Dossier
command-and-control (C2)
Coverage of command-and-control (C2) in the Nexus archive.
- New msaRAT malware uses Chrome, Edge browsers to route C2 traffic
The Chaos ransomware gang is using a new backdoor called msaRAT that routes command-and-control (C2) traffic through Chrome or Edge browsers to hide communication. The malware disguises its C2 traffic by leveraging these commonly used web browsers.
- SystemBC C2 Server Reveals 1,570+ Victims in The Gentlemen Ransomware Operation
Threat actors linked to The Gentlemen ransomware-as-a-service (RaaS) operation are deploying SystemBC proxy malware, with a Check Point analysis revealing over 1,570 victims via a compromised C2 server. The discovery highlights a botnet tied to the ransomware campaign.