Unit 42 is the threat intelligence and incident response organization of Palo Alto Networks. It is a commercial cybersecurity research team rather than a threat actor. Unit 42 is widely known for malware analysis, intrusion investigation, vulnerability research, and reporting on cybercrime and state-linked activity. Its work includes evaluating emerging attack techniques and defensive weaknesses, including research into AI security and jailbreak resistance in major language-model platforms. Because Unit 42 is a defender and research organization, not an adversary, threat-actor attributes such as operational motivation, offensive capabilities, ransomware tactics, source country, and victim targeting are not applicable on the available facts.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
21 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
5 malware families attributed to this actor across reporting.
1 indicator attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.