Skip to main content
← All Articles

Tag

#C2

13 articles

Advertisement

MA
HIGH
Malware

HollowGraph Malware Uses Microsoft Graph for Stealthy C2

HollowGraph malware leverages Microsoft Graph API calendar features for covert command-and-control and data exfiltration from Microsoft 365 environments.

Runtime Rebel Intel
4 min read·Jul 20, 2026
HollowGraph Malware Leverages Microsoft 365 Calendar for Stealthy C2
HIGH
Malware

HollowGraph Malware Leverages Microsoft 365 Calendar for Stealthy C2

HollowGraph, a new espionage malware, hides C2 commands and exfiltrates data via legitimate Microsoft 365 calendar events, mimicking normal Graph API traffic.

Runtime Rebel Intel
5 min read·Jul 20, 2026
MODBEACON RAT: Silver Fox Uses gRPC for Stealthy C2
HIGH
Malware

MODBEACON RAT: Silver Fox Uses gRPC for Stealthy C2

A new Rust-based MODBEACON RAT, linked to the Silver Fox cybercrime group, employs gRPC streaming for encrypted C2, propagated via SEO poisoning.

Runtime Rebel Intel
5 min read·Jul 10, 2026
TH
HIGH
Threat Intel

Google Disrupts NetNut Malicious Residential Proxy Network

Google, in coordination with the FBI and Lumen, has significantly disrupted the NetNut residential proxy network, impacting millions of compromised devices.

Runtime Rebel Intel
4 min read·Jul 3, 2026
Mustang Panda Exploits Zoho WorkDrive for C2 in Indian Govt Attacks
CRITICAL
Threat Intel

Mustang Panda Exploits Zoho WorkDrive for C2 in Indian Govt Attacks

Mustang Panda, a China-aligned APT, targets Indian government and hydropower entities, leveraging Zoho WorkDrive as a C2 channel and deploying new malware.

Runtime Rebel Intel
4 min read·Jun 29, 2026
TH
CRITICAL
Threat Intel

GopherWhisper APT Abuses Outlook and Slack for Stealthy C2

Newly discovered GopherWhisper APT group uses a Go-based toolkit and legitimate SaaS platforms like Slack and Outlook to conduct espionage against governments.

Runtime Rebel Intel
3 min read·Apr 23, 2026
SystemBC C2 Analysis: 1,570 Victims of The Gentlemen Ransomware
HIGH
Threat Intel

SystemBC C2 Analysis: 1,570 Victims of The Gentlemen Ransomware

Analysis of a SystemBC C2 server linked to The Gentlemen ransomware reveals over 1,570 victims and the use of SOCKS5 tunnels for persistent access.

Runtime Rebel Intel
3 min read·Apr 21, 2026
Emoji-Based C2: Threat Actors Adopt Covert Communication Tactics
MEDIUM
Threat Intel

Emoji-Based C2: Threat Actors Adopt Covert Communication Tactics

Threat actors are increasingly using emojis for covert Command and Control communications to evade security filters. Learn how to detect these obfuscated TTPs.

Runtime Rebel Intel
4 min read·Apr 9, 2026
SnappyClient C2 Implant Targets Crypto Wallets for Data Theft
HIGH
Malware

SnappyClient C2 Implant Targets Crypto Wallets for Data Theft

A new C2 implant, SnappyClient, is actively targeting crypto wallets, facilitating remote access, extensive data theft, and persistent spying on victims.

Runtime Rebel Intel
5 min read·Mar 19, 2026
Tag Poisoning Compromises Xygeni GitHub Action, C2 Implant Active
HIGH
Supply Chain

Tag Poisoning Compromises Xygeni GitHub Action, C2 Implant Active

Attackers compromised the `xygeni/xygeni-action` GitHub Action using tag poisoning, deploying a C2 implant for up to a week. Users must verify integrity and review logs.

Runtime Rebel Intel
4 min read·Mar 12, 2026
North Korean Malicious npm Packages: Detecting Contagious Interview
HIGH
Supply Chain

North Korean Malicious npm Packages: Detecting Contagious Interview

North Korean actors published 26 malicious npm packages using Pastebin as a C2 dead drop resolver in a new Contagious Interview campaign iteration.

Runtime Rebel Intel
3 min read·Mar 2, 2026
TH
CRITICAL
Threat Intel

GRIDTIDE Espionage: PRC-Nexus UNC2814 Targets Telecoms Globally

Google disrupts GRIDTIDE, a novel backdoor used by PRC-nexus UNC2814 for global cyber espionage against telecommunications and government entities.

Runtime Rebel Intel
5 min read·Feb 25, 2026