Exploitation of CVE-2024-3400 in Palo Alto Networks Firewalls
An active global campaign is targeting organizations with vulnerable Palo Alto Networks firewalls running specific PAN-OS versions. The campaign exploits CVE-2024-3400 within the GlobalProtect gateway feature to gain unauthorized access. OffPerimeter analysis indicates this activity is driven by espionage motivations and targets critical infrastructure across multiple sectors and countries.
- First seen
- 2023-11-12
- Last seen
- 2026-10-06
- Threat actors
- UNC5478, UNC5470, UNC5463, UNC5439, UNC5716, UNC5807, UNC5859, UNC5174, UNC5454
- Malware
- PHOTO, METTLE, SLIVER, BEACON, VSHELL, CROSSC2, CRABPOT, STOWAWAY, SNOWLIGHT
- Sectors
- Defense & Military, Chemicals & Materials, Education & Research, Energy & Utilities, Financial Services, Government, Insurance, Manufacturing
- Countries
- BD, BR, IN, KR, GB, SK, SG, AU
How it works
The attack chain begins with the exploitation of CVE-2024-3400 on Palo Alto Networks firewalls where the GlobalProtect gateway is enabled. Once initial access is achieved, the actors deploy various malware families to establish persistence and facilitate command and control. The attackers then proceed to perform credential dumping and lateral movement to achieve their espionage objectives.
Techniques (MITRE ATT&CK)
- T1003 · Credential AccessOS Credential DumpingThe actors attempt to extract sensitive credentials from the local system to facilitate further movement.
- T1003.008 · Credential AccessSecurity Account ManagerAttackers target the SAM database to obtain local account credentials.
- T1016 · DiscoverySystem Network Configuration DiscoveryThe campaign involves identifying network settings to map the internal environment.
- T1016.001 · DiscoverySystem Network Configuration Discovery: IP ConfigurationActors examine IP configurations to understand the network topology.
- T1021 · Lateral MovementRemote ServicesThe threat actors utilize remote services to move between compromised systems.
- T1021.004 · Lateral MovementRemote Services: SSHSSH is leveraged to access and control remote hosts within the target network.
- T1027 · Defense EvasionObfuscated Files or InformationMalware and communications are obfuscated to bypass security monitoring.
- T1027.002 · Defense EvasionObfuscated Files or Information: Software PackingThe actors use software packing to hide the true nature of their malicious payloads.
- T1027.010 · Defense EvasionObfuscated Files or Information: Encrypted DataData is encrypted to prevent detection by deep packet inspection tools.
- T1027.015 · Defense EvasionObfuscated Files or Information: MasqueradingMalicious files are disguised as legitimate system files or processes.
- T1033 · Initial AccessExternal Remote ServicesThe exploitation of the GlobalProtect gateway provides access via external remote services.
- T1036 · Defense EvasionMasqueradingThe actors use masquerading techniques to blend in with normal user activity.
- T1036.011 · Defense EvasionMasquerading: Drive Name/LabelAttackers may manipulate drive names to hide malicious volumes.
- T1049 · DiscoverySystem Information DiscoveryThe actors gather system information to tailor their subsequent actions.
Indicators
Indicators associated with this campaign in the sources we reviewed. Corroborate before blocking: an address or domain can be shared infrastructure.
- 0856cc2313779f716a6a5ddb9de07373f5fc2d95bdd86dd104f97ca486407160
- 10b0dc48de4a328399bf7d23e3d2b07814e43262d51dd060f2eb48bde066497c
- 12532e3fd9ceb0a74df057522496fd4e7c4efea23f57e3809afc7e2be2a20d1f
