Skip to content
Threat Feed

Tag

C2

28 briefs RSS
rumour rumour

HEAVYGRAM Telegram-based Surveillance Backdoor

HEAVYGRAM is a Windows-based surveillance backdoor used by Handala Hack that utilizes the Telegram API for command-and-control communication to facilitate remote information theft and system monitoring.

Handala Hack backdoor surveillance c2 telegram
1t
high advisory

Detection of Reverse Shell Activity via Shell Command-Line Arguments

This brief outlines detection logic for identifying reverse shell activity on Unix-like systems by monitoring shell processes for suspicious command-line network device redirection.

execution c2 linux macos
1r 2t
high advisory

Path Traversal in BC Security Empire Upload Endpoint

BC Security Empire versions prior to 6.7.1 are vulnerable to path traversal via the multipart filename parameter, allowing an authenticated operator to achieve arbitrary file write and potential code execution.

Empire vulnerability c2 path-traversal
1t
high threat

CL-CRI-1171 Pay-Per-Install Infrastructure and Malware Campaign

The CL-CRI-1171 threat actor operates a large-scale pay-per-install marketplace, leveraging SEO poisoning and YouTube gaming lures to deploy a persistent multi-payload loader used to distribute malware including Insomnia RAT and ARKTunnel.

WinDirStat CL-CRI-1171 ppi malware seo-poisoning loader remote-access-trojan c2
1r 2t 5i
medium advisory

Detection of Socat Usage for Stealthy Remote Connections

The socat utility is being identified in malicious contexts when used with local terminal echo disabled and configured for remote TCP or OpenSSL connections, often indicating C2 or lateral movement.

socat execution c2 macos linux
1r 2t
high threat

Toy Ghouls Deploying Custom HiveMQ and Matrix-Based Backdoors

The threat actor Toy Ghouls is using WinRM to deploy custom 'Bird' backdoors that utilize HiveMQ MQTT brokers and the Matrix protocol for C2, featuring machine-bound encrypted configurations.

Toy Ghouls backdoors persistence winrm c2 mqtt
1r 3t 1i
medium advisory

Detection of DLL Downloads via PowerShell Cmdlets

This brief covers the detection of suspicious PowerShell activity involving the use of web download cmdlets to retrieve and save DLL files to the local file system.

windows powershell c2 malware-delivery
1r 2t
high advisory

Suspicious Outbound Network Connections Initiated by Script Interpreters

Adversaries utilize Windows script engines, wscript.exe and cscript.exe, to initiate outbound network connections for downloading malicious payloads or communicating with command and control infrastructure.

windows c2 living-off-the-land
1r 1t
medium advisory

Unauthorized VNC Exposure to the Internet

The exposure of VNC services to the public internet enables unauthorized remote access, providing adversaries a vector for initial access or persistent backdoors.

vnc c2 network-security remote-access
1r 2t
high threat

BlueDelta Targets European Defense and Diplomacy with HOOKEDGE Backdoor

The Russian threat group BlueDelta is using a custom batch-script backdoor named HOOKEDGE to target European government and diplomatic entities via macro-enabled Microsoft Word documents that leverage legitimate webhook services for C2.

Word BlueDelta espionage windows phishing c2
1r 3t 1i
high advisory

Detecting Malicious Ingress Tool Transfer via Kubernetes Pod Exec

This brief covers the detection of attackers using Kubernetes 'exec' APIs to stage tools or exfiltrate data by invoking 'curl' or 'wget' to HTTPS endpoints from within container workloads.

Kubernetes execution c2 cloud
2t
high advisory

Trojanized npm Packages Distribute RedC2 4.0 Linux Backdoor

Fourteen trojanized npm packages masquerading as utility libraries deliver the RedC2 4.0 'RedShell' Linux beacon, which features AI-assisted command execution and cross-platform post-exploitation capabilities.

supply-chain npm malware linux c2 redc2
1r 2t
high advisory

Project CAV3RN Modular Espionage Framework

Project CAV3RN is a modular espionage framework targeting entities in Israel that uses a .NET NativeAOT-compiled communication module to orchestrate DNS-controlled C2 transport switching between direct HTTPS and Google Apps Script relays.

.NET 8 +1 espionage c2 dns nativeaot modular
1r 4t 3i
high advisory

Aeternum Botnet Leverages Polygon Blockchain for Decentralized C2

Aeternum is a C++ botnet loader that utilizes Polygon blockchain smart contracts for resilient, decentralized command-and-control communication and payload delivery.

botnet blockchain C2 malware execution persistence
1r 3t 3i
medium advisory

Detection of PowerShell-Based Command and Control via DNS TXT Records

This brief describes a detection methodology for identifying malware utilizing DNS TXT records to retrieve commands via PowerShell to bypass network egress restrictions.

