logo

TrevorC2 - Legitimate Covert C2 over Browser Emulation

ID: 5a770a90-71d4-51b3-b28a-30c64c8cbf4f

STIX ID: report--5a770a90-71d4-51b3-b28a-30c64c8cbf4f

Feed Name: TrustedSec blog

Threat Score
60/100

Date Published: 2025-03-19

Date Updated: 2026-05-01

...
...

TrustedSec announced TrevorC2, an open-source HTTP(s) command-and-control framework that masks C2 by cloning a legitimate website and hiding commands in page source parameters; clients poll the site at configurable intervals and exfiltrate command output via base64-encoded query parameters. The release describes server/client setup and usage, supported platforms (Windows, macOS, Linux), and TODO features (encryption, randomized parameters, additional language modules), highlighting its focus on evasion rather than reporting active exploitation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.