RedTail Cryptominer Threat Actors Adopt PAN-OS CVE-2024-3400 Exploit
2024-05-30 • Akamai •
https://www.akamai.com/blog/security-research/2024/may/2024-redtail-cryptominer-pan-os-cve-exploit
Akamai observed RedTail cryptomining operators adding Palo Alto PAN-OS CVE-2024-3400 exploitation to a broader web-exploit arsenal targeting IoT devices, web applications, SSL-VPNs, and security products. The infection chain used command execution to download a bash script that selected a compatible binary by processor architecture and deployed a UPX-packed XMRig-based miner. The new RedTail variant embeds encrypted mining configuration, uses private mining pools or pool proxies, and adds anti-analysis and persistence behavior such as forking, killing GDB, and installing a cron job. Akamai notes that use of private mining pools mirrors tactics associated with Lazarus, but frames this only as attribution speculation rather than evidence of Lazarus responsibility.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| IPv4 | 92.118.39.120 | 2024-05-30 | 2024-05-30 |
| IPv4 | 94.156.79.129 | 2024-05-30 | 2024-05-30 |
| IPv4 | 79.110.62.25 | 2024-05-30 | 2024-05-30 |
| IPv4 | 78.153.140.51 | 2024-05-30 | 2024-05-30 |
| IPv4 | 94.74.75.19 | 2024-05-30 | 2024-05-30 |
| IPv4 | 193.222.96.163 | 2024-05-30 | 2024-05-30 |
| IPv4 | 192.18.157.251 | 2024-05-30 | 2024-05-30 |
| IPv4 | 34.127.194.11 | 2024-05-30 | 2024-05-30 |
| IPv4 | 68.170.165.36 | 2024-05-30 | 2024-05-30 |
| IPv4 | 94.156.79.60 | 2024-05-30 | 2024-05-30 |
| IPv4 | 185.216.70.138 | 2024-05-30 | 2024-05-30 |