#C2
All CosmicBytez Labs articles tagged #C2, across news, security advisories, how-to guides, and projects.
- News
Cavern C2 Uses DNS and Google Apps Script to Blend Into Legitimate Traffic
Iranian nation-state hackers evolved the Cavern C2 framework to tunnel commands through DNS and Google Apps Script, evading detection against Israeli targets.
- News
Chaos Ransomware Uses msaRAT to Route C2 Traffic Through Headless Chrome and Edge
Cisco Talos has detailed msaRAT, a Rust-based implant used by the Chaos ransomware group that hides its command-and-control channel inside the victim's...
- News
msaRAT: Chaos Ransomware's New Backdoor Hides C2 Traffic Inside Chrome and Edge
Cisco Talos has uncovered msaRAT, a Rust-based remote access trojan deployed by the Chaos ransomware group that routes all command-and-control traffic...
- News
Microsoft Teams Relay Servers Abused in DragonForce Ransomware Attack
Security researchers have uncovered a DragonForce ransomware attack deploying a new Go-based backdoor that uses Microsoft Teams relay infrastructure for...
- News
'Underminr' Vulnerability Lets Attackers Hide Malicious
A newly disclosed vulnerability dubbed 'Underminr' affects approximately 88 million domains and enables attackers to bypass DNS filtering tools while...
- News
Tropic Trooper Uses Trojanized SumatraPDF and GitHub to Deploy AdaptixC2
Zscaler ThreatLabz has uncovered a Tropic Trooper (APT23) campaign that delivers the AdaptixC2 post-exploitation beacon via trojanized SumatraPDF...
- News
SSHStalker Linux Botnet Uses IRC Protocol for Command and Control
Security researchers discover a new Linux botnet named SSHStalker that leverages the legacy IRC protocol for C2 operations, marking a return to old-school...