Tag: command-and-control (C2)

GlassWorm Malware Takedown Disrupts Developer Supply Chain Attack Infrastructure
News

GlassWorm Malware Takedown Disrupts Developer Supply Chain Attack Infrastructure

The simultaneous shutdown of all command-and-control (C2) channels connected to GlassWorm, a persistent software chain campaign that targets software developers through malicious packages and extensions, has been announced by CrowdStrike in collaboration with Google and the Shadowserver Foundation. Software developers, who have access to source code repositories, cloud platforms, CI/CD pipelines, and package registries, have been the focus of GlassWorm operators since at least early 2025, according to CrowdStrike. The development coincides with developers becoming more and more lucrative targets for software supply chain attacks, which allow attackers to utilize a single compromised workstation to simultaneously affect thousands of users and downstream firms. Since its debut last...
DPRK-Linked Hackers Use GitHub as C2 in Multi-Stage Attacks Targeting South Korea
News

DPRK-Linked Hackers Use GitHub as C2 in Multi-Stage Attacks Targeting South Korea

GitHub has been seen to be used as command-and-control (C2) infrastructure by threat actors most likely connected to the Democratic People's Republic of Korea (DPRK) in multi-stage operations against South Korean companies. According to Fortinet FortiGuard Labs, the attack chain consists of obfuscated Windows shortcut (LNK) files that serve as the beginning point for dropping a PowerShell script that prepares the assault's subsequent phase and a decoy PDF document. It has been determined that phishing emails are used to disseminate these LNK files. The malicious PowerShell script runs quietly in the background while the victim is shown the PDF document as soon as the payloads are downloaded. The PowerShell script scans for active processes associated with virtual machines, debuggers...
Aeternum C2 Botnet Stores Encrypted Commands on Polygon Blockchain to Evade Takedown
News

Aeternum C2 Botnet Stores Encrypted Commands on Polygon Blockchain to Evade Takedown

Aeternum C2, a new botnet loader that use a blockchain-based command-and-control (C2) infrastructure to make it resistant to takedown attempts, has been revealed by cybersecurity researchers. According to a study provided with The Hacker News by Qrator Labs, Aeternum maintains its instructions on the public Polygon blockchain rather than using conventional servers or domains for command-and-control. Decentralized applications like Polymarket, the biggest prediction market in the world, make extensive use of this network. Aeternum's C2 infrastructure is essentially permanent and impervious to conventional takedown techniques because to this strategy. Botnets that use blockchain for C2 have been discovered previously. Google claimed to have taken action in 2021 to stop the Glupteba...
NANOREMOTE Malware Uses Google Drive API for Hidden Control on Windows Systems
News

NANOREMOTE Malware Uses Google Drive API for Hidden Control on Windows Systems

Cybersecurity researchers have revealed information about NANOREMOTE, a brand-new, fully functional Windows backdoor that employs the Google Drive API for command-and-control (C2) functions. A report from Elastic Security Labs claims that the malware's code is comparable to that of another implant called FINALDRAFT (also known as Squidoor), which uses the Microsoft Graph API for C2. FINALDRAFT is linked to the REF7707 threat cluster (also known as CL-STA-0049, Earth Alux, and Jewelbug). According to Daniel Stepanic, chief security researcher at Elastic Security Labs, one of the main characteristics of the malware is its ability to transfer data back and forth from the victim endpoint via the Google Drive API. In the end, this feature creates a difficult-to-detect conduit for payl...
Russian Ransomware Gangs Weaponize Open-Source AdaptixC2 for Advanced Attacks
News

Russian Ransomware Gangs Weaponize Open-Source AdaptixC2 for Advanced Attacks

Threat actors are increasingly using the open-source command-and-control (C2) framework called AdaptixC2, some of which have ties to Russian ransomware gangs. A new extendable post-exploitation and adversarial emulation system for penetration testing is called AdaptixC2. The GUI client is written in C++ QT for cross-platform compatibility, while the server component is written in Golang. Among its many features are command execution, credential and screenshot managers, a remote terminal, and completely encrypted communications. The GitHub user "RalfHacker" (@HackerRalf on X), who identifies himself a penetration tester, red team operator, and "MalDev" (short for malware developer), made an early version available to the public in August 2024. A number of hacker organizations have...
Researchers Identify PassiveNeuron APT Using Neursite and NeuralExecutor Malware
News

