Fake IT support campaign delivers a malicious MSI that sideloads a trojanized DLL via a signed binary, then uses WMI to launch a custom reverse shell tunneled over a local port (localhost:9001) to an AWS API Gateway C2. Detection and indicators: https://bit.ly/4ycFn7h
Palo Alto Networks Unit 42
Computer and Network Security
SANTA CLARA, CA 101,745 followers
Unit 42 Threat Intelligence & Incident Response. Intelligence Driven. Response Ready.
About us
Palo Alto Networks Unit 42 brings together world-renowned threat researchers with an elite team of incident responders and security consultants to create an intelligence-driven, response-ready organization passionate about helping customers more proactively manage cyber risk. With a deeply rooted reputation for delivering world-class threat intelligence, Unit 42 provides industry-leading incident response and cyber risk management services to security leaders around the globe.
- Website
-
http://paloaltonetworks.com/unit42
External link for Palo Alto Networks Unit 42
- Industry
- Computer and Network Security
- Company size
- 5,001-10,000 employees
- Headquarters
- SANTA CLARA, CA
- Type
- Public Company
- Founded
- 2005
- Specialties
- Incident Response, Risk Management, Operational Threat Intelligence, and Network Security
Locations
-
Primary
Get directions
3000 Tannery Way
SANTA CLARA, CA 95054, US
Employees at Palo Alto Networks Unit 42
Updates
-
MyChart branded lures hawking free Medicare kits to phish recipients' PII and payment info. Details at: https://bit.ly/4i1EPfJ
-
-
Between January and April 2026, we uncovered a coordinated social engineering operation that targeted over 150 employees across at least 10 companies. Adversaries used external Microsoft Teams accounts to masquerade as IT support. Attackers initiated voice phishing (vishing) calls to trick targets into running remote management tools and custom malware, including obfuscated PowerShell payloads. Read our research to explore the complete attack lifecycle and defense strategies: https://bit.ly/4xv73V7
-
-
Unit 42 is actively monitoring newly created network infrastructure likely associated with Com-affiliated threat actors based on known fingerprints. MFA-themed domains are likely being used to target organizations across a variety of industries. Details: https://bit.ly/4xoZsHs
-
Attackers are using AI to move across cloud, network, endpoint, and identity environments in minutes, widening the gap between detection and decisive action. Unit 42 MDR closes that gap. Built natively into the Cortex platform, it combines real-time threat intelligence, AI-driven detection and response, and 24/7 Unit 42 expertise to deliver unified defense across your attack surface. Accelerate security operations, cut response times by up to 90%, and stop threats before they can escalate. https://bit.ly/4xCoiny
-
Our analysis of 405 AI-enabled malware samples revealed that 97% exist solely within sandbox environments and research repositories. Only 12 samples attempted execution in production environments. Defensive telemetry demonstrates that current behavioral analytics and endpoint controls effectively block these threats. The AI component alters how code is authored rather than how it executes on a host. Read our full research: https://bit.ly/4d7tdV1
-
-
Unit 42 continues to track network infrastructure that is likely associated with Com-affiliated threat actors based on known fingerprints. One of these domains (passkeyconnect[.]com) is likely being used to target organizations across a variety of industries. More details here: https://bit.ly/3Sytmd2
-
Palo Alto Networks Unit 42 reposted this
Palo Alto Networks Unit 42 is defending organizations against next-gen frontier AI risks with Anthropic’s Mythos 5. We’re combining frontier AI models with threat intelligence and security expertise to find hidden exposures, validate attack paths, and accelerate remediation before attackers act. Through an expanded agreement with Anthropic, Unit 42 Frontier AI Exposure Analysis is adding Claude Mythos 5, Anthropic’s most capable model for cybersecurity, giving organizations access to its advanced cyber capabilities. Learn more about Unit 42 Frontier AI Exposure Analysis. https://bit.ly/4wDjQTV
-
-
Identity phishing through enterprise collaboration platforms exploits the implicit trust users place in internal communication channels. Attackers frequently send direct messages containing links to adversary-in-the-middle proxy servers, harvesting enterprise credentials and multifactor authentication tokens in real time. Because these messages originate within trusted SaaS environments, target suspicion remains low. Organizations must complement robust multi-factor authentication policies with continuous session risk evaluations and employee reporting workflows. Read our full research to protect your enterprise workforce: https://bit.ly/4g9Omjs
-
-
Our analysis of Kimwolf v7 reveals how botnet operators adapt to try to evade application layer defenses. The variant targets Android TV set-top boxes and introduces HTTP/2 flood capabilities. By constructing complete Chrome browser fingerprints, the malware generates attack traffic that closely mirrors legitimate user browsing. Read our research to learn more about this evolving threat: https://bit.ly/4c5E1mn
-