Unit 42. (2024, April 12). Threat Brief: Operation MidnightEclipse, Post-Exploitation Activity Related to CVE-2024-3400 . Retrieved January 15, 2025.
Not cited by any technique.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1027.013 Encrypted/Encoded File |
MalwareUPSTYLE | UPSTYLE stores primary content as base64-encoded objects. |
| T1053.003 Cron |
CampaignOperation MidnightEclipse | During Operation MidnightEclipse, threat actors configured cron jobs to retrieve payloads from actor-controlled infrastructure. |
| T1057 Process Discovery |
MalwareUPSTYLE | UPSTYLE has the ability to read `/proc/self/cmdline` to see if it is running as a monitored process. |
| T1059.004 Unix Shell |
CampaignOperation MidnightEclipse | During Operation MidnightEclipse, threat actors piped output from stdout to bash for execution. |
| T1059.006 Python |
MalwareUPSTYLE | UPSTYLE is a Python-based application. |
| T1071.001 Web Protocols |
CampaignOperation MidnightEclipse | During Operation MidnightEclipse, threat actors used `wget` via HTTP to retrieve payloads. |
| T1074.001 Local Data Staging |
CampaignOperation MidnightEclipse | During Operation MidnightEclipse, threat actors copied files to the web application folder on compromised devices for exfiltration. |
| T1105 Ingress Tool Transfer |
CampaignOperation MidnightEclipse | During Operation MidnightEclipse, threat actors downloaded additional payloads on compromised devices. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareUPSTYLE | UPSTYLE encodes its main content prior to loading via Python as base64-encoded blobs. |
| T1190 Exploit Public-Facing Application |
CampaignOperation MidnightEclipse | During Operation MidnightEclipse, threat actors exploited CVE-2024-3400 in Palo Alto Networks GlobalProtect. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.