Install
Please confirm you are human
This browser or connection looks automated. Press and continuously hold the control for 3 seconds to enable Google-hosted web results and, when separately allowed, AI-assisted answers.
A successful check enables 100 search requests. Interactive access does not authorize scraping, systematic collection, or reuse of search output.
News
Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure
1+ hour, 12+ min ago (1609+ words) The group behind CL-CRI-1171 provides an infection service for other threat actors who want to spread their malware indiscriminately. This pay-per-install (PPI) marketplace drove hundreds of infections through YouTube channels and a parallel search engine optimization (SEO)-poisoning funnel, all…...
An AI-Assisted Cyber Attack: Inside a Unit 42 Investigation
1+ week, 1+ hour ago (307+ words) The threat actor told us in negotiations that they leveraged frontier AI models and attack-specific agentic AI frameworks. By shifting execution to an automated loop, the attacker compressed weeks of methodical intrusion tradecraft (using more than 50 MITRE ATT&CK techniques)…...
Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams
1+ week, 2+ day ago (1594+ words) Custom-built to fit your organization's needs, you can choose to allocate your retainer hours to any of our offerings, including proactive cyber risk management services. Learn how you can put the world-class Unit 42 Incident Response team on speed dial. Highlights…...
Perturbation Probing: A New Diagnostic for the Fragility of LLM Safety
1+ week, 4+ day ago (588+ words) Unit 42 Perturbation Probing: A New Diagnostic for the Fragility of LLM Safety Introducing a New Angle on LLM Safety Our previous research on logit-gap steering demonstrated that the safety guardrails of an aligned LLM can be bypassed by closing a…...
The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution
2+ week, 1+ day ago (1217+ words) Of the 405 samples in our dataset, only 12 appeared in our telemetry on Cortex XDR-protected endpoints, and a small subset was forwarded through Next-Generation Firewalls to WildFire for analysis. Palo Alto Networks products detected and blocked every sample that attempted to…...
Identity Abuse Through Trusted Communication Channels
2+ week, 6+ day ago (706+ words) Palo Alto Networks customers are better protected from the threats discussed above through the following products and services: If you think you might have been compromised or have an urgent matter, contact the Unit 42 Incident Response team. As organizations adopt…...
Kimwolf v7: An Evolution of the Kimwolf Botnet
4+ week, 1+ day ago (1602+ words) We are providing a content warning because the following article contains usage of a racial slur by a threat actor, which Unit 42 does not condone in any instance. We have partially redacted the racial slur, but preserved some references to…...
The Permanent Threat: Analyzing Aeternum’s Blockchain-Based C2 Operations and Communications
4+ week, 1+ day ago (1633+ words) Custom-built to fit your organization's needs, you can choose to allocate your retainer hours to any of our offerings, including proactive cyber risk management services. Learn how you can put the world-class Unit 42 Incident Response team on speed dial. Highlights…...
Inside the Modern SOC: The Identity Front Door
1+ mon, 1+ day ago (511+ words) In The 72-Minute Race, we explored how attackers are compressing the time between initial access and business impact. But as attacks continue to accelerate, another trend has emerged: Attackers are increasingly gaining access through compromised identities rather than exploiting technology…...
ChainDrop: Inside a Self-Propagating npm Worm
1+ mon, 2+ day ago (1699+ words) Custom-built to fit your organization's needs, you can choose to allocate your retainer hours to any of our offerings, including proactive cyber risk management services. Learn how you can put the world-class Unit 42 Incident Response team on speed dial. Highlights…...