{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/badpatch/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":[],"_cs_severities":["low"],"_cs_tags":["command-and-control","exfiltration","network-traffic","smtp","badpatch"],"_cs_type":"advisory","_cs_vendors":[],"content_html":"\u003cp\u003eThis brief outlines the risk posed by adversaries, such as the operators of the BadPatch malware, who repurpose TCP port 26 for command and control (C2) and exfiltration activities. While port 25 is the standard for Simple Mail Transfer Protocol (SMTP), port 26 is frequently leveraged to bypass traditional security controls that primarily scrutinize port 25 traffic. By initiating outbound SMTP communication from internal hosts to external destinations on port 26, attackers maintain persistent C2 channels that blend in with legitimate traffic if not explicitly monitored. Defensive teams must focus on identifying this non-standard outbound traffic to detect potential infections and unauthorized data movement within their environments.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eInitial compromise occurs on a target host (e.g., via phishing or exploit).\u003c/li\u003e\n\u003cli\u003eThe malware identifies the need for external communication to a C2 server.\u003c/li\u003e\n\u003cli\u003eThe malware checks network configuration or hardcoded settings to use port 26/TCP.\u003c/li\u003e\n\u003cli\u003eThe host initiates a TCP connection to an external, attacker-controlled IP address over port 26.\u003c/li\u003e\n\u003cli\u003eThe malware encapsulates C2 instructions or exfiltrated data within the SMTP protocol format.\u003c/li\u003e\n\u003cli\u003eThe connection is maintained to receive subsequent tasking or data upload commands.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccess of this attack allows attackers to establish persistent, stealthy control over internal Windows systems. Impact includes the risk of sensitive data exfiltration and the potential for further malware deployment or lateral movement within the network. The scope of targeting is primarily enterprise organizations where standard port monitoring may be insufficient.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize the identification of baseline network traffic to eliminate known legitimate services before alerting.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eDeploy the provided detection logic to network monitoring sensors to alert on outbound traffic on port 26/TCP.\u003c/li\u003e\n\u003cli\u003eEnable network flow or firewall logging for outbound connections originating from internal subnets.\u003c/li\u003e\n\u003cli\u003eEstablish a baseline for authorized internal mail relays that communicate with external SMTP destinations to reduce false positives in the SIEM.\u003c/li\u003e\n\u003cli\u003eIsolate systems identified in alerts and perform incident response procedures, focusing on memory and file system analysis for the BadPatch malware.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-31T07:05:01Z","date_published":"2026-08-31T07:05:01Z","id":"https://feed.craftedsignal.io/briefs/2026-08-smtp-port-26-c2/","summary":"Adversaries, including the BadPatch malware family, utilize non-standard port 26/TCP for SMTP-based command and control and data exfiltration to evade traditional security monitoring.","title":"Detection of Potential Command and Control via SMTP on Port 26/TCP","url":"https://feed.craftedsignal.io/briefs/2026-08-smtp-port-26-c2/"}],"language":"en","title":"CraftedSignal Threat Feed - Badpatch","version":"https://jsonfeed.org/version/1.1"}