logo

BrewJack: Censys Researchers Uncover First Malware Campaign Targeting IP over Avian Carriers

ID: 5655342a-f67c-592d-8443-ceffa69652a8

STIX ID: report--5655342a-f67c-592d-8443-ceffa69652a8

Feed Name: Censys Blog

Threat Score
0/100

Date Published: 2026-04-01

Date Updated: 2026-04-27

...
...

This advisory humorously claims an APT called "Pigeon Forge" is operating a campaign named "BrewJack" that uses carrier pigeons (RFC 2549) carrying microSDs as an IP-over-Avian-Carriers C2 transport and miscompiled HTCPCP/418 "I'm a teapot" responses; it provides IOCs, TTP mappings, and mitigations but is published as an April Fools' Day satire and should not be treated as a real incident.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.