Tag
HEAVYGRAM Telegram-based Surveillance Backdoor
1 TTPHEAVYGRAM is a Windows-based surveillance backdoor used by Handala Hack that utilizes the Telegram API for command-and-control communication to facilitate remote information theft and system monitoring.
Detection of Reverse Shell Activity via Shell Command-Line Arguments
1 rule 2 TTPsThis brief outlines detection logic for identifying reverse shell activity on Unix-like systems by monitoring shell processes for suspicious command-line network device redirection.
Path Traversal in BC Security Empire Upload Endpoint
1 TTPBC Security Empire versions prior to 6.7.1 are vulnerable to path traversal via the multipart filename parameter, allowing an authenticated operator to achieve arbitrary file write and potential code execution.
CL-CRI-1171 Pay-Per-Install Infrastructure and Malware Campaign
1 rule 2 TTPs 5 IOCsThe CL-CRI-1171 threat actor operates a large-scale pay-per-install marketplace, leveraging SEO poisoning and YouTube gaming lures to deploy a persistent multi-payload loader used to distribute malware including Insomnia RAT and ARKTunnel.
Detection of Socat Usage for Stealthy Remote Connections
1 rule 2 TTPsThe socat utility is being identified in malicious contexts when used with local terminal echo disabled and configured for remote TCP or OpenSSL connections, often indicating C2 or lateral movement.
Toy Ghouls Deploying Custom HiveMQ and Matrix-Based Backdoors
1 rule 3 TTPs 1 IOCThe threat actor Toy Ghouls is using WinRM to deploy custom 'Bird' backdoors that utilize HiveMQ MQTT brokers and the Matrix protocol for C2, featuring machine-bound encrypted configurations.
Detection of DLL Downloads via PowerShell Cmdlets
1 rule 2 TTPsThis brief covers the detection of suspicious PowerShell activity involving the use of web download cmdlets to retrieve and save DLL files to the local file system.
Suspicious Outbound Network Connections Initiated by Script Interpreters
1 rule 1 TTPAdversaries utilize Windows script engines, wscript.exe and cscript.exe, to initiate outbound network connections for downloading malicious payloads or communicating with command and control infrastructure.
Unauthorized VNC Exposure to the Internet
1 rule 2 TTPsThe exposure of VNC services to the public internet enables unauthorized remote access, providing adversaries a vector for initial access or persistent backdoors.
BlueDelta Targets European Defense and Diplomacy with HOOKEDGE Backdoor
1 rule 3 TTPs 1 IOCThe Russian threat group BlueDelta is using a custom batch-script backdoor named HOOKEDGE to target European government and diplomatic entities via macro-enabled Microsoft Word documents that leverage legitimate webhook services for C2.
Detecting Malicious Ingress Tool Transfer via Kubernetes Pod Exec
2 TTPsThis brief covers the detection of attackers using Kubernetes 'exec' APIs to stage tools or exfiltrate data by invoking 'curl' or 'wget' to HTTPS endpoints from within container workloads.
Trojanized npm Packages Distribute RedC2 4.0 Linux Backdoor
1 rule 2 TTPsFourteen trojanized npm packages masquerading as utility libraries deliver the RedC2 4.0 'RedShell' Linux beacon, which features AI-assisted command execution and cross-platform post-exploitation capabilities.
Project CAV3RN Modular Espionage Framework
1 rule 4 TTPs 3 IOCsProject CAV3RN is a modular espionage framework targeting entities in Israel that uses a .NET NativeAOT-compiled communication module to orchestrate DNS-controlled C2 transport switching between direct HTTPS and Google Apps Script relays.
Aeternum Botnet Leverages Polygon Blockchain for Decentralized C2
1 rule 3 TTPs 3 IOCsAeternum is a C++ botnet loader that utilizes Polygon blockchain smart contracts for resilient, decentralized command-and-control communication and payload delivery.
Detection of PowerShell-Based Command and Control via DNS TXT Records
1 rule 2 TTPsThis brief describes a detection methodology for identifying malware utilizing DNS TXT records to retrieve commands via PowerShell to bypass network egress restrictions.
