Writing a BugSleep C2 server and detecting its traffic with Snort
ID: e8b53e0e-5536-50f1-b434-e57d528e0594
STIX ID: report--e8b53e0e-5536-50f1-b434-e57d528e0594
Feed Name: Cisco Talos
Threat Score
This Cisco Talos analysis details a newly observed RAT called BugSleep (aka MuddyRot/BugSleep) used in recent MuddyWater campaigns: it reverse-engineers the implant's bespoke TCP pseudo-TLV protocol, implements a Python C2 server that emulates beaconing, ping, file transfer, and reverse shell commands, publishes Snort detection rules (SIDs 63937/63938), and provides IOCs (IPs and file hashes) to support detection and mitigation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
