UTA0218 is a China-linked threat actor tracked by Volexity and associated with targeted compromises of Palo Alto Networks PAN-OS firewalls. Its exploitation of CVE-2024-3400, an unauthenticated command-injection vulnerability in GlobalProtect, dates to March 2024 and preceded public disclosure. The exploitation campaign is known as Operation MidnightEclipse. No additional actor aliases or subgroups are established. UTA0218 exploited internet-facing firewalls to execute commands as root, establish reverse shells, retrieve additional tools, steal firewall configurations, and access internal networks. It attempted to deploy UPSTYLE, a custom Python backdoor that processes commands embedded in specially crafted network requests and conceals activity by removing command-bearing log entries and restoring modified files and timestamps. Other techniques included scheduled-task persistence through cron, GOST-based SOCKS5 and reverse TCP tunnels, and an open-source SSH reverse-shell tool. In an investigated intrusion, UTA0218 abused a firewall service account with domain-administrator privileges to move laterally through SMB and WinRM. It stole Active Directory credential data, domain and user DPAPI keys, and browser credentials and cookies from selected workstations, compromising domain credentials and enabling potential continued access through stolen authentication material. Its infrastructure included VPN-based anonymization, cloud storage, and virtual private servers. Hands-on intrusions were targeted, while vulnerability reconnaissance was broader. Independent exploitation of CVE-2024-3400 by ransomware operators does not establish a ransomware role or operational relationship for UTA0218.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
1 distinct technique observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 malware families attributed to this actor across reporting.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
35 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
China-nexus activity cluster cited as exploiting the PAN-OS GlobalProtect zero-day CVE-2024-3400.
A China-nexus activity cluster exploiting the PAN-OS GlobalProtect zero-day CVE-2024-3400; the same vulnerability was subsequently used by ransomware operators.
UTA0218 is known for exploiting the CVE-2024-3400 vulnerability in Palo Alto Networks PAN-OS firewalls as part of Operation MidnightEclipse, using the flaw to gain root privileges and facilitate lateral movement within victim networks.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.