Researchers Identify PassiveNeuron APT Using Neursite and NeuralExecutor Malware

According to Kaspersky, a new campaign called PassiveNeuron is aimed at government, financial, and industrial entities in Asia, Africa, and Latin America. The Russian cybersecurity provider initially discovered the cyber espionage operation in November 2024 when it revealed a series of attacks targeting government organizations in East Asia and Latin America in June that used previously unheard-of malware families known as Neursite and NeuralExecutor. Additionally, it stated that the operation was highly sophisticated and that the threat actors used internal servers that had already been compromised as an intermediary command-and-control (C2) infrastructure in order to evade detection. According to Kaspersky at the time, the threat actor can travel laterally through the infrastru...
Fake Nethereum NuGet Package Used Homoglyph Trick to Steal Crypto Wallet Keys
News

Fake Nethereum NuGet Package Used Homoglyph Trick to Steal Crypto Wallet Keys

Researchers studying cybersecurity have discovered a new supply chain attack that uses malicious typosquats of Nethereum, a well-known Ethereum.NET integration platform, to target the NuGet package management and steal the cryptocurrency wallet keys of its victims. Security firm Socket has discovered that the package Nethereum.All contains the ability to decode a command-and-control (C2) endpoint and exfiltrate private keys, keystore data, and mnemonic phrases. On October 16, 2025, a person going by the moniker "nethereumgroup" uploaded the library. Four days later, it was removed from NuGet due to a violation of the service's Terms of Use. The NuGet package is noteworthy for tricking unwary developers into downloading it by substituting the Cyrillic homoglyph read more about Fak...
New GodRAT Trojan Targets Trading Firms Using Steganography and Gh0st RAT Code
News

New GodRAT Trojan Targets Trading Firms Using Steganography and Gh0st RAT Code

A recent effort targets financial institutions, such as trading and brokerage firms, by distributing GodRAT, a remote access trojan that has not been previously identified. In a technical study released today, Kaspersky researcher Saurabh Sharma said that the malicious activity entails the "distribution of malicious.SCR (screen saver) files disguised as financial documents via Skype messenger." The assaults use a method known as steganography to hide the shellcode needed to download the malware from a command-and-control (C2) server within image files. They have been active as recently as August 12, 2025. Since September 9, 2024, the screen saver artifacts have been identified, focusing on nations and territories such as Hong Kong, the United Arab Emirates, Malaysia, Jordan, and Leb...
Apache ActiveMQ Flaw Exploited to Deploy DripDropper Malware on Cloud Linux Systems
News

Apache ActiveMQ Flaw Exploited to Deploy DripDropper Malware on Cloud Linux Systems

Threat actors are gaining permanent access to cloud Linux servers and distributing malware known as DripDropper by taking advantage of a security hole in Apache ActiveMQ that has existed for almost two years. However, in a surprising turn of events, Red Canary reported to The Hacker News that the unidentified attackers had been seen patching the exploited vulnerability after gaining initial access in order to avoid notice and stop additional exploitation by other adversaries. According to researchers Christina Johns, Chris Brook, and Tyler Edmonds, follow-on adversary command-and-control (C2) techniques differed depending on the endpoint and included Sliver and Cloudflare Tunnels to sustain long-term covert command and control. The attacks take advantage of a remote code executio...
Malicious PyPI and npm Packages Discovered Exploiting Dependencies in Supply Chain Attacks
News

Malicious PyPI and npm Packages Discovered Exploiting Dependencies in Supply Chain Attacks

A malicious package that adds malicious behavior through a dependency that enables it to establish persistence and accomplish code execution has been found by cybersecurity experts in the Python Package Index (PyPI) repository. According to Zscaler ThreatLabz, the program, dubbed termncolor, uses a multi-stage malware operation to actualize its malicious capability through a dependent package called colorinal. Colorinal received 529 downloads, compared to 355 for termncolor. On PyPI, both libraries are no longer accessible. According to researchers Manisha Ramcharan Prajapati and Satyam Singh, this attack may use DLL side-loading to enable decryption, create persistence, and carry out command-and-control (C2) communication, ultimately leading to remote code execution. Following i...