UPSTYLE is a custom Python-based web shell targeting Palo Alto Networks PAN-OS firewalls running GlobalProtect. It is associated with UTA0218, also tracked as SLIME61, and the Operation MidnightEclipse campaign involving zero-day exploitation of CVE-2024-3400 in 2024. This unauthenticated command-injection vulnerability enables remote code execution with root privileges on affected firewalls. UPSTYLE-associated attacks have included targeting the manufacturing sector in Saudi Arabia. Installation attempts failed in some investigated intrusions, after which the attackers used alternative persistence mechanisms.
UPSTYLE executes commands embedded in specially crafted requests to nonexistent pages on the compromised firewall. It monitors the resulting VPN web-service error logs, extracts and decodes the commands, and executes them locally. Command output is temporarily appended to a legitimate, web-accessible CSS resource for retrieval. The implant removes command-bearing log entries, restores the CSS resource after approximately 15 seconds, and restores access and modification timestamps to conceal activity. Its installer uses a Python package-initialization mechanism to execute a Base64-encoded backdoor when Python starts. UPSTYLE also uses benign-looking filenames for masquerading. These behaviors provide persistent post-exploitation command execution while minimizing visible changes to legitimate firewall resources.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Threat actors have been actively exploiting CVE-2024-3400 since March 2024. SLIME60 has exploited it with XStealer, while SLIME61 (aka UTA0218) has exploited it as a zero-day with UPStyle.
Successful exploitation allows attackers to reconfigure firewalls, exfiltrate sensitive data, or deploy persistent backdoors like the UPSTYLE malware observed in prior PAN-OS campaigns.
Successful exploitation allows attackers to reconfigure firewalls, exfiltrate sensitive data, or deploy persistent backdoors like the UPSTYLE malware observed in prior PAN-OS campaigns.
Successful exploitation allows attackers to reconfigure firewalls, exfiltrate sensitive data, or deploy persistent backdoors like the UPSTYLE malware observed in prior PAN-OS campaigns.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
SLIME61 (aka UTA0218) has exploited CVE-2024-3400 as zero-day with UPStyle web shell in several attacks, including an attack against manufacturing industry in Saudi Arabia.
SLIME61 (aka UTA0218) has exploited CVE-2024-3400 as zero-day with UPStyle web shell in several attacks, including an attack against manufacturing industry in Saudi Arabia.
After initial exploitation, threat actors have been observed deploying reverse shells and the UPSTYLE backdoor, as well as executing a variety of commands on the firewall, including copying and exfiltrating configuration files.
19 distinct techniques documented for this family, organized by ATT&CK tactic.
"Threat Hunting: Monitor for anomalous gNMI requests or unexpected cron job creation, indicators of UPSTYLE backdoor activity."
Tracked as CVE-2024-3400 (CVSS: 10), this is a command injection vulnerability in the GlobalProtect feature of Palo Alto Networks PAN-OS software. | After initial exploitation, threat actors have been observed deploying reverse shells and the UPSTYLE backdoor...
"Threat Hunting: Monitor for anomalous gNMI requests or unexpected cron job creation, indicators of UPSTYLE backdoor activity."
"Successful exploitation allows attackers to... deploy persistent backdoors like the UPSTYLE malware observed in prior PAN-OS campaigns."
"Threat Hunting: Monitor for anomalous gNMI requests or unexpected cron job creation, indicators of UPSTYLE backdoor activity."
The content repeatedly describes payloads, strings, configuration files, scripts, URLs, and binaries being obfuscated or encoded using Base64, XOR, RC4, AES, RSA, hex encoding, custom algorithms, and other methods across many malware families and threat actors.
The content repeatedly describes adversaries and malware deleting files, directories, droppers, scripts, logs, archives, staged data, and other artifacts from compromised systems, e.g., 'APT29 has used SDelete to remove artifacts from victim networks' and 'Lazarus Group malware has deleted files in various ways, including "suicide scripts" to delete malware binaries from the victim.'
APT28 has performed timestomping on victim files. APT29 has used timestomping to alter the Standard Information timestamps on their web shells to match other files in the same directory. APT32 has used scheduled task raw XML with a backdated timestamp... APT38 has modified data timestamps to mimic files that are in the same folder on a compromised host.
13 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A persistent backdoor malware referenced as being deployed on Palo Alto Networks PAN-OS devices after exploitation, enabling long-term unauthorized access (with noted hunting guidance including monitoring for unexpected cron job creation).
Malware that restores original timestamps after modifying files.
Web shell designed for Palo Alto Networks PAN-OS SSL VPN devices. Attackers generate crafted error-log entries through requests to the VPN service; UPStyle parses those entries to execute arbitrary commands. The report identifies web-shell samples and droppers that install a child web shell at /usr/lib/python3.6/site-packages/system.pth. SLIME61 used it in zero-day exploitation of CVE-2024-3400.
UPSTYLE is a custom Python-based backdoor developed specifically for exploitation of CVE-2024-3400 in Palo Alto Networks PAN-OS firewalls. It is designed to provide persistent remote access, execute commands, and exfiltrate data while evading detection by using legitimate log and CSS files for command and control and output exfiltration.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.