#RedTail

Malware/Tool

2024-05-30 • RedTail Cryptominer Threat Actors Adopt PAN-OS CVE-2024-3400 Exploit

RedTail is Linux cryptocurrency-mining malware deployed by exploiting Internet-facing systems. Its operators added CVE-2024-3400 in Palo Alto Networks PAN-OS to an exploit set that had previously targeted other server vulnerabilities. After compromise, RedTail enrolls the victim's computing resources into attacker-controlled private mining pools, giving the operators greater control over mining operations and proceeds. The toolchain also incorporates anti-analysis and persistence behavior, supporting sustained unauthorized use of Linux server capacity for cryptocurrency generation.

Tagged Reports

« Back