Skip to content
.ca
sign in

Threat intelligence from Palo Alto Networks

42 reports on cyfar.ca summarizing Palo Alto Networks research. Visit Palo Alto Networks

Palo Alto Networks3 days ago11 minLLM reporthigh

Token Jacking: Cybercriminals Could Be Stealing Your AI Resources

Unit 42 reports a growing trend of 'token jacking' where cybercriminals steal AI API keys from developers via info stealers, phishing, exposed repositories, and poisoned npm packages. These stolen tokens are used to fuel gray-market 'transfer station' proxy services that resell AI computing access at discounted rates, generating tens of millions of API calls per day and causing catastrophic financial losses for victim organizations. The attack exploits the default limitless scaling and cyclical billing model of AI API providers, meaning victims may not discover the theft until massive charges have accrued.

Palo Alto Networks5 days ago13 minLLM reporthigh

Almost Half of Malware Samples Communicate Direct to IP

Unit 42 analysis of 4 million dynamic analysis reports reveals that 45.32% of malware samples with C2 activity communicate directly to hard-coded IP addresses without DNS resolution, rendering DNS-based security controls ineffective. The article introduces ZT-IP (Zero Trust IP), a network-level enforcement approach that blocks outbound connections to IPs not previously sanctioned by a DNS response. Multiple active threats are documented including Phorpiex ransomware droppers, a custom \GET exfiltration campaign, SectopRAT credential harvesting, and Mozi/Boatnet IoT botnets — all leveraging D2IP communication to evade detection.

Palo Alto Networks5 days ago10 minLLM reporthigh

Pass the Passkey: A Novel Attack Surface in Passwordless Authentication

Unit 42 discloses three novel attack classes against Google's synced passkey ecosystem on Windows TPM devices, collectively nicknamed 'Pass-ta-key.' All three require pre-existing unprivileged malware on the victim's endpoint. The Pass-ta-key attack silently signs cloud authenticator requests using the extracted TPM-backed device identity key. The Silver Pass-ta-key attack exploits Chrome's deferred UV key onboarding to register an attacker-controlled verification key, enabling persistent remote access without the victim's device. The Golden Pass-ta-key attack extracts the Security Domain Secret from Chrome's process memory during forced re-onboarding, enabling decryption of all synced passkeys. Key gaps include lack of UV flag validation by relying parties, absence of attestation verification for newly registered UV keys, and exposure of the SDS to the client environment.

Palo Alto Networks9 days ago10 minLLM reporthigh

The Xcode Assassin Returns: A Deep Dive Into the Latest XCSSET Version

XCSSET v40 is a modular macOS malware targeting software developers through infected Xcode projects. It features advanced stealth techniques including fileless persistence via the macOS defaults system, multi-layered polymorphism, and active impairment of macOS security mechanisms like XProtect and TCC. New operational modules include a Chrome DevTools Protocol (CDP) hijacker for browser manipulation and a Telegram trojanizer for persistent access.

Palo Alto Networks10 days ago13 minLLM reporthigh

Chinese-Speaking Threat Actor Harnesses AI Models for Autonomous Cyberattacks

Unit 42 documented an autonomous AI-enabled cyberattack campaign in which a Chinese-speaking threat actor used DeepSeek (via the Hermes Agent framework) as an autonomous offensive operator, orchestrated through Telegram, to independently perform reconnaissance via FOFA, source public exploit PoCs from GitHub, and attempt exploitation across seven CVEs affecting Langflow, n8n, Citrix NetScaler, Apache Tomcat, Marimo Notebook, PAN-OS, and Windows IKE VPN extensions. The actor also evaluated Western AI tools (Claude Code, Codex) in a limited testing capacity routed through an anti-attribution proxy, but relied on DeepSeek due to its lack of provider-side safety restrictions; while most autonomous exploitation attempts failed due to target-side configuration barriers, manual campaigns achieved confirmed data exfiltration from Citrix NetScaler targets, and the AI agent's own actions inadvertently exposed the entire operational infrastructure.

Palo Alto Networks17 days ago9 minLLM reporthigh

Russian Global Webmail Espionage

Unit 42 details CL-STA-1114, a Russian-nexus cyberespionage campaign overlapping with Void Blizzard/LAUNDRY BEAR, exploiting CVE-2025-66376 in Zimbra webmail through zero-click phishing emails containing obfuscated HTML/SVG that decodes and executes a Base64-encoded JavaScript payload in the victim's browser. The payload exfiltrates CSRF tokens, credentials, 2FA scratch codes, and up to 90 days of email/search history to hardcoded C2 servers, with at least nine IPs and nine domains identified as rotating infrastructure averaging 35.4 days of activity.

