← All campaigns

ATT&CK technique

T1027

3 campaigns

Compare campaigns in this att&ck technique →

Feng Shui: A Custom, Fully-Obfuscated Sliver Implant Deployed to a Palo Alto Firewall (CVE-2024-0012 + CVE-2024-9474)

Over two days we watched a single operator chain two PAN-OS vulnerabilities in one request to install a custom-compiled, fully-obfuscated Sliver implant that appears in no public malware database and beacons to domains absent from every threat feed. A step-by-step walkthrough of the intrusion, with deployable Sigma and YARA detection.

2026-07-09

TeamPCP v21: Inside a 45-Second Docker Escape to Multi-Persistence Cryptojacking

Docker exposes a management interface, the Docker daemon API, that lets you create, start, and control containers. When it is accidentally published to the internet with no authentication, anyone who can reach that port can take over the host underneath it. We watched a fully automated toolkit do exactly that in about 45 seconds.

2026-06-29

Polydrop: Dissecting a Four-Stage Implant Chain Delivered via Langflow RCE

Langflow is an open-source tool that lets developers build AI and large-language-model pipelines visually, by dragging and connecting components in a browser.

2026-06-03