Threats Tagged 'c2'
View all threats tagged with 'c2'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'c2'
Click on any threat for detailed analysis and mitigation recommendations
An Iranian threat actor's operational infrastructure was exposed through an open directory, revealing a 15-node relay network spanning Finland and Iran, an SSH-based botnet framework, and an active command and control server. The exposed bash history documented the full operation, including tunnel deployment, DDoS tooling development, and botnet creation. The actor used on-host compilation to evade detection and leveraged a Python script for mass SSH deployment. The botnet client, compiled and renamed 'hex' on infected hosts, showed automatic reconnection capabilities. This operation appears to be financially or personally motivated rather than state-directed, with infrastructure dual-purposed for censorship bypass and attack operations. Join the discussion | AlienVault OTX General | 03/17/2026, 15:07:57 UTC Added: 03/17/2026, 19:27:29 UTC |
MuddyWater APT has launched Operation Olalampo, targeting organizations in the MENA region. The campaign involves new malware variants, including a Rust backdoor called CHAR, downloaders GhostFetch and HTTP_VIP, and an advanced backdoor GhostBackDoor. Notably, the group is using Telegram bots for command-and-control, revealing insights into their post-exploitation tactics. The operation, first observed on January 26, 2026, shows tactical and technical overlaps with previous MuddyWater activities. Key discoveries include potential AI-assisted malware development and infrastructure reuse dating back to October 2025. The campaign aligns with ongoing geopolitical tensions and provides valuable information on the threat actor's evolving techniques. Join the discussion | AlienVault OTX General | 02/23/2026, 10:13:38 UTC Added: 02/23/2026, 10:16:19 UTC |
0 A sophisticated malware campaign targeting macOS users has been discovered, utilizing typosquatted domains impersonating the Homebrew package manager. The attack, dubbed ClickFix, exploits users' trust in command-line installation processes. Victims are tricked into executing malicious curl commands, leading to the deployment of a credential harvester and the Cuckoo Stealer malware. This infostealer establishes persistence through LaunchAgents, bypasses Gatekeeper, and employs encrypted C2 communication. It systematically exfiltrates sensitive data including browser credentials, cryptocurrency wallets, and system information. The campaign's infrastructure spans multiple domains hosted on shared IP addresses, indicating a coordinated and evolving threat. Join the discussion | AlienVault OTX General | 02/19/2026, 15:26:27 UTC Added: 02/19/2026, 18:01:12 UTC |
North Korean threat actors have evolved their techniques in the Contagious Interview campaign, now abusing Microsoft Visual Studio Code task configuration files. The infection chain begins when a victim opens a malicious Git repository, often disguised as part of a recruitment process. If trust is granted, arbitrary commands are executed on the system. The malware uses JavaScript payloads hosted on vercel.app to implement backdoor logic, including remote code execution, system fingerprinting, and persistent command-and-control communication. The backdoor collects host information and beacons to a C2 server every five seconds. Recent observations show further execution of similar payloads, indicating ongoing development of these tactics. Join the discussion | AlienVault OTX General | 01/21/2026, 12:38:22 UTC Added: 01/21/2026, 23:20:55 UTC |
The Sysdig Threat Research Team analyzed VoidLink, a sophisticated Linux malware framework targeting cloud environments. Key findings include the first documented Serverside Rootkit Compilation, Chinese development with AI assistance, adaptive detection evasion, and use of the Zig programming language. VoidLink employs a multi-stage loader architecture, fileless execution techniques, and kernel-level stealth mechanisms. It features three control channels, including a covert ICMP channel, and specialized functionality for cloud and container environments. Despite its sophistication, VoidLink can be detected using runtime monitoring tools. The malware shows indicators of Chinese-speaking developers with significant kernel expertise, likely using AI-assisted development methods. Join the discussion | AlienVault OTX General | 01/19/2026, 09:35:38 UTC Added: 01/19/2026, 09:56:45 UTC |
