Threats Tagged 'c2 infrastructure'
View all threats tagged with 'c2 infrastructure'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'c2 infrastructure'
Click on any threat for detailed analysis and mitigation recommendations
0 A misconfigured open directory on IP 86.53.111.212:8080 exposed the Moobot botnet source code, DDoS tools, and fraudulent services linked to an active cybercrime operation. The exposed data included StresD Pro+, a multi-user DDoS panel with multiple registered accounts and recorded attacks. Analysis of the Moobot source code revealed a dormant download-and-execute feature likely used by APT28 to deploy malware. Despite a 2024 court-authorized disruption, Moobot remains active as of August 2026, with ongoing DDoS attacks consistent with DDoS-as-a-service activity. Join the discussion | AlienVault OTX General | 08/28/2026, 02:25:31 UTC Added: 08/28/2026, 08:52:30 UTC |
On 5 May 2026, a Jamf Protect deployment blocked a download attempt from jacksonvillemma[.]com, four days after the operator's previous MacSync C2 was publicly disclosed. The new C2's TLS certificate was issued within 24 hours of that disclosure. Analysis revealed a Stage 2 zsh loader containing a static api-key value observed across four distinct C2 domains spanning December 2025 to May 2026. URI-pattern pivoting through any.run identified eleven additional candidate C2 domains dating back to February 2026, suggesting parallel infrastructure operation rather than sequential rotation. The loader exfiltrates macOS credentials, browser data, and cryptocurrency wallets, and transmits the victim's account password in cleartext via URL query strings, making it visible in web proxy logs. Join the discussion | AlienVault OTX General | 08/18/2026, 20:05:15 UTC Added: 08/19/2026, 15:22:26 UTC |
A massive campaign distributes malicious installer archives hosted on spoofed websites masquerading as popular software like OBS Studio, DNS Jumper, DS4Windows, and Bandicam. Over 90 domain names localized across 10 languages were discovered. The malicious archives bundle a legitimate Microsoft-signed install.exe binary with a rogue install.res.1033.dll library deployed via DLL sideloading. This installs the ScreenConnect remote access service, which then deploys AsyncRAT payloads through PowerShell and VBS scripts. The threat actors leverage SEO techniques to position fraudulent sites at the top of search engine results, targeting both individual users and corporate networks. The infrastructure spans three IP addresses with domains registered between October 2025 and March 2026, creating a global footprint with multi-language support. Join the discussion | AlienVault OTX General | 07/01/2026, 16:52:43 UTC Added: 07/02/2026, 07:06:43 UTC |
Recent activity has been detected linked to the Sidewinder advanced persistent threat group. The campaign utilizes a malicious document named No.9374.docx with the hash value 64f2681ad0940e6c2c9c76e6834117bf as a lure mechanism. The infrastructure supporting command and control operations includes the domain update[.]ms-office[.]app. This observation indicates ongoing operations by Sidewinder, a threat actor known for targeting specific regions and sectors. The use of weaponized documents and deceptive domains mimicking legitimate Microsoft services demonstrates continued sophisticated social engineering tactics employed by this group. Join the discussion | AlienVault OTX General | 06/24/2026, 03:26:21 UTC Added: 06/24/2026, 17:24:12 UTC |
Kazuar is a sophisticated malware attributed to Russian state actor Secret Blizzard, having evolved from a traditional backdoor into a highly modular peer-to-peer botnet ecosystem. The malware comprises three distinct module types—Kernel, Bridge, and Worker—that distribute functionality across infected systems. A leadership election mechanism ensures only one Kernel module communicates externally, reducing detection opportunities. The architecture supports flexible configuration with over 150 options, multiple C2 channels including HTTP, WebSockets, and Exchange Web Services, and extensive data collection capabilities. Secret Blizzard primarily targets government, diplomatic, and defense organizations in Europe, Central Asia, and Ukraine to support Russian foreign policy and military intelligence objectives. The botnet maintains persistent access through sophisticated IPC mechanisms, staged data exfiltration during working hours, and comprehensive anti-analysis checks. Join the discussion | AlienVault OTX General | 05/14/2026, 20:10:32 UTC Added: 05/15/2026, 18:51:38 UTC |
