#unit42
Cyberattackers may have compromised lots of organizations by exploiting two zero-day vulnerabilities found in widely used Palo Alto Networks systems. unit42.paloaltonetworks.com/cve-2024-001...
November 22, 2024 at 9:54 AM
September 30, 2025 at 1:05 PM
Romania's cybersecurity agency says the Lynx ransomware is behind the attack on the country's largest electricity provider

dnsc.ro/citeste/aler...

Per PAN, Lynx is allegedly a rebrand of the old INC gang: unit42.paloaltonetworks.com/inc-ransomwa...
December 11, 2024 at 6:58 PM
Both Wiz and Palo Alto Networks have found evidence that the compromise of the Changed-Files GitHub Action might have been a complex multi-tier supply chain attack targeting tools used by Coinbase developers

www.wiz.io/blog/new-git...

unit42.paloaltonetworks.com/github-actio...
March 23, 2025 at 12:27 PM
The FortiBleed attacker has also targeted Microsoft SQL database servers and Sophos firewalls

A known initial access broker has taken credit for the campaign in a dark web forum post

unit42.paloaltonetworks.com/large-scale-...
June 21, 2026 at 10:46 AM
Palo Alto looks at Slow Pisces, a North Korean APT and its recent campaign that targeted cryptocurrency developers on LinkedIn, posing as potential employers, and sending malware disguised as coding challenges.

unit42.paloaltonetworks.com/slow-pisces-...
April 15, 2025 at 12:34 PM
"Between early November and December 2024, Palo Alto Networks researchers discovered new Linux malware called Auto-color."

Was used to target universities and government offices in North America and Asia, so prolly an APT here

unit42.paloaltonetworks.com/new-linux-ba...
February 25, 2025 at 10:32 AM
PAN's Unit42 solves an old APT mystery and links the Stately Taurus APT to Bookworm, a mysterious trojan used in espionage campaigns for the past decade.

unit42.paloaltonetworks.com/stately-taur...
Stately Taurus Activity in Southeast Asia Links to Bookworm Malware
Unit 42 details the just-discovered connection between threat group Stately Taurus (aka Mustang Panda) and the malware Bookworm, found during analysis of the group's infrastructure. Unit 42 details th...
unit42.paloaltonetworks.com
February 20, 2025 at 1:50 PM
PAN's Unit42 looks at IUAM ClickFix Generator, a new phishing kit designed around using ClickFix-based phishing pages.

unit42.paloaltonetworks.com/clickfix-gen...
October 9, 2025 at 4:35 PM
Writeup on DPRK IT workers by Unit42. unit42.paloaltonetworks.com/north-korean...
November 13, 2024 at 1:59 PM
#100DaysofYARA throwback to @0xkyle.bsky.social and I finding a weird payload getting dropped by UNK_SweetSpector - it was like a weird cross-mutation of SugarGh0st and what Unit42 called TunnelSpecter and SweetSpecter. payload uses Incognito framework for token forgery

github.com/100DaysofYAR...
January 10, 2025 at 7:35 PM
New, by me: A newly discovered zero-day bug in Microsoft SharePoint is being used to mass-hack and steal data from companies and governments around the world.

🚨 Unit42 says if you have a SharePoint server exposed to the internet, "you should assume that you have been compromised at this point."
New zero-day bug in Microsoft SharePoint under widespread attack | TechCrunch
Security researchers say Microsoft customers should take immediate action to defend against the ongoing cyberattacks, and must assume they have already been compromised.
techcrunch.com
July 21, 2025 at 12:56 PM
Auto-Color : An Emerging and Evasive Linux Backdoor : unit42.paloaltonetworks.com/new-linux-ba...
February 25, 2025 at 1:51 PM
Coinbase was the initial target of the supply chain actor behind tj-actions. Still no attribution yet. unit42.paloaltonetworks.com/github-actio...
unit42.paloaltonetworks.com
March 21, 2025 at 4:07 PM
September 18, 2025 at 3:30 PM
Palo Alto Networks has published a blog post on how its APT naming scheme works

unit42.paloaltonetworks.com/unit-42-attr...
July 31, 2025 at 6:57 PM
📢 Extortion and Ransomware Trends January-March 2025
https://unit42.paloaltonetworks.com/2025-ransomware-extortion-trends/
April 25, 2025 at 1:41 AM
This is fantastic research from Unit42. My takeaway here is that passkeys are still much better than passwords, and Chrome as a credential manager is still a terrible idea.

Use a separate password manager.
Pass the Passkey: A Novel Attack Surface in Passwordless Authentication
Explore how passkey implementation gaps undermine security when relying parties fail to validate the User Verified flag, reducing MFA to a single factor.
unit42.paloaltonetworks.com
August 3, 2026 at 7:58 PM
El Jefe's missive:

If there's something to pass,
there's something to steal.

unit42.paloaltonetworks.com/passwordless...
Pass the Passkey: A Novel Attack Surface in Passwordless Authentication
Explore how passkey implementation gaps undermine security when relying parties fail to validate the User Verified flag, reducing MFA to a single factor.
unit42.paloaltonetworks.com
August 3, 2026 at 8:06 PM
In a recent wave of #SocialEngineering, attackers impersonate help desk personnel and use MS Teams to contact potential victims. This campaign distributes Trojanized installers for GlobalProtect to infect vulnerable hosts with #MadMxShell. More info at bit.ly/43lCQLo
Unit42-timely-threat-intel/2025-05-07-IOCs-from-Teams-phishing-for-MadMxShell.txt at main · PaloAltoNetworks/Unit42-timely-threat-intel
A collection of files with indicators supporting social media posts from Palo Alto Network's Unit 42 team to disseminate timely threat intelligence. - PaloAltoNetworks/Unit42-timely-threat-intel
bit.ly
May 12, 2025 at 9:36 PM
A new #phishing campaign uses lures mimicking legitimate messages from online services, but sent from compromised emails. Embedded links in the email body lead to malicious content hosted on Replit's AI cloud platform, to harvest credentials. Indicators: bit.ly/4l8RV8N
Unit42-timely-threat-intel/2025-07-29-IOCs-for-Replit-activity.txt at main · PaloAltoNetworks/Unit42-timely-threat-intel
A collection of files with indicators supporting social media posts from Palo Alto Network's Unit 42 team to disseminate timely threat intelligence. - PaloAltoNetworks/Unit42-timely-threat-intel
bit.ly
July 29, 2025 at 9:42 PM
An emerging attachk technique, in which adversaries systematically query LLMs to identify predictable hallucinated domains, register those domains, & exploit LLMs' recommendations to direct users or autonomous agents to attacker-controlled infrastructure.
unit42.paloaltonetworks.com/phantom-squa...
Phantom Squatting: AI-Hallucinated Domains as a Software Supply Chain Vector
Attackers can exploit LLM domain hallucinations through phantom squatting to target supply chains. Read the analysis to learn more.
unit42.paloaltonetworks.com
July 17, 2026 at 11:31 AM
PAN published TTPs from Muddled Libra (Scattered Spider) intrusions.

Per the graph, they've certainly changed.

This is because individuals who made up the Scattered Spider "group" back in 2023 have been arrested, and this is a new "batch" of APTeens.

unit42.paloaltonetworks.com/muddled-libra/
July 27, 2025 at 6:36 PM
November 18, 2024 at 1:25 PM