Russian Ransomware C2 Network Discovered in Censys Data
ID: 53cf8616-0a6c-5212-9153-61eccdfd6a6f
STIX ID: report--53cf8616-0a6c-5212-9153-61eccdfd6a6f
Feed Name: Censys Blog
Date Published: 2022-07-21
Date Updated: 2026-04-27
Author: Matt Lembright; Global Lead Of Censys Data
Censys identified multiple hosts—mostly in Russia and one in Ohio—hosting offensive tooling (Metasploit, Deimos C2, PoshC2) and malware kits that include ransomware-related components and credential theft/C2 tools (Cobalt Strike, Mimikatz). Historical certificate and file evidence links at least one kit to MedusaLocker and Bitcoin nodes likely used for ransom payments, leading Censys to assess these hosts as part of a ransomware C2 network.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
