Threat actors exploited internet-exposed Palo Alto Networks PAN-OS management interfaces by chaining CVE-2024-0012 and CVE-2024-9474, a combination that enabled authentication bypass followed by privilege escalation to run arbitrary commands as root on affected firewall devices. Security reporting described a surge in exploitation after public disclosure, with campaigns targeting exposed firewalls and quickly moving from initial access to hands-on post-compromise activity.
Investigators observed attackers validating exploitation with OAST domains, retrieving payloads with tools such as curl and wget, and establishing Sliver command-and-control. Follow-on activity included downloads of ELF, shell script, and PHP payloads, persistence through cron jobs and web shells, suspicious TLS traffic without SNI, use of uncommon ports, reconnaissance, lateral movement, and cryptomining tied to infrastructure including herominers and xmrig. One repeatedly downloaded payload, /palofd from 38.180.147[.]18 with SHA1 90f6890fa94b25fbf4d5c49f1ea354a023e06510, was linked by open-source reporting to Spectre RAT, indicating that compromised perimeter devices were being used for broader intrusion activity rather than simple opportunistic exploitation.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
7 events from the most recent confirmed update back to the earliest known activity.
A GitHub repository titled for CVE-2025-0133 was published, indicating public exploit-related material had become available for that vulnerability.
Darktrace released its analysis of Operation Lunar Peek, summarizing the late-November 2024 exploitation wave against Palo Alto firewalls and the broader post-exploitation behaviors it observed.
Arctic Wolf published a report describing a threat campaign targeting Palo Alto Networks firewall devices, corroborating active exploitation activity around the PAN-OS issue set.
Post-compromise activity included exploit validation via OAST domains, payload retrieval with curl and Wget, Sliver command-and-control traffic, downloads of ELF, shell script, and PHP payloads, and in some cases reconnaissance, lateral movement, persistence, and cryptomining. One repeatedly downloaded payload, /palofd from 38.180.147[.]18, was associated by OSINT sources with Spectre RAT.
In late November 2024, Darktrace observed a spike in exploitation and post-exploitation activity targeting internet-exposed Palo Alto PAN-OS firewall devices following disclosure of CVE-2024-0012 and CVE-2024-9474.
CVE-2024-0012 and CVE-2024-9474 were publicly disclosed as PAN-OS vulnerabilities. Darktrace later described them as an authentication bypass in the management interface and a privilege escalation flaw that could be chained for root command execution on affected firewalls.
Palo Alto Networks published a product advisory for CVE-2020-2034, an OS command injection vulnerability affecting the PAN-OS GlobalProtect portal.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
darktrace.com
Open sourcegithub.com
Open sourcearcticwolf.com
Open sourcesecurity.paloaltonetworks.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.