Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
actively-exploited-vulnerabilityperimeter-device-exposureembedded-device-vulnerabilityrapid-weaponization

Attackers chained PAN-OS flaws to seize Palo Alto firewalls and deploy malware

Updated 29d agoFirst seen May 25, 20264 sources

Threat actors exploited internet-exposed Palo Alto Networks PAN-OS management interfaces by chaining CVE-2024-0012 and CVE-2024-9474, a combination that enabled authentication bypass followed by privilege escalation to run arbitrary commands as root on affected firewall devices. Security reporting described a surge in exploitation after public disclosure, with campaigns targeting exposed firewalls and quickly moving from initial access to hands-on post-compromise activity.

Investigators observed attackers validating exploitation with OAST domains, retrieving payloads with tools such as curl and wget, and establishing Sliver command-and-control. Follow-on activity included downloads of ELF, shell script, and PHP payloads, persistence through cron jobs and web shells, suspicious TLS traffic without SNI, use of uncommon ports, reconnaissance, lateral movement, and cryptomining tied to infrastructure including herominers and xmrig. One repeatedly downloaded payload, /palofd from 38.180.147[.]18 with SHA1 90f6890fa94b25fbf4d5c49f1ea354a023e06510, was linked by open-source reporting to Spectre RAT, indicating that compromised perimeter devices were being used for broader intrusion activity rather than simple opportunistic exploitation.

Share:
Attackers chained PAN-OS flaws to seize Palo Alto firewalls and deploy malware
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

7 events from the most recent confirmed update back to the earliest known activity.

7 EVENTS
Sep 23, 20259mo ago

Public exploit repository appears for CVE-2025-0133

A GitHub repository titled for CVE-2025-0133 was published, indicating public exploit-related material had become available for that vulnerability.

Dec 9, 20242y ago

Darktrace publishes retrospective on Operation Lunar Peek activity

Darktrace released its analysis of Operation Lunar Peek, summarizing the late-November 2024 exploitation wave against Palo Alto firewalls and the broader post-exploitation behaviors it observed.

Nov 22, 20242y ago

Arctic Wolf reports a threat campaign targeting Palo Alto firewall devices

Arctic Wolf published a report describing a threat campaign targeting Palo Alto Networks firewall devices, corroborating active exploitation activity around the PAN-OS issue set.

Attackers deploy payloads, Sliver C2, and cryptomining after PAN-OS compromise

Post-compromise activity included exploit validation via OAST domains, payload retrieval with curl and Wget, Sliver command-and-control traffic, downloads of ELF, shell script, and PHP payloads, and in some cases reconnaissance, lateral movement, persistence, and cryptomining. One repeatedly downloaded payload, /palofd from 38.180.147[.]18, was associated by OSINT sources with Spectre RAT.

Threat actors begin exploiting exposed Palo Alto firewalls at scale

In late November 2024, Darktrace observed a spike in exploitation and post-exploitation activity targeting internet-exposed Palo Alto PAN-OS firewall devices following disclosure of CVE-2024-0012 and CVE-2024-9474.

Palo Alto PAN-OS flaws CVE-2024-0012 and CVE-2024-9474 are disclosed

CVE-2024-0012 and CVE-2024-9474 were publicly disclosed as PAN-OS vulnerabilities. Darktrace later described them as an authentication bypass in the management interface and a privilege escalation flaw that could be chained for root command execution on affected firewalls.

Jul 8, 20206y ago

Palo Alto discloses CVE-2020-2034 PAN-OS command injection flaw

Palo Alto Networks published a product advisory for CVE-2020-2034, an OS command injection vulnerability affecting the PAN-OS GlobalProtect portal.

The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Attackers chained PAN-OS flaws to seize Palo Alto firewalls and deploy malware | Mallory