NotDoor is a backdoor malware leveraging Outlook macros for persistence and lateral movement within compromised environments. It stages files in C:\ProgramData and abuses DLL sideloading via OneDrive.exe to evade detection. The malware executes encoded PowerShell commands, modifies registry keys to enable macros and disable security dialogs, and uses Outlook functions for command-and-control (C2) communication and email monitoring. Detection strategies include monitoring suspicious PowerShell activity, registry changes, and the creation of VbaProject. OTM files by non-Outlook processes. The threat is linked to the APT28 (Fancy Bear) actor and represents a medium-severity risk. European organizations using Microsoft Outlook and OneDrive are potential targets, especially those in critical infrastructure and government sectors. Mitigation requires focused monitoring, macro policy enforcement, and DLL sideloading prevention measures. Join the discussion | AlienVault OTX General | 11/15/2025, 04:44:45 UTC Added: 11/17/2025, 09:32:29 UTC |
GhostSocks is a Malware-as-a-Service (MAAS) that converts compromised devices into residential proxies, enabling threat actors to bypass anti-fraud mechanisms. Introduced in October 2023, it gained popularity after partnering with LummaStealer in February 2024. The malware, coded in Golang, uses obfuscation techniques and can be built as a 32-bit DLL or executable. It doesn't implement persistence mechanisms but focuses on SOCKS5 functionality. GhostSocks uses a configuration file or hardcoded config to connect to C2 servers, randomly generates credentials, and establishes a SOCKS5 connection using open-source libraries. Despite law enforcement actions against related platforms, GhostSocks continues to operate, posing ongoing risks of double victimization and long-term network access for cybercriminals. Join the discussion | AlienVault OTX General | 10/01/2025, 07:39:51 UTC Added: 10/01/2025, 08:49:39 UTC |
ChillyHell is a sophisticated macOS backdoor discovered in 2021 that has evaded detection by antivirus vendors. It is a modular C++ malware targeting Intel architectures, using multiple persistence mechanisms and communication protocols. The backdoor performs host profiling, establishes persistence through LaunchAgents, LaunchDaemons, or shell profile injection, and communicates with command and control servers via DNS or HTTP. ChillyHell's modular structure allows for various capabilities, including reverse shell access, self-updating, payload execution, and local password cracking. The malware's flexibility, stealth techniques, and notarization status make it a significant threat in the macOS landscape. Join the discussion | AlienVault OTX General | 09/10/2025, 16:18:10 UTC Added: 09/10/2025, 19:45:51 UTC |
ZynorRAT is a newly discovered Go-based Remote Access Trojan that provides a full suite of command and control capabilities for Linux and Windows systems. It was first identified in July 2025 and is believed to be of Turkish origin. The malware uses Telegram as its C2 infrastructure and offers features such as file exfiltration, system enumeration, screenshot capture, persistence through systemd services, and arbitrary command execution. The Linux version is fully functional, while the Windows version appears to be in early development. The malware's author seems to be actively working on improving its detection avoidance. ZynorRAT's capabilities include discovery, exfiltration, persistence, and remote code execution on victim machines. Join the discussion | AlienVault OTX General | 09/10/2025, 07:54:45 UTC Added: 09/10/2025, 08:15:15 UTC |
A massive distribution of SmartLoader malware has been discovered through GitHub repositories masquerading as legitimate projects. These repositories focus on topics like game cheats, software cracks, and automation tools to attract users. The malware is distributed via compressed files containing a legitimate Lua loader executable, a malicious batch file, and an obfuscated Lua script. Once executed, SmartLoader establishes persistence, sends system information to a C2 server, and downloads additional payloads. The malware has been observed downloading InfoStealer malware such as Rhadamanthys, Redline, and Lumma Stealer. Users are advised to download software only from official sources and to carefully verify the credibility of GitHub repositories before use. Join the discussion | AlienVault OTX General | 08/13/2025, 15:43:17 UTC Added: 08/13/2025, 15:47:48 UTC |
Showing 1 to 10 of 15 results