UTA0218 is a China-linked threat actor tracked by Volexity and associated with Operation MidnightEclipse, a campaign exploiting Palo Alto Networks PAN-OS firewalls through the GlobalProtect feature. Exploitation was observed from March 26, 2024, before public disclosure of CVE-2024-3400, an unauthenticated operating-system command-injection vulnerability that enables remote code execution with root privileges. The actor used compromised firewalls as entry points into victim networks, established reverse shells, downloaded additional tools, and exported firewall configurations. Its documented hands-on intrusions were targeted; specific victim countries and industry sectors have not been established. UTA0218 attempted to deploy UPSTYLE, a custom Python backdoor that processes commands embedded in specially crafted network requests. UPSTYLE conceals activity by removing command-bearing log entries, temporarily embedding command output in legitimate web content, and restoring modified files and timestamps. The actor also established recurring execution through scheduled tasks and used GOST and an open-source reverse-SSH utility for tunneling and remote access. In one investigated intrusion, it abused a firewall service account with domain-administrator privileges to move laterally over SMB and WinRM. It stole Active Directory database contents, domain and user DPAPI keys, and browser credentials and cookies, exposing credentials for all domain accounts. UTA0218 also used VPN infrastructure, compromised cloud storage, and virtual private servers to support its operations. No established aliases or subgroups are documented.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
1 distinct technique observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 malware families attributed to this actor across reporting.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
44 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
China-nexus activity cluster cited as exploiting the PAN-OS GlobalProtect zero-day CVE-2024-3400.
A China-nexus activity cluster exploiting the PAN-OS GlobalProtect zero-day CVE-2024-3400; the same vulnerability was subsequently used by ransomware operators.
UTA0218 is known for exploiting the CVE-2024-3400 vulnerability in Palo Alto Networks PAN-OS firewalls as part of Operation MidnightEclipse, using the flaw to gain root privileges and facilitate lateral movement within victim networks.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.