logo

GreyNoise Launches C2 Detection for Exploited Edge Devices

ID: 135d6251-c8c0-56cd-b58a-5a128797b1cb

STIX ID: report--135d6251-c8c0-56cd-b58a-5a128797b1cb

Feed Name: GBHackers

Threat Score
55/100

Date Published: 2026-04-08

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

GreyNoise launched a C2 Detection capability to identify compromised edge devices (firewalls, routers, VPNs) by extracting callback destinations from observed exploit payloads and building a continuously updated dataset of malicious callback IPs and malware hashes; defenders can correlate outbound traffic with this dataset and integrate detections into SIEM/SOAR for investigation and automated response, with callback IPs classified into Unconfirmed, Stage 1 (file downloaded), and Stage 2 (C2 suspected).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.