logo

Cybercriminals Exploit Pyramid Pentesting Tool for Covert C2 Communications

ID: ae1fbbab-a423-52fc-be97-c232073b3d41

STIX ID: report--ae1fbbab-a423-52fc-be97-c232073b3d41

Feed Name: GBHackers

Threat Score
65/100

Date Published: 2025-02-13

Date Updated: 2026-04-22

Author: Aman Mishra

...
...

Researchers have observed malicious actors abusing the open-source Pyramid post-exploitation framework as a stealthy C2 channel. Pyramid's Python-based HTTP/S server returns distinctive Basic auth responses, headers (e.g., Server:BaseHTTP/0.6 Python/3.10.4), and JSON error bodies that both aid evasion and provide reliable network detection artifacts; analysts have developed signatures based on these traits and identified several IPs and domains linked to recent campaigns, highlighting the need for focused threat hunting and detection tuning.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.