ATT&CKReferencesPalo Alto MidnightEclipse APR 2024

Palo Alto MidnightEclipse APR 2024

Unit 42. (2024, April 12). Threat Brief: Operation MidnightEclipse, Post-Exploitation Activity Related to CVE-2024-3400 . Retrieved January 15, 2025.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns1

Procedure examples10

TechniqueUsed byProcedure example
T1027.013
Encrypted/Encoded File
MalwareUPSTYLE

UPSTYLE stores primary content as base64-encoded objects.

T1053.003
Cron
CampaignOperation MidnightEclipse

During Operation MidnightEclipse, threat actors configured cron jobs to retrieve payloads from actor-controlled infrastructure.

T1057
Process Discovery
MalwareUPSTYLE

UPSTYLE has the ability to read `/proc/self/cmdline` to see if it is running as a monitored process.

T1059.004
Unix Shell
CampaignOperation MidnightEclipse

During Operation MidnightEclipse, threat actors piped output from stdout to bash for execution.

T1059.006
Python
MalwareUPSTYLE

UPSTYLE is a Python-based application.

T1071.001
Web Protocols
CampaignOperation MidnightEclipse

During Operation MidnightEclipse, threat actors used `wget` via HTTP to retrieve payloads.

T1074.001
Local Data Staging
CampaignOperation MidnightEclipse

During Operation MidnightEclipse, threat actors copied files to the web application folder on compromised devices for exfiltration.

T1105
Ingress Tool Transfer
CampaignOperation MidnightEclipse

During Operation MidnightEclipse, threat actors downloaded additional payloads on compromised devices.

T1140
Deobfuscate/Decode Files or Information
MalwareUPSTYLE

UPSTYLE encodes its main content prior to loading via Python as base64-encoded blobs.

T1190
Exploit Public-Facing Application
CampaignOperation MidnightEclipse

During Operation MidnightEclipse, threat actors exploited CVE-2024-3400 in Palo Alto Networks GlobalProtect.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.