- 1509303da0eb3024e5a666623ba4a325ce355d1cab23ae7d97f255dab4c9b966
- 15cd7ea45247c1409112b379705f6dfe0ab0568af7cbed8b2b67bdc1a03a2403
- 286c4699b785558913fc3e49fbc8639fee7bd1bb664c96cfaa36c8ed442f762b
- 295a30a2b4420f873ec8b491d3cb1cf5d4df9cd4a294d69bb5c7147b990108df
- 2bdc441c988cf7962897c140a2c44c5956a7976e5a0009c2b74bc6d8193a1dcd
- 3de2a4392b8715bad070b2ae12243f166ead37830f7c6d24e778985927f9caac
- 3f6165cc620c04937a3ef8d7b9fd05bf7a239d0a048559557661c8e977e1beaf
- 49513eb831d0cbc9801bc1763e7b6f32d813e7679cb3965ed8cb404d83a88473
- 52fa5823993992db3baf6051240eb978a3a133c813e4b7541b6f2657c5613039
- 53c59cc5616349bb74013fbd8c1d79845cec6a509b66ae452921dc0c1487b588
- 568d523f68c6d27272b15896aea1f4d48798a7dd2eb0e860e73029d1326ba007
- 5c743d73ac91e6788aa14a0b2adc044b2732afeb24aa67d7abb1e3599e36ee72
- 5d5fb9e14c673c80c0eded00f5fe50522add96313f63409dce9e17ad68428aea
- 5f4699232d6c95cb4b4b6390998fc754a751c6018d9fd79f22bf423de2430ca8
- 61a26509c2678d5c1237e52836b21a43a55aa0c8dc5c1a080191f0a154b8b2f3
- 6949e0d601126045efe3915c5a3b01c099b477473360e7e51345b4bbb9f343d5
- 7787eca1528144693930458282ee26c39508a9014152d36efa3b8645c188964c
- 821e5f38c73df277bebabca60f6f9d618f467596a84be24fb5ec012eb4e6457d
- 8b703bd014139a4f1ee525647c002ac3a9a471a6583758fffec084b253fede0a
- 965726977fffd0ee0fb2f15d609a2da7bb755652df00a7fbf63ef58ecd5cd749
- a3092bfa4199def7fc525465895ee3784c6fcf55f0a7e9c8436c027e0f41cb4b
- a6eea0ebef6c20fcf457e9f3709be9a5cd5dfaea7295ba11bb36ba489b44b1be
- aa677e5668ddc6edda8f5bddc91448fa4d1f6d03db2a8e20ed1bd55060c993b4
- acbd2ed341e3dab5d7f258afc098ca86be9916bca6b9d2624557100164a4df2e
- ae19378b68baba9404906cef8ba146fa0b2bf7eab37ccccd8ca09e00567bcd4e
- af788c0bf2463bd56a442b09bbb8b26f629bf62be4af0bfa86eab9abbde5c9ba
- b94d9412764529f264433c39b6043d43b96e824d016f40a5a38e26771374171f
- c3d78260040e897519695fa6d554fbe3daca17ec266f310acd0420f0b3127a71
- c611350b59fd8f056dd710f96b597aa4e5dff164289dfcecd638248b9dc67b68
- cba4417813584f4def56a685e38b98a0e85713fd85339adf9f38fbf503ec17c7
- e0556e910d37a0d9667bb9ba952c3d95845c185e2675c1a3875a0d298a27742d
- e386a0d71efe36d6959c57867b91eb72fd79cfee1b8843b0f6e9ed92b8cc7c99
- e96f6ca8ecc00fcfac88679e475022091ce47f75c54f47570d66a56d77cd5ea6
- eb1df006c34463faf8325c52c2f132b62adaaff37afc0bd7ddf0274fa30e59d0
- ed7b722c482b62b0cb0d81f0b1a3e1a8ab36145d6e5e648099e528202a41f277
- ee36214c0084f8c7a753704cf08229757f662cbead135c73748cc59b06c95f23
- ef65b5d6ace96a9fdd9521cd1def06068f42cbe28e95d2197df42f8b6ae64490
- f24f03b704fa52977a59e8f6b26a3685d95618fc1ec9c3c5761067cc19a5b5e7
- f670912ea8dc775e57b1352091a5a11894ae55fd59fbadcb64f1dc34331668c2
- f6cb2d070a301ac1f93d2d648dc443ae7e21ffb729f44ca407cefd3a5bc056c4
- fdd85e50bb93238860b11a7dc6c6c84246087549d777b98cdf393db9763c5a2d
- 1cce3c80.dnslog.biz
- admins.windowstimes.online
- ccc.jw44yo.dnslog.cn
- cof960h1ckcrrrblos10cjtwoyrwiqheb.oast.site
- cog0ksv4nbke32ners3gkhmkndrtxnhie.oast.site
- cog0mmf4nbkfic0tol404pfux5q345hbt.oast.me
- cog0mmf4nbkfic0tol40tfzg5imoqypno.oast.me
- d2d03890.dnslog.biz
- dd.1b6e00d440.ipv6.1433.eu.org
- dnslog.biz
- edcjn.57fe6f5d9d.ipv6.1433.eu.org
- image.windowstimes.online
- images.windowstimes.online
- img.dxyjg.com
- kekeoamigo.com
- obugthbjgbtxngvppgaonru691httfo9n.oast.fun
- orveckjdwmtogblfzhwb2rhs30k8nzrz9.oast.fun
- so1dsa.dnslog.cn
- srgsd1f.842b727ba4.ipv6.1433.eu.org
- srgsdf.842b727ba4.ipv6.1433.eu.org
- times.windowstimes.online
- update.windowstimes.online
- windowstimes.online
- 101.100.160.82
- 103.228.108.247
- 103.241.27.7
- 103.37.228.210
- 104.131.69.106
- 107.191.48.109
- 109.120.178.253
