UPSTYLE is a custom Python web shell and backdoor targeting Palo Alto Networks PAN-OS firewalls running GlobalProtect. It is associated with UTA0218 and Operation MidnightEclipse, a campaign exploiting CVE-2024-3400, an unauthenticated command-injection vulnerability, in March and April 2024. UPSTYLE was intended for post-exploitation access to compromised firewalls; installation attempts failed in documented intrusions, and successful deployment was not established in those cases.
Its installer abuses Python's path-configuration import mechanism to execute a Base64-encoded backdoor and establish persistence. The implant monitors GlobalProtect web-server error logs for specially crafted requests to nonexistent pages, extracts and decodes embedded commands, and executes them. It places command output in a legitimate, web-accessible CSS resource for retrieval by the attacker.
UPSTYLE conceals its activity by removing command-bearing log entries, restoring the modified CSS resource after approximately 15 seconds, and restoring original access and modification timestamps. Its installer also uses benign-looking naming to masquerade as an update. The associated campaign involved configuration theft, reverse shells, tunneling, and lateral movement, but those activities should not be treated as distinct built-in UPSTYLE capabilities.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Palo Alto Networks PSIRT confirmed an OS command injection issue and assigned it CVE-2024-3400. The issue is an unauthenticated remote code execution vulnerability with a CVSS base score of 10.0. | During its investigation, Volexity observed that UTA0218 attempted to install a custom Python backdoor, which Volexity calls UPSTYLE, on the firewall.
Successful exploitation allows attackers to reconfigure firewalls, exfiltrate sensitive data, or deploy persistent backdoors like the UPSTYLE malware observed in prior PAN-OS campaigns.
Successful exploitation allows attackers to reconfigure firewalls, exfiltrate sensitive data, or deploy persistent backdoors like the UPSTYLE malware observed in prior PAN-OS campaigns.
Successful exploitation allows attackers to reconfigure firewalls, exfiltrate sensitive data, or deploy persistent backdoors like the UPSTYLE malware observed in prior PAN-OS campaigns.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
rule apt_malware_py_upstyle : UTA0218 ... description = "Detect the UPSTYLE webshell."
After initial exploitation, threat actors have been observed deploying reverse shells and the UPSTYLE backdoor, as well as executing a variety of commands on the firewall, including copying and exfiltrating configuration files.
19 distinct techniques documented for this family, organized by ATT&CK tactic.
"Threat Hunting: Monitor for anomalous gNMI requests or unexpected cron job creation, indicators of UPSTYLE backdoor activity."
Tracked as CVE-2024-3400 (CVSS: 10), this is a command injection vulnerability in the GlobalProtect feature of Palo Alto Networks PAN-OS software. | After initial exploitation, threat actors have been observed deploying reverse shells and the UPSTYLE backdoor...
"Threat Hunting: Monitor for anomalous gNMI requests or unexpected cron job creation, indicators of UPSTYLE backdoor activity."
"Successful exploitation allows attackers to... deploy persistent backdoors like the UPSTYLE malware observed in prior PAN-OS campaigns."
"Threat Hunting: Monitor for anomalous gNMI requests or unexpected cron job creation, indicators of UPSTYLE backdoor activity."
The content repeatedly describes payloads, strings, configuration files, scripts, URLs, and binaries being obfuscated or encoded using Base64, XOR, RC4, AES, RSA, hex encoding, custom algorithms, and other methods across many malware families and threat actors.
The content repeatedly describes adversaries and malware deleting files, directories, droppers, scripts, logs, archives, staged data, and other artifacts from compromised systems, e.g., 'APT29 has used SDelete to remove artifacts from victim networks' and 'Lazarus Group malware has deleted files in various ways, including "suicide scripts" to delete malware binaries from the victim.'
APT28 has performed timestomping on victim files. APT29 has used timestomping to alter the Standard Information timestamps on their web shells to match other files in the same directory. APT32 has used scheduled task raw XML with a backdated timestamp... APT38 has modified data timestamps to mimic files that are in the same folder on a compromised host.
5 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A persistent backdoor malware referenced as being deployed on Palo Alto Networks PAN-OS devices after exploitation, enabling long-term unauthorized access (with noted hunting guidance including monitoring for unexpected cron job creation).
Malware that restores original timestamps after modifying files.
UPSTYLE is a custom Python-based backdoor developed specifically for exploitation of CVE-2024-3400 in Palo Alto Networks PAN-OS firewalls. It is designed to provide persistent remote access, execute commands, and exfiltrate data while evading detection by using legitimate log and CSS files for command and control and output exfiltration.
Malware that uses benign-looking filenames (e.g., update.py) to appear legitimate and evade scrutiny.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.