logo

Tracking Pyramid C2: Identifying Post-Exploitation Servers in Hunt

ID: 9171d20c-8f87-51ad-93eb-85a98a6a290b

STIX ID: report--9171d20c-8f87-51ad-93eb-85a98a6a290b

Feed Name: Hunt.io Blog

Threat Score
65/100

Date Published: 2026-02-16

Date Updated: 2026-04-28

...
...

This report analyzes Pyramid, an open-source Python post-exploitation C2 server, describing distinctive HTTP/S behaviors (401 responses, BaseHTTP/Python Server header, WWW-Authenticate Basic realm, and a specific JSON error body hash), provides detection query examples to find related infrastructure, and lists identified IPs and domains—several of which overlap with ransomware-affiliated activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.