Palo Alto Networks Unit 42
Coverage of Palo Alto Networks Unit 42 in the Nexus archive.
- Phantom Squatting Uses AI-Hallucinated Domains for Phishing and Malware
Attackers are exploiting AI-generated fake domains by purchasing them and hosting phishing pages or malware, a tactic named 'phantom squatting' by Palo Alto Networks' Unit 42. The practice leverages domains hallucinated by large language models to direct traffic to malicious sites.
- FlutterShell Backdoor Spreads to macOS via Malicious Google and YouTube Ads
A macOS malvertising campaign named Operation FlutterBridge is spreading a new backdoor called FlutterShell via malicious Google and YouTube ads. The campaign is linked to a prior activity cluster dubbed JSCoreRunner (FileRipple) by cybersecurity researchers at Palo Alto Networks Unit 42.
- Mirai Variant Nexcorium Exploits CVE-2024-3721 to Hijack TBK DVRs for DDoS Botnet
Threat actors are exploiting CVE-2024-3721, a medium-severity command injection vulnerability in TBK DVRs and end-of-life TP-Link Wi-Fi routers, to deploy the Mirai-botnet variant Nexcorium. Fortinet FortiGuard Labs and Palo Alto Networks Unit 42 have identified this attack, which hijacks devices for DDoS botnet operations.