Skip to main content

Threats Tagged 'c2 server'

View all threats tagged with 'c2 server'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: c2 server

Threats Tagged 'c2 server'

Click on any threat for detailed analysis and mitigation recommendations

A sophisticated attack chain was uncovered involving a malicious disk-cleaning utility that installed proxyware on a compromised system. The infection used PowerShell scripts, download cradles, and in-memory execution to evade detection and establish a connection to a command-and-control (C2) server. The attack was intercepted before the proxyware installation completed. This incident underscores the dangers of unauthorized software installations and the critical need to restrict PowerShell usage in corporate environments. The threat leverages multiple advanced techniques including obfuscation, living-off-the-land binaries, and scheduled task abuse. Although no known exploits are currently in the wild, the attack demonstrates a medium severity risk due to its potential for stealthy persistence and resource abuse. European organizations should be vigilant, especially those with lax software installation policies and insufficient PowerShell controls.

Join the discussion
0

A critical vulnerability named DanaBleed was discovered in DanaBot's C2 server, causing memory leaks from June 2022 to early 2025. This bug, introduced in version 2380, exposed sensitive information including threat actor details, server data, and victim credentials. The leak resulted from uninitialized memory in the C2 protocol update. Researchers gained insights into DanaBot's operations, infrastructure, and affiliates. In May 2025, law enforcement dismantled DanaBot's infrastructure and indicted 16 individuals in Operation Endgame. The blog details the technical analysis of the vulnerability, its impact, and the type of data exposed through the memory leak.

Join the discussion

Showing 1 to 2 of 2 results

Filters:Tag: c2 server
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses