Operation MidnightEclipse last observed
The campaign source marks this as the latest known activity date.
Operation MidnightEclipse was a campaign conducted in March and April 2024 that involved initial exploit of zero-day vulnerability CVE-2024-3400, a critical command injection vulnerability in the GlobalProtect feature of Palo Alto Networks PAN-OS.
Each relationship retains its own confidence and source.
Every date says what it measures so catalog dates are not confused with publication dates.
The campaign source marks this as the latest known activity date.
The campaign source marks this as the beginning of the known activity window.
CVEs, techniques, malware, and indicators in the sections below are associated with an attributed actor. They are useful investigative context, but the campaign source does not necessarily link every item directly to this campaign.
Use this material to guide hunting and prioritization, then confirm each relationship against its cited source.
No linked CVEs are available.
No linked techniques are available.
No linked malware or tools are available.
No source-linked indicators are available.
Open the original material before making an attribution or response decision.