42.paloaltonetworks.com/tag/finance/ "Finance")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/threat-assessment-north-korean-threat-groups-2024/ "Threat Assessment: North Korean Threat Groups")  
  ![Pictorial representation of APT Fighting Ursa. The silhouette of a bear and the Ursa constellation inside an orange abstract planet. Abstract, stylized cosmic setting with vibrant blue and purple claw marks, representing space and distant planetary bodies.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/08/Fighting-URSA-1920x900-1-786x368.png)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/threat-actor-groups.svg)Threat Actor Groups](https://unit42.paloaltonetworks.com/category/threat-actor-groups/) August 2, 2024 [#### Fighting Ursa Luring Targets With Car for Sale](https://unit42.paloaltonetworks.com/fighting-ursa-car-for-sale-phishing-lure/)

* [Advanced Persistent Threat](https://unit42.paloaltonetworks.com/tag/advanced-persistent-threat/ "Advanced Persistent Threat")

* [APT28](https://unit42.paloaltonetworks.com/tag/apt28/ "APT28")

* [Fancy Bear](https://unit42.paloaltonetworks.com/tag/fancy-bear/ "Fancy Bear")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/fighting-ursa-car-for-sale-phishing-lure/ "Fighting Ursa Luring Targets With Car for Sale")  
  ![A digital image depicting a skull formed by binary code, composed of ones and zeros, in shades of blue against a black background. The binary numbers appear to float and overlay each other, creating a visually striking and thematic technological motif.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/01_Malware_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) May 23, 2024 [#### Operation Diplomatic Specter: An Active Chinese Cyberespionage Campaign Leverages Rare Tool Set to Target Governmental Entities in the Middle East, Africa and Asia](https://unit42.paloaltonetworks.com/operation-diplomatic-specter/)

* [Advanced Persistent Threat](https://unit42.paloaltonetworks.com/tag/advanced-persistent-threat/ "Advanced Persistent Threat")

* [Backdoor](https://unit42.paloaltonetworks.com/tag/backdoor/ "backdoor")

* [China](https://unit42.paloaltonetworks.com/tag/china/ "China")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/operation-diplomatic-specter/ "Operation Diplomatic Specter: An Active Chinese Cyberespionage Campaign Leverages Rare Tool Set to Target Governmental Entities in the Middle East, Africa and Asia")  
  ![Digital security concept with a visual depiction of a lock icon and various cybersecurity-related words such as "password," "attack" and "danger" illuminated in a blue digital interface that includes a world map.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/04_Nation-State-cyberattacks_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/threat-actor-groups.svg)Threat Actor Groups](https://unit42.paloaltonetworks.com/category/threat-actor-groups/) March 26, 2024 [#### ASEAN Entities in the Spotlight: Chinese APT Group Targeting](https://unit42.paloaltonetworks.com/chinese-apts-target-asean-entities/)

* [Advanced Persistent Threat](https://unit42.paloaltonetworks.com/tag/advanced-persistent-threat/ "Advanced Persistent Threat")

* [Stately Taurus](https://unit42.paloaltonetworks.com/tag/stately-taurus/ "Stately Taurus")

* [APAC](https://unit42.paloaltonetworks.com/tag/apac/ "APAC")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/chinese-apts-target-asean-entities/ "ASEAN Entities in the Spotlight: Chinese APT Group Targeting")

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)  
  ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg) ![Enlarged Image]()  
  ![Newsletter](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/unit42-footer-subscribe-desktop.png)  
  ![UNIT 42 Small Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/palo-alto-logo-small.svg) Get updates from Unit 42

## Peace of mind comes from staying ahead of threats. Subscribe today.

Your Email

Subscribe for email updates to all Unit 42 threat research.  
By submitting this form, you agree to our [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use "Terms of Use") and acknowledge our [Privacy Statement.](https://www.paloaltonetworks.com/legal-notices/privacy "Privacy Statement")

This site is protected by reCAPTCHA and the Google [Privacy Policy](https://policies.google.com/privacy) and [Terms of Service](https://policies.google.com/terms) apply.

