The latest research and news from Unit 42, the Palo Alto Networks (@paloaltontwks) Threat Intelligence and Security Consulting Team covering incident response.

Joined December 2015
1,990 Photos and videos
Unit 42 is tracking the active targeting of Oracle PeopleSoft servers by Bling Libra (aka #ShinyHunters). Our analysis reveals suspected exploitation of RCE flaw CVE-2026-35273 and primary targeting of the education sector since at least late May 2026. bit.ly/4xpxKLb
12
27
3,081
We detected a #Browser-in-the-Browser phishing campaign using a draggable, OS/browser-fingerprinted popup with a spoofed OAuth URL. It evades detection by blocking debugging, fragmenting keywords, and redirecting bots. Details at bit.ly/49Md3yO
2
40
150
10,781
Unit 42 provides indicators of activity and mitigations for PAN-OS CVE-2026-0257, an authentication bypass in GlobalProtect. bit.ly/4fu1rEo
12
41
4,882
We detected an evasive #ClickFix injection with a fake Lirunex payment platform lure tricking the user into requesting the SSL certificate path through a file dialog box but silently delivers a RAT disguised as image files. Details at bit.ly/4eo0Sea
22
77
5,437
FlutterShell is a new macOS backdoor spread by malvertising. Built with Flutter, it uses a WebView-based architecture for adware, allowing attackers to remain dynamic. We discuss its evolution, variants and command structure in a recent campaign. bit.ly/43TZaLr
14
58
5,644
We are tracking Pink (CL-CRI-1147), a new Com-affiliated extortion brand whose leak site went live 5/31/26. Pink uses vishing and IT impersonation to phish credentials/MFA, then exfiltrates enterprise cloud storage and productivity data to extort victims: bit.ly/4en565G
22
68
8,957
An update to our Threat Brief on npm supply chain attacks discusses the latest compromise, pushing a payload named Miasma. The tradecraft used substantially matches Mini Shai-Hulud malware used by TeamPCP. Read now: bit.ly/4cwtCk3
13
33
4,259
An #adware campaign involving 50 Chrome extensions (disguised as live wallpapers) has hit ~30K users. Spread across three publisher accounts, the attackers are pushing remote HTML to 40 extensions and wiping IndexedDB on install and startup. Details at bit.ly/3Q05sWB
1
35
101
10,749
We detected indirect prompt injection on a fake Excel template store. Hidden via white text, the prompt uses social engineering to manipulate AI agents into boosting SEO, aiming to funnel users to a malicious Chrome extension. Details at bit.ly/3RCl2s2
3
31
127
19,176
New analysis reveals a massive network of fraudulent domains capitalizing on the 2026 FIFA World Cup, with 1k registered in the past 6 months. Tactics include redirects to shady gambling apps, data harvesting, malvertising, and PUP downloads. Details at bit.ly/4dDTiMd
6
18
3,967
#TuxBot v3 Evolution: IoT malware/C2 framework tied to AISURU/Keksec. Self-ID "Akiru." 30-plus exploit targets, 1,496 credential pairs, encrypted C2, and DGA. Developers used an LLM to port exploits and write code, leaving traces in some files. Details at bit.ly/3RAFJ7N
1
27
87
8,142
2026-05-26 (Tuesday): Another page impersonating Claude was used to push #SHubStealer when viewed on a macOS host. Details at bit.ly/4fcekmj
2
31
134
14,766
Offensive and defensive framework ROADtools is being misused by nation-state actors for cloud attacks. Understand how to identify the activity that signals its malicious usage, including proactive hunting for anomalous activity: bit.ly/4fyQYHB
32
98
31,050
Unit 42 retweeted
May 22
Iranian hackers have posed as job recruiters to target software engineers in the aviation sector as part of an elaborate espionage scheme during the US and Israeli war with Iran, cybersecurity researchers tell CNN. cnn.it/3RUyl7a
93
119
279
126,549
Users attempting to download open-source C IDE are hijacked via malicious CloudFront JS on-click, redirecting to fake MEGA-Transfer pages delivering #RemusStealer. Details at bit.ly/49bLy1u
2
26
69
5,724
A single threat actor uses multiple identities to run dozens of #AI-accelerated fake VPN Chrome extensions. All traffic routes through 15 SOCKS5 proxies, with some impersonating major VPN service providers. Details at bit.ly/4nNiByT
19
63
7,645
Iran-nexus APT Screening Serpens (aka UNC1549, Smoke Sandstorm) is deploying novel RAT variants in espionage campaigns targeting entities in the U.S., Israel and the UAE. These campaigns use AppDomainManager hijacking. Read our analysis for details: bit.ly/4dYHBQk
19
60
4,153
We identified 4,000 samples of TamperedChef malware hiding in trojanized productivity apps. These campaigns use code signing to bypass security filters. The malware can remain dormant for days before stealing data. Read our analysis: bit.ly/4wI0z57
2
21
76
6,741
2026-05-20 (Tuesday): Pages impersonating Claude and Homebrew continue to distribute malware like #MacSync stealer by employing a #ClickFix-style social engineering technique. Details at bit.ly/4upfAHC
3
22
92
9,433
The latest Gremlin stealer variants employ multiple layers of obfuscation such as identifier renaming and string encryption. These methods remove context and hide intentions from static analysis tools. Read our analysis for technical insights: bit.ly/4nyM8fq
1
11
29
3,773