Cybercriminals Exploit Pyramid Pentesting Tool for Covert C2 Communications
ID: ae1fbbab-a423-52fc-be97-c232073b3d41
STIX ID: report--ae1fbbab-a423-52fc-be97-c232073b3d41
Feed Name: GBHackers
Researchers have observed malicious actors abusing the open-source Pyramid post-exploitation framework as a stealthy C2 channel. Pyramid's Python-based HTTP/S server returns distinctive Basic auth responses, headers (e.g., Server:BaseHTTP/0.6 Python/3.10.4), and JSON error bodies that both aid evasion and provide reliable network detection artifacts; analysts have developed signatures based on these traits and identified several IPs and domains linked to recent campaigns, highlighting the need for focused threat hunting and detection tuning.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
