Ultimately, this Python loader decrypts and runs NightshadeC2 directly in memory. NightshadeC2 acts as a fully featured information stealer.
Reported operators
Threat actors
1 named in public reportingMITRE ATT&CK
NightshadeC2 in ATT&CK
20 distinct techniquesTechniques
20 techniques T1105 Ingress Tool Transfer T1027 Obfuscated Files or Information T1204 User Execution T1185 Browser Session Hijacking T1620 Reflective Code Loading T1140 Deobfuscate/Decode Files or Information T1059.001 PowerShell T1041 Exfiltration Over C2 Channel T1219 Remote Access Tools T1059.006 Python T1071 Application Layer Protocol T1090 Proxy T1548.002 Bypass User Account Control T1562 Impair Defenses T1539 Steal Web Session Cookie T1059 Command and Scripting Interpreter T1548 Abuse Elevation Control Mechanism T1555 Credentials from Password Stores T1498 Network Denial of Service T1071.001 Web Protocols
Reporting