The latest research and news from Unit 42, the Palo Alto Networks (@paloaltontwks) Threat Intelligence and Security Consulting Team covering incident response.
We identified a coordinated campaign of 10 browser #extensions disguised as browser games. On installation, extension names resolve through fragmented translation keys and runtime #impersonates crypto wallets with a remote kill switch. Details at bit.ly/3VzIV5o
ALT A code snippet is shown with comments and JavaScript functions. It includes logic for handling game maintenance and loading processes.
ALT A screenshot of code with annotations. Annotations highlight a dynamically loaded extension name, changing the open window name to impersonate TronLink, allowing embedded iframes, and allowing scripts and WebAssembly execution.
We examined how AWS secures exposed credentials through managed policies. We tracked policy updates against new cloud threats, tested the GitHub secret scanning integration, and outlined practical logging strategies to detect quarantine events: bit.ly/4yQVjfD
Unit 42 continues to track network infrastructure that is likely associated with Com-affiliated threat actors. Two of these domains are likely being used to target organizations operating across a wide array of industries. Details at bit.ly/3THZQCi
Unit 42 continues to track network infrastructure likely associated with Com-affiliated threat actors. One of these domains (my-passkeys[.]com) is likely being used to target organizations operating with the healthcare and pharmaceutical sectors. Details: bit.ly/4yUh667
In testing AWS AgentCore Harness default configurations, we found prompt injection can leverage the shell tool to access plaintext credentials in process memory. Operators can mitigate these risks by restricting default tools and enforcing least privilege: bit.ly/4h7sGVK
We found an active indirect prompt injection campaign targeting AI ad review systems. 10 domains, one of which was ranked #1 in web search results, embed hidden payloads impersonating a popular advertiser compliance to bypass ad review. Details at bit.ly/46K6vij
ALT Screenshot of a webpage for "AccountEase," featuring a headline that reads "Effortless Accounting Solutions."
ALT Code snippet displaying HTML and CSS styles with a comment for an LLM to ignore previous instructions.
ALT Screenshot of homepage for "Exec Coach Pro" website.
ALT Screenshot of a Google search results page for "strategic economic awareness courses." The top result is circled in red. It appears as the #1 ranking search result.
🚨 Armed with AI, threat actors now weaponize vulnerabilities in minutes. Human-speed defense can’t keep up.
Meet @Unit42_Intel Continuous Frontier AI Defense: leading frontierAI models + elite security experts to find, validate, and fix exposures.
Giving the advantage back to defenders.
bit.ly/4rvQWo8
Identifying functional cloud roles is difficult when attackers obscure identity behavior. We mapped 40,000 identities across 125 environments with unsupervised machine learning algorithms to deliver continuous visibility in standard SQL: bit.ly/4xv5YvD
We documented P2PInfect in 2023 spreading via a Lua sandbox escape. In Mar–Aug 2026, our honeypots saw 692 attacking IPs and 363 C2s push the same worm via Redis misconfig: SLAVEOF to a rogue master, and RDB writes planting a crontab entry and an SSH key: bit.ly/3VDGdvC
ALT This image is a screenshot of technical log entries related to "P2PInfect Malware Delivery Using Both a SLAVEOF to a Rogue Master and RDB Writes That Plant a Crontab Entry." It details command execution, module loading, and related connections.
ALT Three line graphs showing the number of new attacking IPs per month for a Redis campaign, categorized by different vectors.
ALT The image is a detailed spreadsheet titled "Redis Module Implants.
A sustained ClickFix campaign has compromised 350+ websites on a leading CMS platform since August. The attack abuses a free CDN, hosting and rotating malicious payloads across public repos. Details at bit.ly/4rCmBEt
ALT An image illustrating a cyberattack process. The top section shows an "Obfuscated Clipboard Payload" code snippet. Below, a step labeled "Stage-2 WebDAV dropper" includes commands for creating a WebDAV connection and executing a payload. On the right, CAPTCHA elements are depicted: a "I'm not a robot" checkbox and a "Continue to Verification Steps" page.
A compromised regional news outlet’s WordPress site is using malicious JS to serve #ClickFix prompts, ultimately delivering a ConfuserEx-encrypted #StealC payload. One observed infection chain routed a targeted user via a local library's proxy. Details at: bit.ly/4ran9B3
ALT The image shows a computer screen displaying a browser with an active popup verification step. In the background, a banner advertises the Lenexa Spinach Festival.
ALT Diagram showing a process tree for "SearchIndexer.exe" with powershell.exe, chrome.exe, and msedge.exe. Arrows indicate payload injections into Chrome and Edge processes for credential theft. The left panel displays process details such as path, PID, MD5, and running time.
ALT Diagram of a cyber-attack process. The sequence starts with a compromised site, leading to JavaScript injection and cookie stealing. The process includes a fake ClickFix overlay display.
Attackers with root access on a compromised Kubernetes node can manipulate control group metadata to bypass SPIFFE and SPIRE open standard workload identity controls. This prompts systems to issue credentials for co-located app: bit.ly/4iVSIMO
NeuralOverride is a Cyrillic Python RAT using Telegram for C2 and integrating the #OpenRouter LLM for autonomous attack planning. It includes #SCADA tasking stubs referencing a missing scada_commander.py module. The 5-build family evolved over one month: bit.ly/4j5xRXs
ALT A computer screen displays the code for BEURALE, a neural override and auto dependency manager.
ALT Code editor displaying Python script for initializing and configuring a local AI model.
ALT A screenshot of a security analysis report from VirusTotal. The report flags a Python file named "neural_override_v12.py" as malicious, with a community score of 9 out of 57.
ALT Screenshot of a malware analysis report from VirusTotal. The community score is 0/61, indicating no detection of security threats. The screen shows details like file hash, size, and last analysis date.
ZionSiphon v4 is a #Rust rewrite of the OT (ICS) sabotage tool targeting Israeli water and #desalination systems. Adds USB propagation and Modbus write attempts. Details at bit.ly/4hucnlP
ALT Screenshot of assembly code with syntax highlighting.
ALT Code snippet displaying hexadecimal values and configuration parameters for a process involving chlorine control and reverse osmosis purifiers.
ALT Screenshot of a code analysis tool showing disassembled code with references to fictional file paths with some redactions. Data types and subroutines are visible, and some text is highlighted in green.
ALT The image shows a portion of assembly code with hexadecimal memory addresses on the left. The color coding highlights syntax elements.
We tracked a cybercrime pay per install network reaching enterprise endpoints by targeting young gamers on YouTube and corporate users via SEO poisoning. A single custom loader deployed multiple malware strains across networks: bit.ly/4r6F7Ew
We continue to actively track newly created infrastructure likely associated with Com-affiliated threat actors that are used as part of their data theft and extortion campaigns. We've identified 17 FQDNs since our last post on Aug. 28th. Details on GitHub: bit.ly/4d3JdYc
We saw attackers using commercial AI tools, targeting systems in transportation and financial sectors in Latin America. They used self-hosted NextChat to fix collection errors, and exposed their AI-generated scripts. Read our analysis for details: bit.ly/4xI8XS6
We investigated a breach where autonomous AI agents executed an intrusion in under 10 hours, compressing weeks of tradecraft. The actor mapped networks, seized root credentials and left an AI-generated report. Explore our full investigation: bit.ly/4iKWXe2