Skip to content

DeimosC2

DeimosC2 is an open-source, GoLang-based command-and-control framework with RAT-like capabilities comparable to Cobalt Strike and Sliver.

Profile source: Mallory opens in a new tab

DeimosC2

Family profile

DeimosC2 is an open-source, GoLang-based command-and-control framework with RAT-like capabilities comparable to Cobalt Strike and Sliver. In the provided reporting, it is associated with DPRK-linked Lazarus Group / Andariel activity and is explicitly listed by U.S. and partner agencies as an open-source or dual-use tool used and/or customized by the actors. In one documented Lazarus campaign exploiting CVE-2022-47966 in ManageEngine ServiceDesk, researchers observed an unmodified DeimosC2 agent deployed as a Linux ELF implant for initial or persistent access on compromised Linux servers. The beacon was described as generated by the DeimosC2 server and using out-of-the-box URI paths. The same campaign reused infrastructure that also hosted QuiteRAT, CollectionRAT, and a trojanized PuTTY Plink utility, and the shared infrastructure was used for command-and-control. More broadly, joint government reporting includes DeimosC2 among the open-source and dual-use tools used by Andariel alongside utilities such as 3Proxy, Impacket, PLINK, Stunnel, and web shells. The surrounding reporting states Andariel targets defense, aerospace, nuclear, engineering, medical, and energy sectors, typically gaining access through exploitation of public-facing applications and known vulnerabilities including Log4Shell and other CVEs.

Reported operators

Threat actors

2 named in public reporting
Andariel

...open-source and dual-use tools as used and/or customized by the actors: ... DeimosC2 ...

Stonefly/Clasiopa

The authoring agencies have identified the following open source and dual-use tools as used and/or customized by the actors: ▪ DeimosC2

Exploited software

Vulnerabilities linked to DeimosC2

1 CVEs

MITRE ATT&CK

DeimosC2 in ATT&CK

1 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.