Suspicious Windows Public IP Address Discovery via DNS
1 rule 1 TTP 33 IOCsAdversaries frequently use public IP lookup services to perform network reconnaissance and verify egress connectivity prior to establishing C2 channels, a behavior detectable via DNS query analysis from suspicious processes.
Web Server Outbound Connections to File Sharing Services
1 rule 2 TTPs 26 IOCsAttackers compromise web servers (Apache, Nginx, Tomcat, PHP) and leverage them to make unexpected outbound network connections to public file-sharing or content hosting services, indicating post-exploitation activity for ingress tool transfer and further compromise.
Windows DNS Query Request by Telegram Bot API
1 rule 2 TTPs 1 IOCAn analytic detects DNS queries to `api.telegram.org` originating from non-Telegram processes on Windows systems, indicating potential malware command and control (C2) communication or data exfiltration via the Telegram Bot API.
TrickBot Variant Utilizes DNS Tunneling for Command and Control
4 TTPsFortiGuard Labs analyzed a new TrickBot variant that employs DNS tunneling for command and control communications, modular execution, and incorporates persistence and obfuscation techniques to evade detection and maintain presence on infected systems.
UAT-11795 Deploys Starland RAT and WLDR Agent via Trojanized Software
2 rules 6 TTPsUAT-11795, a sophisticated and financially motivated Russian-speaking threat actor, targets users in the U.S. and Europe with trojanized software installers to deploy custom Python-based Starland RAT and an in-memory PowerShell WLDR agent for credential theft and cryptocurrency exfiltration.
HelloNet Campaign Uses ViPNet Update System for Malicious Module Delivery
3 rules 11 TTPs 1 IOCAn unknown sophisticated threat actor is leveraging DLL sideloading within the ViPNet update system to deploy a multi-stage malware suite, including HelloInjector, HelloProxy, HelloExecutor, HelloCleaner, and HelloBackdoor, to establish persistence, exfiltrate data, and maintain covert access to large Russian organizations in government, energy, and other critical sectors.
Linux C2 Agent Activity: Suspicious Network Connection and File Creation
2 rules 2 TTPsThreat actors leverage C2 agents like Poseidon and Athena, operating from suspicious Linux writable directories, to establish network connections with C2 frameworks such as Mythic, subsequently creating files to stage further malicious activities.
Windows DNS Query to Telegram Bot API Indicating Malware C2
1 rule 2 TTPs 1 IOCThis brief details the detection of suspicious DNS queries from non-Telegram processes to api.telegram.org on Windows systems, a strong indicator of malware utilizing the Telegram Bot API for command and control (C2) communications to receive commands or exfiltrate data.
Suspicious Process DNS Queries to Discord
1 rule 1 TTP 2 IOCsThis brief identifies a detection for non-legitimate processes making DNS queries to Discord domains, indicating potential malware attempting to download additional payloads, as seen in campaigns like WhisperGate, leading to further code execution and system compromise.
China-Nexus Campaign Using Google Calendar as C2
2 rules 4 TTPsA China-nexus threat actor is utilizing Google Calendar as a command and control (C2) infrastructure to conduct stealthy operations.
Iranian Botnet Operation Exposed via Open Directory
1 rule 1 TTP 1 IOCAn Iranian botnet operation utilizing a 15-node relay network and active C2 infrastructure was exposed through an open directory.
MuddyWater PowGoop Beacon Decoding Detection
2 rules 4 TTPsThis detection identifies a DLL decoding and executing the PowGoop config.txt payload, indicating a stage in the MuddyWater infection chain where an obfuscated PowerShell beacon is unwrapped and live C2 communication starts.
Suspicious DNS Queries to Telegram Bot API
2 rules 2 TTPs 1 IOCDetection of DNS queries to api.telegram.org by processes other than telegram.exe indicates potential command and control communication via Telegram bots, a technique leveraged by malware to establish covert communication channels.