s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-ps1.phonyc2

📛 Threat Title

Malware family: PhonyC2

Category: PhonyC2 First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `ps1.phonyc2`. Printable name: PhonyC2.

Indicators of Compromise (0)

No indicators of compromise on this threat.

References (1)

Remediations (10)

  • web:apt.etda.or.th

    Tool: PhonyC2 ... Last change to this tool card: 13 October 2023 Download this tool card in JSON format

  • web:github.com

    This repository contains the source code of the PhonyC2 and MuddyC2, a custom-made command and control (C2) framework used by the MuddyWater threat group.

  • web:main.whoisxmlapi.com

    WhoisXML API found 400+ artifacts that could be closely tied to MuddyWater's PhonyC2 framework and DEV-1084 partnership. Download the threat research materials now.

  • web:social.cyware.com

    The Iranian state-sponsored group dubbed MuddyWater has been attributed to a previously unseen command-and-control (C2) framework called PhonyC2 that's been put to use by the actor since 2021. Evidence shows that the custom made, actively developed framework has been leveraged in the February 2023 attack on Technion, an Israeli research institute, cybersecurity firm Deep Instinct said in a ...

  • web:vulners.com

    The Iranian state-sponsored group dubbed **MuddyWater **has been attributed to a previously unseen command-and-control (C2) framework called PhonyC2 that's been put to use by the actor since 2021. Evidence shows that the custom made, actively develo...

  • web:www.linkedin.com

    Check out the latest from Deep Instinct's Threat Research team - Dubbed PhonyC2 , a new C2 (command & control) has been used by the MuddyWater group since at least 2021. PhonyC2 is similar to ...

  • web:www.reddit.com

    At r/purpleteamsec, we believe that when Red and Blue teams unite, security becomes not just a goal but a shared journey. Join us today to connect, learn, and collaborate in the pursuit of a safer digital world. Your insights, experiences, and questions are all welcome here. Let's harness the power of Purple Teaming and protect what matters most! Remember, the future of cybersecurity is Purple ...

  • web:www.redpacketsecurity.com

    The Iranian state-sponsored group dubbed MuddyWater has been attributed to a previously unseen command-and-control (C2) framework called PhonyC2 that's been put to use by the actor since 2021. Evidence shows that the custom made, actively developed framework has been leveraged in the February 2023 attack on Technion, an Israeli research institute, cybersecurity firm Deep Instinct said in a ...

  • web:www.scworld.com

    Attacks by Iranian state-backed threat group MuddyWater, also known as Mango Sandstorm and Mercury, against Israeli research institute Technion, as well as PaperCut servers have involved the utilization of the PhonyC2 post-exploitation command-and-control framework.

  • web:www.zolentz.com

    In April 2023, Deep Instinct found the PhonyC2 framework on a server linked to MuddyWater's broader infrastructure used in the Technion attack this year. PhonyC2 , the latest version, is written in Python3, sharing structural and functional similarities with Python2-based MuddyC3, a previous custom C2 framework by MuddyWater.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.