2,000 Palo Alto Networks devices compromised in latest attacks

Share:

Attackers have compromised around 2,000 Palo Alto Networks firewalls by leveraging the two recently patched zero-days (CVE-2024-0012 and CVE-2024-9474), Shadowserver Foundation’s internet-wide scanning has revealed.

Compromised devices are predominantly located in the US and India, the nonprofit says.

Manual and automated scanning activity has been spotted

Approximately two weeks ago, Palo Alto Networks warned that attackers have been spotted leveraging a zero-day flaw to achieve remote code execution on vulnerable devices, and advised admins to make sure that access to the devices’ management interfaces was appropriately secured.

On Monday, the company confirmed that there were two zero-days under exploitation: CVE-2024-0012, which allows unauthenticated access to the interface in question, and CVE-2024-9474, which allows attackers to escalate their privileges on compromised Palo Alto Networks firewalls to root, and that attackers have been dropping webshells on them.

WatchTowr researchers followed that by publishing an analysis of how the two bugs can be used in concert and a Nuclei template that admins could leverage to check whether their devices are affected by them.

In the meantime, the attacks continued and Palo Alto thinks they may escalate.

“At this time, Unit 42 assesses with moderate to high confidence that a functional exploit chaining CVE-2024-0012 and CVE-2024-9474 is publicly available, which will enable broader threat activity,” the company’s incident responders have shared on Wednesday.

“Unit 42 has also observed both manual and automated scanning activity aligning with the timeline of third-party artifacts becoming widely available.”

Palo Alto Networks continues adding new indicators of compromise associated with these attacks.

The company has additionally revealed that the two vulnerabilities also affect its Panorama (firewall management) appliances, as well as its WildFire appliances, which are used for setting up sandbox systems to analyze suspicious files. (Those appliances are also running PAN-OS.)

Affected organizations are advised to check the security advisories for remediation guidance.

UPDATE (November 22, 2024, 02:20 p.m. ET):

“Arctic Wolf has observed multiple intrusions across a variety of industries involving Palo Alto Network firewall devices,” the company’s researchers shared today.

Based on the timing – the attacks started several hours after watchTowr published their analysis of the two vulnerabilities and explained how they can be exploited in tandem – and based on the names of some files observed in the attacks, “we assess with moderate confidence that these intrusions likely involved the exploitation of CVE-2024-0012 chained together with CVE-2024-9474 for initial access,” they said.

Following the initial compromise, in some instances the attackers tried to:

  • Download a Sliver C2 (command and Control) implant
  • Exfiltrate data (firewall configuration files, mostly, but also operating system passwd and shadow files)
  • Deploy an obfuscated PHP webshell
  • Deployment the XMRig cryptocoin miner on the compromised devices

Zeljka Zorz

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
1:28 pm, Feb 3, 2025
weather icon 8°C
L: 7° | H: 9°
overcast clouds
Humidity: 81 %
Pressure: 1024 mb
Wind: 9 mph S
Wind Gust: 0 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 100%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 7:35 am
Sunset: 4:53 pm
DailyHourly
Daily ForecastHourly Forecast
Today 9:00 pm
weather icon
7° | 9°°C 0 mm 0% 8 mph 97 % 1025 mb 0 mm/h
Tomorrow 9:00 pm
weather icon
5° | 9°°C 0.2 mm 20% 14 mph 98 % 1027 mb 0 mm/h
Wed Feb 05 9:00 pm
weather icon
4° | 8°°C 0 mm 0% 8 mph 89 % 1044 mb 0 mm/h
Thu Feb 06 9:00 pm
weather icon
3° | 8°°C 0 mm 0% 10 mph 86 % 1045 mb 0 mm/h
Fri Feb 07 9:00 pm
weather icon
3° | 6°°C 0 mm 0% 14 mph 91 % 1039 mb 0 mm/h
Today 3:00 pm
weather icon
7° | 8°°C 0 mm 0% 8 mph 86 % 1025 mb 0 mm/h
Today 6:00 pm
weather icon
6° | 7°°C 0 mm 0% 5 mph 91 % 1024 mb 0 mm/h
Today 9:00 pm
weather icon
5° | 5°°C 0 mm 0% 5 mph 97 % 1024 mb 0 mm/h
Tomorrow 12:00 am
weather icon
5° | 5°°C 0 mm 0% 5 mph 98 % 1024 mb 0 mm/h
Tomorrow 3:00 am
weather icon
7° | 7°°C 0 mm 0% 7 mph 91 % 1023 mb 0 mm/h
Tomorrow 6:00 am
weather icon
6° | 6°°C 0 mm 0% 9 mph 95 % 1022 mb 0 mm/h
Tomorrow 9:00 am
weather icon
7° | 7°°C 0 mm 0% 11 mph 90 % 1023 mb 0 mm/h
Tomorrow 12:00 pm
weather icon
9° | 9°°C 0 mm 0% 13 mph 79 % 1022 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€92,756.24
-3.76%
Ethereum(ETH)
€2,518.10
-16.10%
Tether(USDT)
€0.98
0.15%
XRP(XRP)
€2.32
-14.72%
Solana(SOL)
€190.98
-7.19%
USDC(USDC)
€0.98
0.00%
Dogecoin(DOGE)
€0.246701
-14.10%
Shiba Inu(SHIB)
€0.000015
-14.85%
Pepe(PEPE)
€0.000010
-21.08%
Scroll to Top