logo

Writing a BugSleep C2 server and detecting its traffic with Snort

ID: e8b53e0e-5536-50f1-b434-e57d528e0594

STIX ID: report--e8b53e0e-5536-50f1-b434-e57d528e0594

Feed Name: Cisco Talos

Threat Score
70/100

Date Published: 2024-10-30

Date Updated: 2026-04-27

Author: Aaron Boyd

...
...

This Cisco Talos analysis details a newly observed RAT called BugSleep (aka MuddyRot/BugSleep) used in recent MuddyWater campaigns: it reverse-engineers the implant's bespoke TCP pseudo-TLV protocol, implements a Python C2 server that emulates beaconing, ping, file transfer, and reverse shell commands, publishes Snort detection rules (SIDs 63937/63938), and provides IOCs (IPs and file hashes) to support detection and mitigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.