Palo Alto Networks Firewall Vulnerability Exploited by RedTail Crypto-Mining Malware

The threat actors behind the RedTail cryptocurrency mining malware have upped their game by incorporating a recently disclosed security flaw affecting Palo Alto Networks firewalls into their exploit arsenal. According to findings from web infrastructure and security company Akamai, the malware now includes new anti-analysis techniques and utilizes private crypto-mining pools for greater control over mining outcomes.

The infection sequence discovered by Akamai exploits a now-patched vulnerability in PAN-OS that could allow an attacker to execute arbitrary code with root privileges on the firewall. Once successful, the malware retrieves and runs a bash shell script from an external domain to download the RedTail payload based on the CPU architecture.

RedTail has been known to exploit various security flaws in TP-Link routers, ThinkPHP, Ivanti Connect Secure, and VMWare Workspace ONE Access and Identity Manager. The latest version of the malware detected in April includes an encrypted mining configuration to launch the XMRig miner, indicating a deep understanding of crypto-mining by the threat actors.

The sophistication and level of polish observed in RedTail suggest a high level of investment in running a private crypto-mining operation, leading researchers to speculate that the attack group behind it may be nation-state-sponsored. This advanced malware employs evasion and persistence techniques to hinder analysis, making it a notable threat in the cryptocurrency mining landscape.

Stay updated on the latest cybersecurity news by following us on Twitter and LinkedIn for more exclusive content.

Related articles

Only one suspect being held on suspicion of attempted murder

Police confirm that only one suspect being held on suspicion of attempted murder for transport attacks on the train to London. An update from British Transport Police. They say a 32-year-old man arrested yesterday is now...

Starmer hosts Zelenskyy for meaningful and warm talks

Keir Starmer hosts Zelenskyy for meaningful and warm talks, according to a Downing Street statement, where the Ukrainian President managed to secure a 2.3Bn loan (handout) and able to send a statement to the...

Baby red panda dies ‘from stress’ during fireworks night – days after mother’s tragic death

Baby red panda dies in Edinburgh Zoo has been linked to stress likely caused by fireworks – as experts call for stricter regulations. The three-month-old red panda cub named Roxie died on Bonfire Night at...

David Beckham shares difficult moment before sharing family photo at Victoria’s Paris fashion show

David Beckham faced a challenging moment before posting a sweet family photo at wife Victoria's Paris fashion show, where he was joined by his dapper husband in a black tailored suit and tie. The...

Warnings for Wind and Rain Issued for Southern England and South Wales in UK Weather

Weather warnings have been issued as strong winds and heavy rain are on the way to the UK – days after some areas were hit by flooding. A yellow rain warning has been issued...

Latest articles

LEAVE A REPLY

Please enter your comment!
Please enter your name here