Detection of Malware-Associated HTTP User-Agent Strings
This analytic identifies potential C2 traffic by matching HTTP User-Agent strings from proxy or web logs against a repository of known malicious agents used by infostealers including Lokibot, Lumma, Meduza, and RedLine.
Security operations teams frequently encounter malware that utilizes specific, identifiable HTTP User-Agent strings to facilitate Command and Control (C2) communication. This analytic leverages network telemetry to cross-reference observed traffic against a curated list of malicious user agents associated with prominent infostealers, such as Lokibot, Lumma Stealer, Meduza Stealer, and RedLine Stealer. By identifying these strings within web or proxy logs, defenders can uncover compromised internal hosts that are actively beaconing or exfiltrating data to adversary-controlled infrastructure. This detection logic is critical for visibility into network-based C2, specifically focusing on the application layer indicators often overlooked by perimeter defenses. Implementation requires ingestion of structured web/proxy logs into the network security datamodel.
Impact
Successful detection of these User-Agent strings allows for the early identification of compromised systems before secondary objectives like credential theft, lateral movement, or data exfiltration are fully realized. If these malicious agents go undetected, infostealers can persist on host endpoints, leading to the theft of sensitive session tokens, browser data, and crypto-wallet information from the affected environment.
Recommendation
Prioritize the deployment of network-layer detection logic to surface suspicious User-Agent activity.
- Integrate web, proxy, or EDR-captured network request logs into your central logging platform.
- Implement a lookup-based detection approach to compare
http_user_agentfields against a regularly updated threat intelligence list of known malware agents (e.g., the referenced GitHub list). - Use the provided drilldown procedure to correlate alert findings with host-based risk events over the preceding 7-day period to assess the impact of identified compromised systems.
Immediate actions
Deploy lookup-based detection for suspicious User-Agents
Threat Hunt
Identify internal hosts exhibiting unknown or uncommon User-Agent strings
Data: Web proxy logs containing http_user_agent