- 111.90.146.240
- 116.212.120.32
- 122.186.150.242
- 134.213.29.14
- 137.118.185.101
- 139.59.14.149
- 140.82.63.209
- 143.198.1.178
- 144.172.122.152
- 146.70.192.174
- 146.70.192.180
- 149.248.77.9
- 149.28.92.212
- 149.36.48.72
- 15.235.130.26
- 154.88.26.223
- 156.244.14.127
- 159.65.33.252
- 167.99.87.255
- 174.119.93.220
- 178.17.169.233
- 18.221.169.125
- 180.210.220.139
- 181.214.164.177
- 185.196.9.154
- 185.244.208.129
- 185.245.80.234
- 188.166.87.88
- 192.248.172.177
- 193.222.96.163
- 194.124.216.24
- 194.35.121.160
- 194.36.171.43
- 198.58.109.149
- 203.160.86.50
- 206.237.0.87
- 206.237.3.150
- 207.148.121.70
- 212.113.106.100
- 216.128.141.153
- 216.250.118.219
- 217.155.101.248
- 217.69.3.218
- http://43.226.17.41:8000/cs/Ladon911/
- http://43.226.17.41:8000/cs/c2lint
- http://image.windowstimes.online/swk
- http://43.226.17.41:8000/nuclei-templates/
- http://image.windowstimes.online/slt
- http://43.226.17.41:8000/plugin.xray.yaml
- http://43.226.17.41:8000/reports/
- http://43.226.17.41:8000/cs/taowu-cobalt-strike-master/
- http://43.226.17.41:8000/cs/cobaltstrike.store
- http://172.233.228.93/vpn_prot.gz
- http://109.120.178.253:8443/
- http://38.60.214.5/2.txt
- http://43.226.17.41:8000/qd.sh
- http://43.226.17.41:8000/kr.txt
- http://images.windowstimes.online/?h=images.windowstimes.online&p=80&t=tcp&a=l32&stage=true
- http://43.226.17.41:8000/.xterminal/
- http://109.120.178.253:10000/cp.txt
- http://43.226.17.41:8000/arm_eabi5_agent
- http://43.226.17.41:8000/inft.txt
- http://43.226.17.41:8000/cs/.cobaltstrike.beacon_keys
- http://43.226.17.41:8000/FH-Admin-registerSysUser-do-ShiroRCE.yaml
- http://43.226.17.41:8000/dur.txt
- http://image.windowstimes.online/swt
- http://images.windowstimes.online/?h=images.windowstimes.online&p=80&t=tcp&a=w32&stage=true
- http://43.226.17.41:8000/.Xauthority
- http://43.226.17.41:8000/%E7%BA%A2%E9%98%9F%E7%89%88.zip
- http://43.226.17.41:8000/jp.txt
- http://43.226.17.41:8000/qq.txt
- http://images.windowstimes.online/?h=images.windowstimes.online&p=80&t=ws&a=w64&stage=true
- http://43.226.17.41:8000/xray.yaml
- http://43.226.17.41:8000/cs/data/listeners.bin
- http://43.226.17.41:8000/cs/cs.jar
- http://43.226.17.41:8000/cs/logs/
- http://43.226.17.41:8000/.bash_history
- http://images.windowstimes.online/sww
- http://43.226.17.41:8000/Anarchy%20Panel%204.7.zip
- http://43.226.17.41:8000/.local/
- http://43.226.17.41:8000/uk.txt
- http://43.226.17.41:8000/.ssh/
- http://185.196.9.154:8081/ROvI-JgW2oTA1Q8XiNRzXQ
- http://43.226.17.41:8000/
- http://43.226.17.41:8000/.cache/
- http://43.226.17.41:8000/NewArtifact.exe
- http://43.226.17.41:8000/cs.exe
- http://43.226.17.41:8000/cs/data/
- http://43.226.17.43:8000/cs/nohup.out
- http://images.windowstimes.online/?h=images.windowstimes.online&p=80&t=ws&a=l32&stage=true
- http://images.windowstimes.online/?a=w64&h=images.windowstimes.online&t=ws_&p=80
- http://43.226.17.41:8000/cs/.UserData.user
- http://217.69.3.218:443/snmpd.elf
What to do
- Immediately patch Palo Alto Networks PAN-OS to versions unaffected by CVE-2024-3400.
- Disable the GlobalProtect gateway feature if it is not strictly required for business operations.
- Monitor firewall logs for unusual administrative access or unexpected configuration changes.
- Implement strict egress filtering to block communication with known malicious C2 infrastructure.
- Audit all service accounts and rotate credentials for high value administrative users.
- Deploy endpoint detection and response solutions to identify unauthorized credential dumping attempts.