Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Detect ICMP-Ghost Implant ICMP and DNS Tunnelling C2 Traffic Using PacketSmith Yara-X & ICMP Detection Modules

0
Medium
Published: 08/14/2026 (08/14/2026, 14:42:27 UTC)
Source: Reddit BlueTeam

Description

ICMP-Ghost is an open-source tunnelling framework that uses ICMP and DNS protocols for command and control (C2) communication. It is designed in x64 assembly and claims to evade endpoint detection and network intrusion detection systems. The framework supports dual-channel C2 with the ability to switch between ICMPv4 and DNS tunnelling on the fly. Detection rules using PacketSmith Yara-X modules have been developed to identify traffic generated by this framework.

Reddit Discussion

r/blueteamsec·posted by u/MFMokbel
00

https://blog.netomize.ca/detect-icmp-ghost-implant-icmp-and-dns-tunnelling-c2-traffic-using-packetsmith-yara-x-icmp-detection-modules

ICMP-Ghost is an open-source tunnelling framework written in pure x64 assembly. What stands out about this framework, compared to other closed- and open-source ones, is the author's claims about its EDR evasion and Suricata IDS/IPS evasion capabilities. The framework supports a dual-channel C2 architecture (despite the exclusivity of the "ICMP" in the framework title), including ICMPv4 and DNS, with the ability to switch between them on the fly. The author makes some grandiose claims about its architecture and design with respect to performance, efficiency, endpoint and network evasion, and memory footprint.

Despite the author's claims, in this article, we detail the structures of each of the C2 protocols, along with PacketSmith Yara-X detection module rules for detecting the traffic of both C2 channels.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/14/2026, 15:56:47 UTC

Technical Analysis

ICMP-Ghost is a dual-channel C2 tunnelling framework implemented in pure x64 assembly, utilizing ICMPv4 and DNS protocols for covert communication. The author claims advanced evasion capabilities against EDR and Suricata IDS/IPS. Despite these claims, the article provides detailed protocol structures and detection rules using PacketSmith Yara-X modules to detect the ICMP and DNS tunnelling traffic generated by ICMP-Ghost. This detection approach enables defenders to identify and mitigate the presence of this implant in their networks.

Potential Impact

The framework enables covert command and control communication using ICMP and DNS tunnelling, potentially allowing attackers to maintain stealthy control over compromised systems. Its evasion claims, if accurate, could hinder detection by common endpoint and network security tools, increasing the risk of prolonged undetected intrusion.

Defensive Guidance

Detection rules using PacketSmith Yara-X and ICMP detection modules are available to identify ICMP-Ghost C2 traffic. Organizations should deploy these detection capabilities to monitor for and respond to such covert channels. No official patches or vendor advisories exist since this is an open-source framework rather than a software vulnerability. Standard network monitoring focused on ICMP and DNS tunnelling traffic patterns is recommended.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Source Type
reddit
Subreddit
blueteamsec+AskNetsec+Information_Security
Reddit Score
0
Discussion Level
minimal
Content Source
reddit_link_post
Post Type
link
Domain
null
Newsworthiness Assessment
{"score":38,"reasons":["external_link","newsworthy_keywords:yara","established_author","recent_news"],"isNewsworthy":true,"foundNewsworthy":["yara"],"foundNonNewsworthy":[]}
Has External Source
true
Trusted Domain
false

Threat ID: 6a7f3ab8bf8831d5394fa09a

Added to database: 08/14/2026, 15:56:40 UTC

Last enriched: 08/14/2026, 15:56:47 UTC

Last updated: 08/14/2026, 18:41:09 UTC

Views: 4

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses