A buffer overflow vulnerability in the User-ID Authentication Portal of PAN-OS software allows unauthenticated attackers to execute arbitrary code with root privileges on PA-Series and VM-Series firewalls. Limited exploitation has been observed starting April 9, 2026, by a likely state-sponsored threat cluster. Attackers successfully achieved remote code execution by injecting shellcode into nginx worker processes. Post-exploitation activities included deployment of EarthWorm and ReverseSocks5 tunneling tools, Active Directory enumeration using compromised firewall credentials, and systematic log destruction to evade detection. The attackers demonstrated operational discipline with intermittent interactive sessions over multiple weeks, using open-source tools instead of proprietary malware to minimize detection. The vulnerability poses elevated risk when the portal is exposed to untrusted networks or the public internet.
Executive Summary
Threat actor cl-sta-1132 exploited a buffer overflow vulnerability in PAN-OS User-ID Authentication Portal to gain root privileges on firewalls. The actors demonstrated state-sponsored characteristics, using tools like EarthWorm and ReverseSocks5, and displayed operational discipline by avoiding detection through minimal use of proprietary malware.
Goals & Targeting
The strategic objectives of cl-sta-1132 remain unclear due to limited available data. However, their targeting of PAN-OS vulnerabilities suggest they focus on compromising firewall systems for potential access to sensitive networks and data. The use of state-sponsored tactics indicates a possible long-term campaign aiming to establish persistence and gather intelligence or assets of strategic importance. Their victims are likely organizations with exposed User-ID Authentication Portals in sectors such as critical infrastructure, government agencies, and financial institutions.
Enhanced Description
Threat actor cl-sta-1132 exploits a critical buffer overflow vulnerability in the User-ID Authentication Portal of PAN-OS software, targeting PA-Series and VM-Series firewalls. The attack allows unauthenticated attackers to execute arbitrary code with root privileges. Limited exploitation was observed starting April 9, 2026, by a likely state-sponsored threat cluster. Attackers achieved remote code execution by injecting shellcode into nginx worker processes. Post-exploitation activities included the deployment of EarthWorm and ReverseSocks5 tunneling tools, Active Directory enumeration using compromised firewall credentials, and systematic log destruction to evade detection. The attackers demonstrated operational discipline with intermittent interactive sessions over multiple weeks, using open-source tools instead of proprietary malware to minimize detection. This approach highlights their ability to maintain persistence while avoiding traditional signature-based detection mechanisms. The vulnerability poses an elevated risk when the portal is exposed to untrusted networks or the public internet. The actors' use of established tools and techniques suggests a level of sophistication, potentially aligning with state-sponsored activity targeting critical infrastructure or high-value assets.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Threat actor cl-sta-1132 has demonstrated a limited but targeted campaign leveraging PAN-OS vulnerabilities. Their operational tempo includes intermittent interactive sessions over multiple weeks, indicating a patient and methodical approach to exploitation. The actors' focus on compromising firewall credentials suggests they seek long-term access or strategic assets within targeted networks. Notable past operations include successful exploitation of the buffer overflow vulnerability and subsequent deployment of tunneling tools for persistence and data exfiltration.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The confidence level in the available data about cl-sta-1132 is low due to limited information on their primary motivation, strategic goals, and long-term objectives. The analysis relies heavily on observed exploit activity and associated tools, which suggests a moderately sophisticated actor but leaves open questions about their broader campaign patterns and geographic or sectoral targeting beyond what has been observed.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics