Skip to content
The Nexus
DossierENTITY

Palo Alto Networks Unit 42

Coverage of Palo Alto Networks Unit 42 in the Nexus archive.

Earliest in view: Apr 18 · 06:01 UTCMost recent: Jul 31 · 11:21 UTC
Co-mentioned in this coverage
Recent coverage
  • SECURITYJul 31 · 11:21 UTCTHE HACKER NEWS
    Chinese Hacker Commands DeepSeek via Telegram to Launch Autonomous Attacks

    A Chinese-speaking threat actor used DeepSeek through the Hermes Agent framework to autonomously launch attacks via Telegram. The operator issued an initial instruction, after which the agent identified internet-facing systems and selected public exploits without further input.

  • SECURITYJul 1 · 07:20 UTCTHE HACKER NEWS
    Phantom Squatting Uses AI-Hallucinated Domains for Phishing and Malware

    Attackers are exploiting AI-generated fake domains by purchasing them and hosting phishing pages or malware, a tactic named 'phantom squatting' by Palo Alto Networks' Unit 42. The practice leverages domains hallucinated by large language models to direct traffic to malicious sites.

  • SECURITYJun 4 · 11:19 UTCTHE HACKER NEWS
    FlutterShell Backdoor Spreads to macOS via Malicious Google and YouTube Ads

    A macOS malvertising campaign named Operation FlutterBridge is spreading a new backdoor called FlutterShell via malicious Google and YouTube ads. The campaign is linked to a prior activity cluster dubbed JSCoreRunner (FileRipple) by cybersecurity researchers at Palo Alto Networks Unit 42.

  • SECURITYApr 18 · 06:01 UTCTHE HACKER NEWS
    Mirai Variant Nexcorium Exploits CVE-2024-3721 to Hijack TBK DVRs for DDoS Botnet

    Threat actors are exploiting CVE-2024-3721, a medium-severity command injection vulnerability in TBK DVRs and end-of-life TP-Link Wi-Fi routers, to deploy the Mirai-botnet variant Nexcorium. Fortinet FortiGuard Labs and Palo Alto Networks Unit 42 have identified this attack, which hijacks devices for DDoS botnet operations.