Edge Rewrite
// HTMLRewriter · presentation

This page was redesigned at the edge.

Cloudflare fetched the original article and streamed it through HTMLRewriter to apply an entirely new visual system without rebuilding the source page.

Jump to content

Draft:Unit 42

From Wikipedia, the free encyclopedia
  • Comment: Sources that just summarize/repeat their research are not significant coverage about the organization itself. Helpful Raccoon (talk) 02:00, 21 September 2026 (UTC)
  • Comment: In accordance with the Wikimedia Foundation's Terms of Use, I disclose that I have been paid by my employer for my contributions to this article. ThePlay82 (talk) 16:29, 17 September 2026 (UTC)

Unit 42 is the threat intelligence and incident response organization of Palo Alto Networks, an American cybersecurity company. The organization conducts research into cyberespionage, malware, ransomware and software vulnerabilities and provides incident-response services.

History and organization

[edit]

Unit 42 originated as Palo Alto Networks' threat intelligence research team. Its activities subsequently expanded to include incident response and security consulting.

The organization has been cited in independent reporting concerning cyberespionage campaigns, malware, vulnerability exploitation and major cybersecurity incidents.

Cybersecurity research

[edit]

Unit 42 conducts research into state-sponsored cyberespionage, malware and other cyber threats.

In February 2026, Recorded Future News reported on a Unit 42 investigation into a cyberespionage campaign that had compromised institutions in 37 governments. Unit 42 said it had tracked compromises of at least 70 institutions and reconnaissance activity affecting organizations in 155 countries.[1]

Reuters subsequently reported that Unit 42 researchers had initially connected the campaign to China but that Palo Alto Networks chose not to directly attribute the activity to China in the published report. Reuters reported that the decision reflected concerns about potential retaliation by Beijing and risks to company personnel and customers in China.[2]

In 2024, TechTarget reported on Unit 42 research documenting an increase in malware-initiated vulnerability scanning. The research described attackers compromising systems and then using those systems to scan other networks for vulnerabilities, allowing attackers to obscure the origin of scanning activity.[3]

Incident response

[edit]

In addition to threat research, Unit 42 performs incident-response work for organizations affected by cyberattacks. Its incident responders and researchers have participated in investigations of ransomware, data theft, network intrusions and other cybersecurity incidents.

References

[edit]
  1. Greig, Jonathan; Matishak, Martin (February 5, 2026). "Researchers uncover vast cyberespionage operation targeting dozens of governments worldwide". Recorded Future News. Retrieved September 16, 2026.
  2. "Palo Alto chose not to tie China to hacking campaign for fear of retaliation from Beijing, sources say". Reuters. February 12, 2026. Retrieved September 16, 2026.
  3. Culafi, Alexander (April 9, 2024). "Unit 42: Malware-initiated scanning attacks on the rise". TechTarget. Retrieved September 16, 2026.
[edit]

References

[edit]