TF-MAL-ps1.phonyc2
📛 Threat Title
Malware family: PhonyC2
Description
ThreatFox malware family `ps1.phonyc2`. Printable name: PhonyC2.
Indicators of Compromise (0)
No indicators of compromise on this threat.
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:apt.etda.or.th
Tool: PhonyC2 ... Last change to this tool card: 13 October 2023 Download this tool card in JSON format
-
web:github.com
This repository contains the source code of the PhonyC2 and MuddyC2, a custom-made command and control (C2) framework used by the MuddyWater threat group.
-
web:main.whoisxmlapi.com
WhoisXML API found 400+ artifacts that could be closely tied to MuddyWater's PhonyC2 framework and DEV-1084 partnership. Download the threat research materials now.
-
web:social.cyware.com
The Iranian state-sponsored group dubbed MuddyWater has been attributed to a previously unseen command-and-control (C2) framework called PhonyC2 that's been put to use by the actor since 2021. Evidence shows that the custom made, actively developed framework has been leveraged in the February 2023 attack on Technion, an Israeli research institute, cybersecurity firm Deep Instinct said in a ...
-
web:vulners.com
The Iranian state-sponsored group dubbed **MuddyWater **has been attributed to a previously unseen command-and-control (C2) framework called PhonyC2 that's been put to use by the actor since 2021. Evidence shows that the custom made, actively develo...
-
web:www.linkedin.com
Check out the latest from Deep Instinct's Threat Research team - Dubbed PhonyC2 , a new C2 (command & control) has been used by the MuddyWater group since at least 2021. PhonyC2 is similar to ...
-
web:www.reddit.com
At r/purpleteamsec, we believe that when Red and Blue teams unite, security becomes not just a goal but a shared journey. Join us today to connect, learn, and collaborate in the pursuit of a safer digital world. Your insights, experiences, and questions are all welcome here. Let's harness the power of Purple Teaming and protect what matters most! Remember, the future of cybersecurity is Purple ...
-
web:www.redpacketsecurity.com
The Iranian state-sponsored group dubbed MuddyWater has been attributed to a previously unseen command-and-control (C2) framework called PhonyC2 that's been put to use by the actor since 2021. Evidence shows that the custom made, actively developed framework has been leveraged in the February 2023 attack on Technion, an Israeli research institute, cybersecurity firm Deep Instinct said in a ...
-
web:www.scworld.com
Attacks by Iranian state-backed threat group MuddyWater, also known as Mango Sandstorm and Mercury, against Israeli research institute Technion, as well as PaperCut servers have involved the utilization of the PhonyC2 post-exploitation command-and-control framework.
-
web:www.zolentz.com
In April 2023, Deep Instinct found the PhonyC2 framework on a server linked to MuddyWater's broader infrastructure used in the Technion attack this year. PhonyC2 , the latest version, is written in Python3, sharing structural and functional similarities with Python2-based MuddyC3, a previous custom C2 framework by MuddyWater.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.