Tag: c2
All the articles with the tag "c2".
-
The Party Invite That Wasn't: Anatomy of a ScreenConnect Phishing Campaign
A fake e-vite, a compromised sender you actually trust, and a remote access tool that never should have been installed. Six devices, one campaign, and the logical inconsistency that gave it away.
-
Poisoned at the Source
Someone shared an interesting article. A colleague forwarded it. Three managed devices got wiped before the week was out.
-
The Midnight Beachhead: A Real-World RCE Incident on a University Network
Shortly after midnight, an attacker exploited a known vulnerability in a web-facing server at one of our international campus locations. This is what happened next.
-
Sinkhole, Bursts, and a 142-Minute Retry Timer: Reading C2 Behavior in the Logs
A phishing click led to fixed-size C2 check-ins arriving in two distinct bursts with a 142-minute gap between them. The pattern told the story before we had a verdict.