Komari Red: The Monitoring Tool with a Built-in Reverse Shell
ID: ceb1bbd8-f8ca-5e07-93aa-f3430dfb7b17
STIX ID: report--ceb1bbd8-f8ca-5e07-93aa-f3430dfb7b17
Feed Name: Huntress Blog
Huntress describes a confirmed intrusion where stolen VPN credentials led to smbexec-based lateral access and RDP, followed by installation of the Komari monitoring agent as a SYSTEM service (masquerading as "Windows Update Service") using NSSM; Komari's built-in WebSocket-based exec/terminal/ping features provided a persistent C2. The report includes a forensic timeline, IoCs (binary hash, IPs, install URL, registry/service keys), analysis of Komari's protocol and capabilities, and remediation steps taken to contain the incident.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