Invalid captcha!
Subscribe ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg) ![loader](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-loader.svg)  
{#footer} Products and Services

* [AI-Powered Network Security Platform](https://www.paloaltonetworks.com/network-security)

* [Secure AI by Design](https://www.paloaltonetworks.com/ai-security)

* [Prisma AIRS](https://www.paloaltonetworks.com/ai-security/prisma-airs)

* [AI Access Security](https://www.paloaltonetworks.com/sase/ai-access-security)

* [Cloud Delivered Security Services](https://www.paloaltonetworks.com/network-security/security-subscriptions)

* [Advanced Threat Prevention](https://www.paloaltonetworks.com/network-security/advanced-threat-prevention)

* [Advanced URL Filtering](https://www.paloaltonetworks.com/network-security/advanced-url-filtering)

* [Advanced WildFire](https://www.paloaltonetworks.com/network-security/advanced-wildfire)

* [Advanced DNS Security](https://www.paloaltonetworks.com/network-security/advanced-dns-security)

* [Enterprise Data Loss Prevention](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention)

* [Enterprise IoT Security](https://www.paloaltonetworks.com/network-security/enterprise-device-security)

* [Medical IoT Security](https://www.paloaltonetworks.com/network-security/medical-device-security)

* [Industrial OT Security](https://www.paloaltonetworks.com/network-security/ot-security-solution)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security)

* [Next-Generation Firewalls](https://www.paloaltonetworks.com/network-security/next-generation-firewall)

* [Hardware Firewalls](https://www.paloaltonetworks.com/network-security/hardware-firewall-innovations)

* [Software Firewalls](https://www.paloaltonetworks.com/network-security/software-firewalls)

* [Strata Cloud Manager](https://www.paloaltonetworks.com/network-security/strata-cloud-manager)

* [SD-WAN for NGFW](https://www.paloaltonetworks.com/network-security/sd-wan-subscription)

* [PAN-OS](https://www.paloaltonetworks.com/network-security/pan-os)

* [Panorama](https://www.paloaltonetworks.com/network-security/panorama)

* [Secure Access Service Edge](https://www.paloaltonetworks.com/sase)

* [Prisma SASE](https://www.paloaltonetworks.com/sase)

* [Application Acceleration](https://www.paloaltonetworks.com/sase/app-acceleration)

* [Autonomous Digital Experience Management](https://www.paloaltonetworks.com/sase/adem)

* [Enterprise DLP](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention)

* [Prisma Access](https://www.paloaltonetworks.com/sase/access)

* [Prisma Browser](https://www.paloaltonetworks.com/sase/prisma-browser)

* [Prisma SD-WAN](https://www.paloaltonetworks.com/sase/sd-wan)

* [Remote Browser Isolation](https://www.paloaltonetworks.com/sase/remote-browser-isolation)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security)

* [AI-Driven Security Operations Platform](https://www.paloaltonetworks.com/cortex)

* [Cloud Security](https://www.paloaltonetworks.com/cortex/cloud)

* [Cortex Cloud](https://www.paloaltonetworks.com/cortex/cloud)

* [Application Security](https://www.paloaltonetworks.com/cortex/cloud/application-security)

* [Cloud Posture Security](https://www.paloaltonetworks.com/cortex/cloud/cloud-posture-security)

* [Cloud Runtime Security](https://www.paloaltonetworks.com/cortex/cloud/runtime-security)

* [Prisma Cloud](https://www.paloaltonetworks.com/prisma/cloud)

* [AI-Driven SOC](https://www.paloaltonetworks.com/cortex)

* [Cortex XSIAM](https://www.paloaltonetworks.com/cortex/cortex-xsiam)

* [Cortex XDR](https://www.paloaltonetworks.com/cortex/cortex-xdr)

* [Cortex XSOAR](https://www.paloaltonetworks.com/cortex/cortex-xsoar)

* [Cortex Xpanse](https://www.paloaltonetworks.com/cortex/cortex-xpanse)

* [Unit 42 Managed Detection \& Response](https://www.paloaltonetworks.com/cortex/managed-detection-and-response)

* [Managed XSIAM](https://www.paloaltonetworks.com/cortex/managed-xsiam)

* [Next-Generation Identity Security](https://www.paloaltonetworks.com/idira)

* [Privileged Access Management](https://www.paloaltonetworks.com/idira/human/privileged-access-management)

