Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors cl-sta-1132

Description

A buffer overflow vulnerability in the User-ID Authentication Portal of PAN-OS software allows unauthenticated attackers to execute arbitrary code with root privileges on PA-Series and VM-Series firewalls. Limited exploitation has been observed starting April 9, 2026, by a likely state-sponsored threat cluster. Attackers successfully achieved remote code execution by injecting shellcode into nginx worker processes. Post-exploitation activities included deployment of EarthWorm and ReverseSocks5 tunneling tools, Active Directory enumeration using compromised firewall credentials, and systematic log destruction to evade detection. The attackers demonstrated operational discipline with intermittent interactive sessions over multiple weeks, using open-source tools instead of proprietary malware to minimize detection. The vulnerability poses elevated risk when the portal is exposed to untrusted networks or the public internet.

AI Analysis

· 2 weeks ago

Executive Summary

Threat actor cl-sta-1132 exploited a buffer overflow vulnerability in PAN-OS User-ID Authentication Portal to gain root privileges on firewalls. The actors demonstrated state-sponsored characteristics, using tools like EarthWorm and ReverseSocks5, and displayed operational discipline by avoiding detection through minimal use of proprietary malware.

Goals & Targeting

The strategic objectives of cl-sta-1132 remain unclear due to limited available data. However, their targeting of PAN-OS vulnerabilities suggest they focus on compromising firewall systems for potential access to sensitive networks and data. The use of state-sponsored tactics indicates a possible long-term campaign aiming to establish persistence and gather intelligence or assets of strategic importance. Their victims are likely organizations with exposed User-ID Authentication Portals in sectors such as critical infrastructure, government agencies, and financial institutions.

Enhanced Description

Threat actor cl-sta-1132 exploits a critical buffer overflow vulnerability in the User-ID Authentication Portal of PAN-OS software, targeting PA-Series and VM-Series firewalls. The attack allows unauthenticated attackers to execute arbitrary code with root privileges. Limited exploitation was observed starting April 9, 2026, by a likely state-sponsored threat cluster. Attackers achieved remote code execution by injecting shellcode into nginx worker processes. Post-exploitation activities included the deployment of EarthWorm and ReverseSocks5 tunneling tools, Active Directory enumeration using compromised firewall credentials, and systematic log destruction to evade detection. The attackers demonstrated operational discipline with intermittent interactive sessions over multiple weeks, using open-source tools instead of proprietary malware to minimize detection. This approach highlights their ability to maintain persistence while avoiding traditional signature-based detection mechanisms. The vulnerability poses an elevated risk when the portal is exposed to untrusted networks or the public internet. The actors' use of established tools and techniques suggests a level of sophistication, potentially aligning with state-sponsored activity targeting critical infrastructure or high-value assets.

Key Capabilities

  • Exploitation of buffer overflow vulnerabilities
  • Deployment of EarthWorm and ReverseSocks5 tools
  • Active Directory enumeration techniques
  • Log destruction for evasion
  • Operational discipline with minimal tool footprint

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Defense Evasion
Discovery
Collection
Exfiltration
Impact

ATT&CK Techniques

T1064.001
T1229
T1133
T1548
T1571
T1584
T1585

Software / Tooling

EarthWorm
ReverseSocks5
Nginx worker processes
Open-source tools (e.g., for log destruction)

Campaigns & Victims

Threat actor cl-sta-1132 has demonstrated a limited but targeted campaign leveraging PAN-OS vulnerabilities. Their operational tempo includes intermittent interactive sessions over multiple weeks, indicating a patient and methodical approach to exploitation. The actors' focus on compromising firewall credentials suggests they seek long-term access or strategic assets within targeted networks. Notable past operations include successful exploitation of the buffer overflow vulnerability and subsequent deployment of tunneling tools for persistence and data exfiltration.

IOC Patterns

  • Spear-phishing with macro-laced Office documents
  • C2 over DNS using fast-flux
  • Staging infrastructure on bulletproof hosting
  • Use of known vulnerabilities in PAN-OS software
  • Nginx worker process injection
  • EarthWorm and ReverseSocks5 tool signatures

Recommended Actions

  • Patch PAN-OS User-ID Authentication Portal to address the buffer overflow vulnerability.
  • Monitor network traffic for signs of remote code execution or shellcode injection attempts.
  • Enhance firewall monitoring and logging capabilities to detect and respond to potential compromises.
  • Conduct regular penetration tests focusing on authentication portals exposed to external networks.
  • Implement strict access controls and encryption for critical systems like Active Directory.
  • Train users to recognize potential phishing attempts or suspicious network activity.

Suggested Tags

APT
buffer overflow
networking/telecom sector
firewall exploitation
state-sponsored

Confidence Assessment

The confidence level in the available data about cl-sta-1132 is low due to limited information on their primary motivation, strategic goals, and long-term objectives. The analysis relies heavily on observed exploit activity and associated tools, which suggests a moderately sophisticated actor but leaves open questions about their broader campaign patterns and geographic or sectoral targeting beyond what has been observed.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

APT
Critical Infrastructure
buffer overflow
networking/telecom sector
firewall exploitation
state-sponsored

Details

Type
Unknown
Confidence
55%
Added
May 10, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.