TrevorC2 - Legitimate Covert C2 over Browser Emulation
ID: 5a770a90-71d4-51b3-b28a-30c64c8cbf4f
STIX ID: report--5a770a90-71d4-51b3-b28a-30c64c8cbf4f
Feed Name: TrustedSec blog
TrustedSec announced TrevorC2, an open-source HTTP(s) command-and-control framework that masks C2 by cloning a legitimate website and hiding commands in page source parameters; clients poll the site at configurable intervals and exfiltrate command output via base64-encoded query parameters. The release describes server/client setup and usage, supported platforms (Windows, macOS, Linux), and TODO features (encryption, randomized parameters, additional language modules), highlighting its focus on evasion rather than reporting active exploitation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
