TF-MAL-py.nightshade_c2
📛 Threat Title
Malware family: NightshadeC2
Description
ThreatFox malware family `py.nightshade_c2`. Printable name: NightshadeC2.
Indicators of Compromise (0)
No indicators of compromise on this threat.
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:cyberenso.jp
Cybersecurity researchers identified a highly sophisticated botnet known as NightshadeC2 , which employs an innovative technique called UAC Prompt Bombing to bypass Windows Defender and evade detection in malware analysis environments. The botnet is primarily distributed through trojanized versions of legitimate software, including VPN clients, system utilities, and file search applications ...
-
web:cybernoz.com
A sophisticated new botnet called NightshadeC2 that employs an innovative "UAC Prompt Bombing" technique to evade Windows Defender and compromise endpoint security systems.
-
web:cybersecuritynews.com
Security teams began observing a novel botnet strain slipping beneath the radar of standard Windows Defender defenses in early August 2025. Dubbed NightshadeC2 , this malware family leverages both C and Python-based payloads to establish persistent, remote-control access on compromised hosts. Initial infection chains often start with customized "ClickFix" landing pages that trick users into ...
-
web:en.hacks.gr
NightshadeC2 : New botnet bypasses Windows Defender with "UAC Prompt Bombing"Cybersecurity teams have identified a new botnet variant called NightshadeC2 , which manages to slip past Windows Defender defenses. The malware's activity has been tracked since early August 2025, with eSentire researchers warning of
-
web:intel.mjolnirsecurity.com
NightShade C2 (also known as NightShade, NightShadeC2 ) is a c2 framework active since 2023. Emerging C2 framework. Key characteristics include: emerging framework, Go-based agents, web dashboard.
-
web:malpedia.caad.fkie.fraunhofer.de
2025-09-04 (Back to Inventory) Propose Change New Botnet Emerges from the Shadows: NightshadeC2 Author (s): eSentire Threat Response Unit (TRU) Organization: eSentire py. nightshade_c2 win. nightshade_c2 Open article directly Show BibTex Entry 2025-08-27 ⋅ eSentire ⋅ eSentire Threat Response Unit (TRU) Threat Actors Deploy Sinobi Ransomware via Compromised SonicWall SSL VPN Credentials Lynx ...
-
web:netcrook.com
Technical Tricks and Evasive Maneuvers Under the hood, NightshadeC2 is versatile. Its main payload is written in C for speed and stealth, while a simpler Python version exists—likely churned out by AI tools. The malware communicates with its controllers using encrypted messages and hides deep in the system, persisting through reboots by embedding itself in Windows' startup settings. It can ...
-
web:threatlibrary.zscaler.com
Summary: NightshadeC2 is a Backdoor malware with functionalities designed for system control, keystroke and clipboard monitoring, reverse shell access, payload execution, and browser credential theft.
-
web:www.derp.ca
According to eSentire, NightshadeC2 demonstrates an extensive capability set, including: Reverse shell via Command Prompt/PowerShell; Download and execute DLL or EXE; Self-deletion; Remote control; Screen capture; Hidden web browsers; Keylogging; clipboard content capturing. Certain variants have been found with stealing capabilities that enable the extraction of browser passwords and cookies ...
-
web:www.linkedin.com
Dubbed NightshadeC2 , this malware family leverages both C and Python-based payloads to establish persistent, remote-control access on compromised hosts.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.