logo

Hunting for Mythic in network traffic

ID: 1905170c-f95c-5e43-ad54-16affb2a0fdf

STIX ID: report--1905170c-f95c-5e43-ad54-16affb2a0fdf

Feed Name: Securelist by Kaspersky

Threat Score
75/100

Date Published: 2025-12-11

Date Updated: 2026-04-29

Author: Valery Akulenko, Dmitry Sabadash

...
...

This report analyzes the Mythic post-exploitation C2 framework, detailing how Mythic agents communicate over SMB, TCP, HTTP(S), WebSocket and covert egress channels (Discord, GitHub), and provides protocol-specific network-detection guidance and Suricata signatures for identifying agent activity (UUID and Base64 patterns, TLS/HTTP behaviors). It emphasizes detection limitations (e.g., TLS/SMBv3 encryption), proposes behavioral fallback rules, and notes Mythic’s adoption by threat actors while listing Kaspersky NDR verdicts for Mythic-related C2s.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.