ATT&CKCampaignsOperation MidnightEclipse

Operation MidnightEclipse

C0048

Campaign, Mar 2024 to Apr 2024.View on attack.mitre.org

About this campaign

Operation MidnightEclipse was a campaign conducted in March and April 2024 that involved initial exploit of zero-day vulnerability CVE-2024-3400, a critical command injection vulnerability in the GlobalProtect feature of Palo Alto Networks PAN-OS.

Techniques used17

Procedure examples17

TechniqueProcedure example
T1003.003
NTDS

During Operation MidnightEclipse, threat actors obtained active directory credentials via the NTDS.DIT file.

T1005
Data from Local System

During Operation MidnightEclipse, threat actors stole saved cookies and login data from targeted systems.

T1021.002
SMB/Windows Admin Shares

During Operation MidnightEclipse, threat actors used SMB to pivot internally in victim networks.

T1021.006
Windows Remote Management

During Operation MidnightEclipse, threat actors used WinRM to move laterally in targeted networks.

T1053.003
Cron

During Operation MidnightEclipse, threat actors configured cron jobs to retrieve payloads from actor-controlled infrastructure.

T1059.004
Unix Shell

During Operation MidnightEclipse, threat actors piped output from stdout to bash for execution.

T1071.001
Web Protocols

During Operation MidnightEclipse, threat actors used `wget` via HTTP to retrieve payloads.

T1074.001
Local Data Staging

During Operation MidnightEclipse, threat actors copied files to the web application folder on compromised devices for exfiltration.

T1078
Valid Accounts

During Operation MidnightEclipse, threat actors extracted sensitive credentials while moving laterally through compromised networks.

T1078.002
Domain Accounts

During Operation MidnightEclipse, threat actors used a compromised domain admin account to move laterally.

T1090
Proxy

During Operation MidnightEclipse, threat actors used the GO Simple Tunnel reverse proxy tool.

T1105
Ingress Tool Transfer

During Operation MidnightEclipse, threat actors downloaded additional payloads on compromised devices.

T1190
Exploit Public-Facing Application

During Operation MidnightEclipse, threat actors exploited CVE-2024-3400 in Palo Alto Networks GlobalProtect.

T1559
Inter-Process Communication

During Operation MidnightEclipse, threat actors wrote output to stdout then piped it to bash for execution.

T1584.003
Virtual Private Server

During Operation MidnightEclipse, threat actors abused Virtual Private Servers to store malicious files.

View all 17 procedure examples

Attributed groups0

MITRE does not attribute this campaign to a group.

Software1

References2

  1. Palo Alto MidnightEclipse APR 2024 Open source
    Unit 42. (2024, April 12). Threat Brief: Operation MidnightEclipse, Post-Exploitation Activity Related to CVE-2024-3400 . Retrieved January 15, 2025.
  2. Volexity UPSTYLE 2024 Open source
    Volexity Threat Research. (2024, April 12). Zero-Day Exploitation of Unauthenticated Remote Code Execution Vulnerability in GlobalProtect (CVE-2024-3400). Retrieved November 20, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.