GhostSocks is an emerging threat that turns compromised devices into residential proxy nodes, enabling attackers to evade detection. Originally marketed on Russian underground forums as Malware-as-a-Service, it has gained popularity due to its partnership with Lumma Stealer. Written in GoLang, GhostSocks uses SOCKS5 proxy protocol and TLS encryption to blend malicious traffic into normal network activity. It also incorporates backdoor functionality for running arbitrary commands and deploying additional payloads. Darktrace observed an increase in GhostSocks activity, detecting it alongside Lumma Stealer in customer networks. The malware's versatility in converting devices into proxy nodes while enabling covert network access illustrates how threat actors maximize the value of compromised infrastructure. Join the discussion | AlienVault OTX General | 03/31/2026, 16:14:29 UTC Added: 03/31/2026, 18:53:15 UTC |
A new malware-as-a-service (MaaS) called TrustConnect has been discovered masquerading as a legitimate remote monitoring and management (RMM) tool. The malware, classified as a remote access trojan (RAT), uses a fake business website as its command and control center and MaaS portal. Priced at $300 per month, it offers features like a web-based C2 dashboard, automated payload generation with digital signatures, and remote desktop capabilities. The malware has been distributed through various email campaigns, often alongside legitimate RMM tools. Proofpoint researchers identified links between TrustConnect's creator and previous users of Redline stealer. The emergence of this new MaaS demonstrates the ongoing evolution of the cybercrime market and the thriving ecosystem of RMM abuse. Join the discussion | AlienVault OTX General | 02/19/2026, 11:10:29 UTC Added: 02/19/2026, 12:50:31 UTC |
A suspected state-affiliated threat actor has been targeting Kazakh and Afghan entities in a persistent campaign since at least August 2022. The attackers use a Windows-based RAT called KazakRAT, which allows for payload downloads, host data collection, and file exfiltration. The malware is delivered via .msi files and persists using the Run registry key. C2 communications are unencrypted over HTTP. The campaign also utilizes modified versions of XploitSpy Android spyware. Multiple KazakRAT variants have been observed with minor command-set changes. Victim targeting includes government and financial sector entities, particularly in Kazakhstan's Karaganda region. The operation shows low sophistication but high persistence, with similarities to APT36/Transparent Tribe activities. Join the discussion | AlienVault OTX General | 01/30/2026, 08:19:02 UTC Added: 01/30/2026, 08:43:08 UTC |
A sophisticated phishing campaign targeting macOS users employs a technique called Clickfix, which tricks victims into running terminal commands that execute malicious AppleScript. This script steals sensitive data including browser profiles, crypto wallets, and personal files. The attackers use fake security prompts and CAPTCHA pages on domains like cryptoinfo-news.com to appear legitimate. The stolen data is exfiltrated to command and control servers, some of which run on unusual ports. The campaign's infrastructure spans multiple regions, with several C2 servers hosted in Russia. The analysis uncovered over 50 related servers with similar configurations, suggesting a financially motivated and globally distributed operation. Join the discussion | AlienVault OTX General | 08/22/2025, 17:35:47 UTC Added: 08/25/2025, 11:17:38 UTC |
Multiple samples of SpyNote, a sophisticated Android spyware, were discovered in open directories, disguised as legitimate apps like Google Translate, Temp Mail, and Deutsche Postbank. The malware exploits accessibility services and device administrator privileges to steal sensitive information from infected devices. Samples were found on various servers, including AWS and SonderCloud Limited, with different command and control (C2) infrastructures. The discovery highlights the ongoing threat of SpyNote, especially after its source code leak in late 2022, and emphasizes the importance of proactive threat detection and analysis. Join the discussion | AlienVault OTX General | 06/20/2025, 19:26:02 UTC Added: 06/21/2025, 10:50:19 UTC |
Showing 1 to 10 of 12 results