Palo Alto Networks23 days ago10 minLLM reportcritical

Three Steps to the Terminal: A Siemens ROX II Zero-Day Trilogy

A chained exploit comprising three zero-day vulnerabilities in Siemens ROX II OT switches allows an attacker to escalate from arbitrary file disclosure to full persistent root-level access. CVE-2025-40948 leverages a root-privileged xz utility to read any file on the filesystem, CVE-2025-40947 exploits unsanitized input in the feature key signature verification to achieve command injection as root, and CVE-2025-40949 enables persistent code execution by injecting commands into the root cron table via the web management task scheduler. Siemens has released firmware V2.17.1 to address all three vulnerabilities.

Palo Alto Networks25 days ago16 minLLM reporthigh

TuxBot v3: Inside an IoT Botnet Framework With LLM-Assisted Development

Unit 42 identified TuxBot v3 Evolution, a modular multi-architecture IoT botnet framework whose developer relied heavily on an LLM to generate C bot and Go C2 server code. The LLM-assisted development introduced reproducible bugs (an XOR key mismatch, an exploit VM file-magic mismatch, and a hallucinated Argon2id implementation that silently uses PBKDF2) that break several fallback C2 channels and exploit delivery mechanisms, while core scanning, encrypted C2, persistence, and DDoS capabilities remain functional. Infrastructure pivoting links TuxBot's dropper and C2 servers to the broader Keksec/Kaitori and AISURU botnet ecosystems, and researchers assess a fixed, fully operational variant is a likely near-term threat.

Palo Alto Networksabout 1 month ago17 minLLM reporthigh

Vidar Stealer Unmasked: Code Signing Abuse, Go Loaders and File Inflation

A financially motivated campaign active in April 2026 delivers Vidar stealer and XMRig cryptocurrency miner to victims worldwide via malvertising for fake software cracks. The campaign uses the Factory-v3 Go loader framework with per-build unique binaries, fabricated Authenticode certificates impersonating legitimate brands, file-size inflation up to 491 MB to evade sandbox analysis, and an in-memory AMSI bypass. Vidar exfiltrates browser credentials, cookies, and crypto wallets to C2 servers, while XMRig mines Monero using the pool.supportxmr.com mining pool. The operator receives Telegram notifications for each new infection.

Palo Alto Networksabout 1 month ago13 minLLM reporthigh

CL-STA-1062 Targets Southeast Asian Governments and Critical Infrastructure

CL-STA-1062, a Chinese-speaking threat cluster assessed to be the same as UAT-7237, has compromised Southeast Asian government and critical energy infrastructure entities throughout 2025 using web shell deployment, MSSQL data exfiltration, and open-source tunneling tools (SoftEther VPN, VNT, yuze). The group has introduced TinyRCT, a previously undocumented .NET backdoor delivered via AppDomainManager Injection (malicious chrome_setup.zip), which uses AES-CBC encrypted HTTP C2, sandbox-evasion path checks, scheduled-task persistence disguised as legitimate updater services, and a self-destruct routine using choice.exe for anti-forensic file deletion.

Palo Alto Networksabout 1 month ago13 minLLM reporthigh

Phantom Squatting: AI-Hallucinated Domains as a Software Supply Chain Vector

Unit 42 researchers identified 'phantom squatting,' a novel supply chain attack vector where adversaries register web domains that LLMs consistently hallucinate for legitimate brands. By proactively mapping LLM hallucination patterns across 913 brands and 2.1 million generated URLs, researchers identified 13,229 confirmed malicious URLs and ~250,000 unregistered phantom domains. Real-world cases — including the Montana Empire phishing kit built with an AI coding assistant — demonstrate that adversaries independently converge on the same hallucinated domains, with detection lead times of 18–51 days. The threat exploits a structural, unpatchable property of LLM architectures and bypasses reputation-based defenses through zero-reputation newly registered domains.

Palo Alto Networksabout 2 months ago6 minLLM reporthigh

OpenClaw’s Skill Marketplace and the Emerging AI Supply Chain Threat

Threat actors are exploiting the OpenClaw AI agent ecosystem by publishing malicious skills on the ClawHub marketplace. These skills leverage semantic instruction hijacking to bypass traditional security controls, delivering macOS infostealers via base64-encoded droppers, utilizing massive file padding for defense evasion, and executing novel agentic financial fraud schemes like runtime affiliate injection and front-running.

