Hunting for Mythic in network traffic
ID: 1905170c-f95c-5e43-ad54-16affb2a0fdf
STIX ID: report--1905170c-f95c-5e43-ad54-16affb2a0fdf
Feed Name: Securelist by Kaspersky
This report analyzes the Mythic post-exploitation C2 framework, detailing how Mythic agents communicate over SMB, TCP, HTTP(S), WebSocket and covert egress channels (Discord, GitHub), and provides protocol-specific network-detection guidance and Suricata signatures for identifying agent activity (UUID and Base64 patterns, TLS/HTTP behaviors). It emphasizes detection limitations (e.g., TLS/SMBv3 encryption), proposes behavioral fallback rules, and notes Mythic’s adoption by threat actors while listing Kaspersky NDR verdicts for Mythic-related C2s.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
