Command & Control infrastructures tracked by Sekoia.io in 2022
ID: f4c21049-d914-586a-9295-5472cbb34a5d
STIX ID: report--f4c21049-d914-586a-9295-5472cbb34a5d
Feed Name: Sekoia.com
Sekoia.io's 2022 C2 tracking report documents discovery of over 65,000 IP addresses used as command-and-control servers, a substantial increase year-over-year, and enumerates top offensive security tools (CobaltStrike, Sliver, etc.) and malware families (EvilProxy, Ramnit, Qakbot, Raccoon). The report highlights large-scale credential theft and MFA-bypass activity (EvilProxy, Evilginx2 ~2,700 domains), geographic concentration of malicious hosts (notably China and the United States), long-lived malicious servers, and observed campaign activity including a CALISTO-linked phishing effort.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
