2,000 Palo Alto Networks devices compromised in latest attacks

Teilen:

Attackers have compromised around 2,000 Palo Alto Networks firewalls by leveraging the two recently patched zero-days (CVE-2024-0012 and CVE-2024-9474), Shadowserver Foundation’s internet-wide scanning has revealed.

Compromised devices are predominantly located in the US and India, the nonprofit says.

Manual and automated scanning activity has been spotted

Approximately two weeks ago, Palo Alto Networks warned that attackers have been spotted leveraging a zero-day flaw to achieve remote code execution on vulnerable devices, and advised admins to make sure that access to the devices’ management interfaces was appropriately secured.

On Monday, the company confirmed that there were two zero-days under exploitation: CVE-2024-0012, which allows unauthenticated access to the interface in question, and CVE-2024-9474, which allows attackers to escalate their privileges on compromised Palo Alto Networks firewalls to root, and that attackers have been dropping webshells on them.

WatchTowr researchers followed that by publishing an analysis of how the two bugs can be used in concert and a Nuclei template that admins could leverage to check whether their devices are affected by them.

In the meantime, the attacks continued and Palo Alto thinks they may escalate.

“At this time, Unit 42 assesses with moderate to high confidence that a functional exploit chaining CVE-2024-0012 and CVE-2024-9474 is publicly available, which will enable broader threat activity,” the company’s incident responders have shared on Wednesday.

“Unit 42 has also observed both manual and automated scanning activity aligning with the timeline of third-party artifacts becoming widely available.”

Palo Alto Networks continues adding new indicators of compromise associated with these attacks.

The company has additionally revealed that the two vulnerabilities also affect its Panorama (firewall management) appliances, as well as its WildFire appliances, which are used for setting up sandbox systems to analyze suspicious files. (Those appliances are also running PAN-OS.)

Affected organizations are advised to check the security advisories for remediation guidance.

UPDATE (November 22, 2024, 02:20 p.m. ET):

“Arctic Wolf has observed multiple intrusions across a variety of industries involving Palo Alto Network firewall devices,” the company’s researchers shared today.

Based on the timing – the attacks started several hours after watchTowr published their analysis of the two vulnerabilities and explained how they can be exploited in tandem – and based on the names of some files observed in the attacks, “we assess with moderate confidence that these intrusions likely involved the exploitation of CVE-2024-0012 chained together with CVE-2024-9474 for initial access,” they said.

Following the initial compromise, in some instances the attackers tried to:

  • Download a Sliver C2 (command and Control) implant
  • Exfiltrate data (firewall configuration files, mostly, but also operating system passwd und shadow files)
  • Deploy an obfuscated PHP webshell
  • Deployment the XMRig cryptocoin miner on the compromised devices

Zeljka Zorz

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
4:32 am, Juli 2, 2025
Wetter-Symbol 19°C
L: 18° | H: 20°
broken clouds
Luftfeuchtigkeit: 81 %
Druck: 1014 mb
Wind: 6 mph NE
Windböe: 0 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 57%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 4:48 am
Sonnenuntergang: 9:20 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 10:00 pm
Wetter-Symbol
18° | 20°°C 0.26 mm 26% 11 mph 81 % 1023 mb 0 mm/h
Tomorrow 10:00 pm
Wetter-Symbol
14° | 26°°C 0 mm 0% 12 mph 54 % 1028 mb 0 mm/h
Fr. Juli 04 10:00 pm
Wetter-Symbol
15° | 26°°C 0 mm 0% 12 mph 61 % 1028 mb 0 mm/h
Sa. Juli 05 10:00 pm
Wetter-Symbol
16° | 21°°C 1 mm 100% 13 mph 95 % 1022 mb 0 mm/h
So. Juli 06 10:00 pm
Wetter-Symbol
14° | 17°°C 1 mm 100% 12 mph 91 % 1009 mb 0 mm/h
Today 7:00 am
Wetter-Symbol
18° | 19°°C 0 mm 0% 8 mph 81 % 1014 mb 0 mm/h
Today 10:00 am
Wetter-Symbol
21° | 21°°C 0 mm 0% 6 mph 76 % 1016 mb 0 mm/h
Today 1:00 pm
Wetter-Symbol
19° | 19°°C 0.2 mm 20% 7 mph 71 % 1017 mb 0 mm/h
Today 4:00 pm
Wetter-Symbol
21° | 21°°C 0.26 mm 26% 8 mph 45 % 1019 mb 0 mm/h
Today 7:00 pm
Wetter-Symbol
24° | 24°°C 0 mm 0% 11 mph 32 % 1020 mb 0 mm/h
Today 10:00 pm
Wetter-Symbol
18° | 18°°C 0 mm 0% 11 mph 35 % 1023 mb 0 mm/h
Tomorrow 1:00 am
Wetter-Symbol
15° | 15°°C 0 mm 0% 7 mph 39 % 1025 mb 0 mm/h
Tomorrow 4:00 am
Wetter-Symbol
14° | 14°°C 0 mm 0% 4 mph 52 % 1026 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€89,872.65
-1.04%
Ethereum(ETH)
€2,056.43
-2.40%
Fesseln(USDT)
€0.85
-0.02%
XRP(XRP)
€1.85
-2.36%
Solana(SOL)
€126.13
-3.09%
USDC(USDC)
€0.85
0.00%
Dogecoin(DOGE)
€0.134885
-3.37%
Shiba Inu(SHIB)
€0.000009
-1.06%
Pepe(PEPE)
€0.000008
-3.50%
Nach oben scrollen