Palo Alto Networksabout 2 months ago5 minLLM reporthigh

The Global Namespace Risk: Universal Bucket Hijacking Technique for Cloud Data Exfiltration

Researchers identified a universal bucket hijacking technique affecting major cloud providers (AWS, GCP, Azure) that allows attackers to silently exfiltrate data streams. By exploiting the global uniqueness of bucket names, an attacker with deletion privileges can delete a target bucket and recreate it in their own environment, seamlessly rerouting logs, backups, and messages without requiring granular configuration update permissions.

Palo Alto Networksabout 2 months ago5 minLLM reportcritical

Pickle in the Middle – Hijacking Vertex AI Model Uploads for Cross-Tenant RCE

A critical vulnerability in the Google Cloud Vertex AI SDK for Python allows attackers to achieve cross-tenant Remote Code Execution (RCE) via bucket squatting. By predicting default staging bucket names and exploiting a lack of ownership verification, attackers can intercept model uploads and inject malicious pickle payloads, leading to the theft of highly privileged service account tokens.

Palo Alto Networksabout 2 months ago5 minLLM reporthigh

Trust No Skill: Integrity Verification for AI Agent Supply Chains

The article introduces Behavioral Integrity Verification (BIV) to audit third-party skills for AI agents by comparing declared metadata against actual executable code and natural-language instructions. Analysis of the OpenClaw registry found that while most deviations are benign documentation errors, a critical 5% of skills contain multi-stage attack chains such as silent credential exfiltration and instruction-override hijacking.

Palo Alto Networks2 months ago5 minLLM reporthigh

Blinding the Watchmen: Abusing Cloud Logging Services for Defense Evasion and Visibility

Threat actors are increasingly targeting cloud logging services like AWS CloudTrail and Google Cloud Logging to evade detection and maintain persistence. By manipulating log routing, deleting storage destinations, or impairing encryption keys, attackers can blind security operations and operate undetected. Furthermore, attackers can redirect log flows to attacker-controlled infrastructure to gain continuous visibility into the victim's cloud environment.

Palo Alto Networks2 months ago7 minLLM reporthigh

Operation FlutterBridge: macOS Malvertising Campaign Spreads New FlutterShell Backdoor

Operation FlutterBridge is a widespread macOS malvertising campaign operated by the CL-CRI-1089 threat cluster, delivering a novel Flutter-based backdoor dubbed FlutterShell. The malware utilizes a dynamic WebView-based JavaScript-to-native bridge to execute arbitrary commands, hijack Google Chrome for adware revenue, and exfiltrate data, all while masquerading as legitimate, Apple-notarized applications.

Palo Alto Networks2 months ago5 minLLM reporthigh

2026 World Cup: Discussing The World’s Biggest Game’s Attack Surface

The 2026 FIFA World Cup presents a massive, multi-jurisdictional attack surface threatened by state-nexus disruptive operations and financially motivated cybercrime. Key risks include Iran-aligned actors targeting municipal OT infrastructure, pro-Russian hacktivists launching high-volume DDoS attacks against tournament services, and cybercriminals deploying ransomware against the hospitality supply chain.

Palo Alto Networks3 months ago7 minLLM reporthigh

Tracking Iranian APT Screening Serpens’ 2026 Espionage Campaigns

Unit 42 identified an active cyberespionage campaign by the Iran-nexus APT group Screening Serpens, targeting entities in the U.S., Israel, and the Middle East. The threat actor deployed two new RAT families, MiniUpdate and MiniJunk V2, utilizing advanced AppDomainManager hijacking and DLL sideloading to evade native .NET security mechanisms like ETW. The attacks rely on highly tailored social engineering lures, such as fake job portals and video conferencing updates, to initiate the infection chain and establish persistent command and control.

Palo Alto Networks3 months ago5 minLLM reporthigh

Paved With Intent: ROADtools and Nation-State Tactics in the Cloud

ROADtools is an open-source Python framework designed for Entra ID exploration that has been co-opted by nation-state threat actors like APT29 and APT33. Attackers leverage its modules to conduct extensive directory reconnaissance, register rogue devices for persistence, and manipulate OAuth tokens to bypass interactive authentication controls such as MFA. Detection relies on identifying anomalous Microsoft Graph API queries, unusual user-agent strings, and default device registration artifacts.