* [Identity and Access Management](https://www.paloaltonetworks.com/idira/human/identity-and-access-management)

* [Endpoint Privilege Manager](https://www.paloaltonetworks.com/idira/human/endpoint-privilege-manager)

* [Identity Governance](https://www.paloaltonetworks.com/idira/human/identity-governance)

* [Workforce Password Management](https://www.paloaltonetworks.com/idira/human/workforce-password-management)

* [Agentic Identities](https://www.paloaltonetworks.com/idira/agentic)

* [Secrets Management](https://www.paloaltonetworks.com/idira/machine/secrets-management)

* [Unified Secrets Governance](https://www.paloaltonetworks.com/idira/machine/unified-secrets-governance)

* [Application Credentials Delivery](https://www.paloaltonetworks.com/idira/machine/application-credentials-delivery)

* [Vendor Privileged Access](https://www.paloaltonetworks.com/idira/human/vendor-privileged-access)

* [Threat Intel and Incident Response Services](https://www.paloaltonetworks.com/unit42)

* [Proactive Assessments](https://www.paloaltonetworks.com/unit42/assess)

* [Incident Response](https://www.paloaltonetworks.com/unit42/respond)

* [Transform Your Security Strategy](https://www.paloaltonetworks.com/unit42/transform)

* [Discover Threat Intelligence](https://www.paloaltonetworks.com/unit42/threat-intelligence-partners)  
  Company

* [About Us](https://www.paloaltonetworks.com/about-us)

* [Careers](https://jobs.paloaltonetworks.com/en/)

* [Contact Us](https://www.paloaltonetworks.com/company/contact-sales)

* [Corporate Responsibility](https://www.paloaltonetworks.com/about-us/corporate-responsibility)

* [Customers](https://www.paloaltonetworks.com/customers)

* [Investor Relations](https://investors.paloaltonetworks.com/)

* [Location](https://www.paloaltonetworks.com/about-us/locations)

* [Newsroom](https://www.paloaltonetworks.com/company/newsroom)  
  Popular Links

* [Blog](https://www.paloaltonetworks.com/blog/)

* [Communities](https://www.paloaltonetworks.com/communities)

* [Content Library](https://www.paloaltonetworks.com/resources)

* [Cyberpedia](https://www.paloaltonetworks.com/cyberpedia)

* [Event Center](https://events.paloaltonetworks.com/)

* [Manage Email Preferences](https://start.paloaltonetworks.com/preference-center)

* [Products A-Z](https://www.paloaltonetworks.com/products/products-a-z)

* [Product Certifications](https://www.paloaltonetworks.com/legal-notices/trust-center/certifications)

* [Report a Vulnerability](https://www.paloaltonetworks.com/security-disclosure)

* [Sitemap](https://www.paloaltonetworks.com/sitemap)

* [Tech Docs](https://docs.paloaltonetworks.com/)

* [Unit 42](https://unit42.paloaltonetworks.com/)

* [Do Not Sell or Share My Personal Information](https://panwedd.exterro.net/portal/dsar.htm?target=panwedd)
  ![Palo Alto Networks Logo](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/pan-logo-dark.svg)

* [Privacy](https://www.paloaltonetworks.com/legal-notices/privacy)

* [Trust Center](https://www.paloaltonetworks.com/legal-notices/trust-center)

* [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use)

* [Documents](https://www.paloaltonetworks.com/legal)

Copyright © 2026 Palo Alto Networks. All Rights Reserved

* [![Youtube](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/youtube-black.svg)](https://www.youtube.com/user/paloaltonetworks)
* [![Podcast](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/icons/podcast.svg)](https://www.paloaltonetworks.com/podcasts/threat-vector)
* [![Facebook](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/facebook-black.svg)](https://www.facebook.com/PaloAltoNetworks/)
* [![LinkedIn](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/linkedin-black.svg)](https://www.linkedin.com/company/palo-alto-networks)
* [![Twitter](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/twitter-x-black.svg)](https://twitter.com/PaloAltoNtwks)
* EN  
  Select your language  
  ![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg) ![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg) ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg)

### Default Heading

Read the article ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg)  
Seekbar

![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg)  
![Volume](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-volume.svg)  
Volume
![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg)
