...open-source and dual-use tools as used and/or customized by the actors: ... DeimosC2 ...
DeimosC2
DeimosC2 is an open-source, GoLang-based command-and-control framework with RAT-like capabilities comparable to Cobalt Strike and Sliver.
Profile source: Mallory opens in a new tabDeimosC2
Family profile
DeimosC2 is an open-source, GoLang-based command-and-control framework with RAT-like capabilities comparable to Cobalt Strike and Sliver. In the provided reporting, it is associated with DPRK-linked Lazarus Group / Andariel activity and is explicitly listed by U.S. and partner agencies as an open-source or dual-use tool used and/or customized by the actors. In one documented Lazarus campaign exploiting CVE-2022-47966 in ManageEngine ServiceDesk, researchers observed an unmodified DeimosC2 agent deployed as a Linux ELF implant for initial or persistent access on compromised Linux servers. The beacon was described as generated by the DeimosC2 server and using out-of-the-box URI paths. The same campaign reused infrastructure that also hosted QuiteRAT, CollectionRAT, and a trojanized PuTTY Plink utility, and the shared infrastructure was used for command-and-control. More broadly, joint government reporting includes DeimosC2 among the open-source and dual-use tools used by Andariel alongside utilities such as 3Proxy, Impacket, PLINK, Stunnel, and web shells. The surrounding reporting states Andariel targets defense, aerospace, nuclear, engineering, medical, and energy sectors, typically gaining access through exploitation of public-facing applications and known vulnerabilities including Log4Shell and other CVEs.
Reported operators
Threat actors
2 named in public reportingThe authoring agencies have identified the following open source and dual-use tools as used and/or customized by the actors: ▪ DeimosC2
Exploited software
Vulnerabilities linked to DeimosC2
1 CVEsMITRE ATT&CK