Campaign, Mar 2024 to Apr 2024.View on attack.mitre.org
Operation MidnightEclipse was a campaign conducted in March and April 2024 that involved initial exploit of zero-day vulnerability CVE-2024-3400, a critical command injection vulnerability in the GlobalProtect feature of Palo Alto Networks PAN-OS.
| Technique | Procedure example |
|---|---|
| T1003.003 NTDS |
During Operation MidnightEclipse, threat actors obtained active directory credentials via the NTDS.DIT file. |
| T1005 Data from Local System |
During Operation MidnightEclipse, threat actors stole saved cookies and login data from targeted systems. |
| T1021.002 SMB/Windows Admin Shares |
During Operation MidnightEclipse, threat actors used SMB to pivot internally in victim networks. |
| T1021.006 Windows Remote Management |
During Operation MidnightEclipse, threat actors used WinRM to move laterally in targeted networks. |
| T1053.003 Cron |
During Operation MidnightEclipse, threat actors configured cron jobs to retrieve payloads from actor-controlled infrastructure. |
| T1059.004 Unix Shell |
During Operation MidnightEclipse, threat actors piped output from stdout to bash for execution. |
| T1071.001 Web Protocols |
During Operation MidnightEclipse, threat actors used `wget` via HTTP to retrieve payloads. |
| T1074.001 Local Data Staging |
During Operation MidnightEclipse, threat actors copied files to the web application folder on compromised devices for exfiltration. |
| T1078 Valid Accounts |
During Operation MidnightEclipse, threat actors extracted sensitive credentials while moving laterally through compromised networks. |
| T1078.002 Domain Accounts |
During Operation MidnightEclipse, threat actors used a compromised domain admin account to move laterally. |
| T1090 Proxy |
During Operation MidnightEclipse, threat actors used the GO Simple Tunnel reverse proxy tool. |
| T1105 Ingress Tool Transfer |
During Operation MidnightEclipse, threat actors downloaded additional payloads on compromised devices. |
| T1190 Exploit Public-Facing Application |
During Operation MidnightEclipse, threat actors exploited CVE-2024-3400 in Palo Alto Networks GlobalProtect. |
| T1559 Inter-Process Communication |
During Operation MidnightEclipse, threat actors wrote output to stdout then piped it to bash for execution. |
| T1584.003 Virtual Private Server |
During Operation MidnightEclipse, threat actors abused Virtual Private Servers to store malicious files. |
MITRE does not attribute this campaign to a group.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.