Skip to content
Threat Feed

Tag

C2

13 briefs RSS
high advisory

Suspicious Windows Public IP Address Discovery via DNS

Adversaries frequently use public IP lookup services to perform network reconnaissance and verify egress connectivity prior to establishing C2 channels, a behavior detectable via DNS query analysis from suspicious processes.

discovery c2 windows reconnaissance
1r 1t 33i
high advisory

Web Server Outbound Connections to File Sharing Services

Attackers compromise web servers (Apache, Nginx, Tomcat, PHP) and leverage them to make unexpected outbound network connections to public file-sharing or content hosting services, indicating post-exploitation activity for ingress tool transfer and further compromise.

Apache HTTP Server +3 post-exploitation ingress-tool-transfer webshell web-server c2 windows
1r 2t 26i
medium advisory

Windows DNS Query Request by Telegram Bot API

An analytic detects DNS queries to `api.telegram.org` originating from non-Telegram processes on Windows systems, indicating potential malware command and control (C2) communication or data exfiltration via the Telegram Bot API.

command-and-control malware windows c2 dns telegram
1r 2t 1i
high threat

TrickBot Variant Utilizes DNS Tunneling for Command and Control

FortiGuard Labs analyzed a new TrickBot variant that employs DNS tunneling for command and control communications, modular execution, and incorporates persistence and obfuscation techniques to evade detection and maintain presence on infected systems.

TrickBot malware banking-trojan dns-tunneling c2 persistence obfuscation
4t
high threat

UAT-11795 Deploys Starland RAT and WLDR Agent via Trojanized Software

UAT-11795, a sophisticated and financially motivated Russian-speaking threat actor, targets users in the U.S. and Europe with trojanized software installers to deploy custom Python-based Starland RAT and an in-memory PowerShell WLDR agent for credential theft and cryptocurrency exfiltration.

exploited Webex +2 UAT-11795 financially-motivated rat c2 trojan windows python powershell
2r 6t
high advisory

HelloNet Campaign Uses ViPNet Update System for Malicious Module Delivery

An unknown sophisticated threat actor is leveraging DLL sideloading within the ViPNet update system to deploy a multi-stage malware suite, including HelloInjector, HelloProxy, HelloExecutor, HelloCleaner, and HelloBackdoor, to establish persistence, exfiltrate data, and maintain covert access to large Russian organizations in government, energy, and other critical sectors.

ViPNet Update System apt dll-sideloading persistence proxy c2 reconnaissance data-exfiltration russia +1
3r 11t 1i
low advisory

Linux C2 Agent Activity: Suspicious Network Connection and File Creation

Threat actors leverage C2 agents like Poseidon and Athena, operating from suspicious Linux writable directories, to establish network connections with C2 frameworks such as Mythic, subsequently creating files to stage further malicious activities.

linux command-and-control execution malware c2 threat-detection
2r 2t
high advisory

Windows DNS Query to Telegram Bot API Indicating Malware C2

This brief details the detection of suspicious DNS queries from non-Telegram processes to api.telegram.org on Windows systems, a strong indicator of malware utilizing the Telegram Bot API for command and control (C2) communications to receive commands or exfiltrate data.

Telegram Bot API network command-and-control c2 telegram windows malware
1r 2t 1i
high advisory

Suspicious Process DNS Queries to Discord

This brief identifies a detection for non-legitimate processes making DNS queries to Discord domains, indicating potential malware attempting to download additional payloads, as seen in campaigns like WhisperGate, leading to further code execution and system compromise.

malware c2 initial-access execution windows
1r 1t 2i
high threat

China-Nexus Campaign Using Google Calendar as C2

A China-nexus threat actor is utilizing Google Calendar as a command and control (C2) infrastructure to conduct stealthy operations.

China-nexus actor google-calendar c2 china-nexus
2r 4t
medium advisory

Iranian Botnet Operation Exposed via Open Directory

An Iranian botnet operation utilizing a 15-node relay network and active C2 infrastructure was exposed through an open directory.

botnet iran C2
1r 1t 1i
high threat

MuddyWater PowGoop Beacon Decoding Detection

This detection identifies a DLL decoding and executing the PowGoop config.txt payload, indicating a stage in the MuddyWater infection chain where an obfuscated PowerShell beacon is unwrapped and live C2 communication starts.

Splunk Enterprise +3 MuddyWater powgoop dll-sideloading powershell c2 beacon
2r 4t
high advisory

Suspicious DNS Queries to Telegram Bot API

Detection of DNS queries to api.telegram.org by processes other than telegram.exe indicates potential command and control communication via Telegram bots, a technique leveraged by malware to establish covert communication channels.

Telegram Bot API telegram bot c2 command-and-control dns
2r 2t 1i