RedTail Cryptominer Threat Actors Adopt PAN-OS CVE-2024-3400 Exploit

2024-05-30 Akamai

https://www.akamai.com/blog/security-research/2024/may/2024-redtail-cryptominer-pan-os-cve-exploit

Thumbnail for RedTail Cryptominer Threat Actors Adopt PAN-OS CVE-2024-3400 Exploit

Akamai observed RedTail cryptomining operators adding Palo Alto PAN-OS CVE-2024-3400 exploitation to a broader web-exploit arsenal targeting IoT devices, web applications, SSL-VPNs, and security products. The infection chain used command execution to download a bash script that selected a compatible binary by processor architecture and deployed a UPX-packed XMRig-based miner. The new RedTail variant embeds encrypted mining configuration, uses private mining pools or pool proxies, and adds anti-analysis and persistence behavior such as forking, killing GDB, and installing a cron job. Akamai notes that use of private mining pools mirrors tactics associated with Lazarus, but frames this only as attribution speculation rather than evidence of Lazarus responsibility.

Indicators of Compromise

Type Value First Seen Last Seen
IPv4 92.118.39.120 2024-05-30 2024-05-30
IPv4 94.156.79.129 2024-05-30 2024-05-30
IPv4 79.110.62.25 2024-05-30 2024-05-30
IPv4 78.153.140.51 2024-05-30 2024-05-30
IPv4 94.74.75.19 2024-05-30 2024-05-30
IPv4 193.222.96.163 2024-05-30 2024-05-30
IPv4 192.18.157.251 2024-05-30 2024-05-30
IPv4 34.127.194.11 2024-05-30 2024-05-30
IPv4 68.170.165.36 2024-05-30 2024-05-30
IPv4 94.156.79.60 2024-05-30 2024-05-30
IPv4 185.216.70.138 2024-05-30 2024-05-30

Related Reports

« Back