VShell Command-and-Control Listener
A command-and-control listener found running on the attacker's staging server alongside the Hermes agent tooling.
A command-and-control listener found running on the attacker's staging server alongside the Hermes agent tooling.
The ENCFORGE campaign used GCP command-and-control servers. The operator tracked the host as a GCP target with task IDs gcp_h1 and gcp_test.
Group-IB has discovered a new espionage implant named HollowGraph that hijacks Microsoft 365 calendars for command-and-control (C2) and data exfiltration. The malware,…
Daxin (srt64.sys) is a kernel-mode rootkit first documented by Symantec in March 2022, used in targeted attacks since 2013. It monitors incoming…
TencShell is a known C2 infrastructure used by suspected China-linked threat actors. Hunt.io observed an open directory sharing identical HTTP header fingerprints…
TuxBot v3 Evolution is a modular IoT botnet framework with C-based bot agent, Go-based C2 server, custom exploit VM, and Docker test…
Version 8.14.0 of the jscrambler npm package, published on July 11, 2026, shipped with a malicious preinstall hook that silently drops and…
The China-linked cybercrime group Silver Fox has been attributed to a new Rust-based remote access trojan (RAT) called MODBEACON. Chinese cybersecurity company…
MODBEACON is a Rust-based RAT using gRPC streaming for encrypted C2 communication. It is memory-resident, modular, and uses Xray/V2Ray transport layer. Capabilities…
LONGLEASH is a full-fledged backdoor framework developed by Chinese APT UAT-7810 as a successor to ShortLeash. It includes an executor component that…