PowerShell c2 dns malware
1r 2t
high advisory

Suspicious Windows Public IP Address Discovery via DNS

Adversaries frequently use public IP lookup services to perform network reconnaissance and verify egress connectivity prior to establishing C2 channels, a behavior detectable via DNS query analysis from suspicious processes.

discovery c2 windows reconnaissance
1r 1t 33i
high advisory

Web Server Outbound Connections to File Sharing Services

Attackers compromise web servers (Apache, Nginx, Tomcat, PHP) and leverage them to make unexpected outbound network connections to public file-sharing or content hosting services, indicating post-exploitation activity for ingress tool transfer and further compromise.

Apache HTTP Server +3 post-exploitation ingress-tool-transfer webshell web-server c2 windows
1r 2t 26i
medium advisory

Windows DNS Query Request by Telegram Bot API

An analytic detects DNS queries to `api.telegram.org` originating from non-Telegram processes on Windows systems, indicating potential malware command and control (C2) communication or data exfiltration via the Telegram Bot API.

command-and-control malware windows c2 dns telegram
1r 2t 1i
high threat

TrickBot Variant Utilizes DNS Tunneling for Command and Control

FortiGuard Labs analyzed a new TrickBot variant that employs DNS tunneling for command and control communications, modular execution, and incorporates persistence and obfuscation techniques to evade detection and maintain presence on infected systems.

TrickBot malware banking-trojan dns-tunneling c2 persistence obfuscation
4t
high threat

UAT-11795 Deploys Starland RAT and WLDR Agent via Trojanized Software

UAT-11795, a sophisticated and financially motivated Russian-speaking threat actor, targets users in the U.S. and Europe with trojanized software installers to deploy custom Python-based Starland RAT and an in-memory PowerShell WLDR agent for credential theft and cryptocurrency exfiltration.

exploited Webex +2 UAT-11795 financially-motivated rat c2 trojan windows python powershell
2r 6t
high advisory

HelloNet Campaign Uses ViPNet Update System for Malicious Module Delivery

An unknown sophisticated threat actor is leveraging DLL sideloading within the ViPNet update system to deploy a multi-stage malware suite, including HelloInjector, HelloProxy, HelloExecutor, HelloCleaner, and HelloBackdoor, to establish persistence, exfiltrate data, and maintain covert access to large Russian organizations in government, energy, and other critical sectors.

ViPNet Update System apt dll-sideloading persistence proxy c2 reconnaissance data-exfiltration russia +1
3r 11t 1i
low advisory

Linux C2 Agent Activity: Suspicious Network Connection and File Creation

Threat actors leverage C2 agents like Poseidon and Athena, operating from suspicious Linux writable directories, to establish network connections with C2 frameworks such as Mythic, subsequently creating files to stage further malicious activities.

linux command-and-control execution malware c2 threat-detection
2r 2t
high advisory

Windows DNS Query to Telegram Bot API Indicating Malware C2

This brief details the detection of suspicious DNS queries from non-Telegram processes to api.telegram.org on Windows systems, a strong indicator of malware utilizing the Telegram Bot API for command and control (C2) communications to receive commands or exfiltrate data.

Telegram Bot API network command-and-control c2 telegram windows malware
1r 2t 1i
high advisory

Suspicious Process DNS Queries to Discord

This brief identifies a detection for non-legitimate processes making DNS queries to Discord domains, indicating potential malware attempting to download additional payloads, as seen in campaigns like WhisperGate, leading to further code execution and system compromise.

malware c2 initial-access execution windows
1r 1t 2i
high threat

China-Nexus Campaign Using Google Calendar as C2

A China-nexus threat actor is utilizing Google Calendar as a command and control (C2) infrastructure to conduct stealthy operations.

China-nexus actor google-calendar c2 china-nexus
2r 4t
medium advisory

Iranian Botnet Operation Exposed via Open Directory

An Iranian botnet operation utilizing a 15-node relay network and active C2 infrastructure was exposed through an open directory.

botnet iran C2
1r 1t 1i
high threat

MuddyWater PowGoop Beacon Decoding Detection

This detection identifies a DLL decoding and executing the PowGoop config.txt payload, indicating a stage in the MuddyWater infection chain where an obfuscated PowerShell beacon is unwrapped and live C2 communication starts.

Splunk Enterprise +3 MuddyWater powgoop dll-sideloading powershell c2 beacon
2r 4t
high advisory

Suspicious DNS Queries to Telegram Bot API

Detection of DNS queries to api.telegram.org by processes other than telegram.exe indicates potential command and control communication via Telegram bots, a technique leveraged by malware to establish covert communication channels.

Telegram Bot API telegram bot c2 command-and-control dns
2r 2t 1i