logo

Komari Red: The Monitoring Tool with a Built-in Reverse Shell

ID: ceb1bbd8-f8ca-5e07-93aa-f3430dfb7b17

STIX ID: report--ceb1bbd8-f8ca-5e07-93aa-f3430dfb7b17

Feed Name: Huntress Blog

Threat Score
75/100

Date Published: 2026-04-30

Date Updated: 2026-05-01

...
...

Huntress describes a confirmed intrusion where stolen VPN credentials led to smbexec-based lateral access and RDP, followed by installation of the Komari monitoring agent as a SYSTEM service (masquerading as "Windows Update Service") using NSSM; Komari's built-in WebSocket-based exec/terminal/ping features provided a persistent C2. The report includes a forensic timeline, IoCs (binary hash, IPs, install URL, registry/service keys), analysis of Komari's protocol and capabilities, and remediation steps taken to contain the incident.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.