PoshC2

MITRE ATT&CK: S0378 View on attack.mitre.org

Aliases: PoshC2

First seen
2018-01-01 00:00:00
Malware type
rat, dropper
Family
Malware family
Operating systems
windows, linux, macos
Related IoCs
72 (7 malicious)
Last IoC activity
2026-08-26 20:25:05
Profile updated
2026-07-07 12:42:37

Context

PoshC2 is an open source remote administration and post-exploitation framework that is publicly available on GitHub. The server-side components of the tool are primarily written in Python, while the implants are written in PowerShell. Although PoshC2 is primarily focused on Windows implantation, it does contain a basic Python dropper for Linux/macOS.

Recent IoC activity

7 malicious indicators in Maltiverse are attributed to PoshC2 (S0378). The 7 most recently updated:

TypeIndicatorUpdatedSources
IP address 52.41.190.254 2026-08-26 1
IP address 70.77.124.96 2026-08-24 3
IP address 137.184.139.185 2026-08-22 1
file sample KTJ8zjM1.posh 2026-08-19 1
IP address 159.223.145.166 2026-08-17 2
file sample e7e7806d23b660ae2b9d59277003677682bf32834882eb3e781ec93d86e09be1.ps1 2026-03-24 2
hostname finix.newsnewth365.com 2025-06-21 1

Detection coverage

  • 1 YARA rules
  • 595 Sigma rules

Malware & tools used

  • System Network Configuration Discovery (attack-pattern)
  • Credentials In Files (attack-pattern)
  • Name Resolution Poisoning and SMB Relay (attack-pattern)
  • Web Protocols (attack-pattern)
  • Windows Management Instrumentation (attack-pattern)
  • System Network Connections Discovery (attack-pattern)
  • Exploitation for Privilege Escalation (attack-pattern)
  • System Service Discovery (attack-pattern)
  • Create Process with Token (attack-pattern)
  • Bypass User Account Control (attack-pattern)
  • Service Execution (attack-pattern)
  • Local Account (attack-pattern)
  • Automated Collection (attack-pattern)
  • System Information Discovery (attack-pattern)
  • Keylogging (attack-pattern)
  • Domain Account (attack-pattern)
  • Archive via Utility (attack-pattern)
  • Pass the Hash (attack-pattern)
  • Local Groups (attack-pattern)
  • File and Directory Discovery (attack-pattern)
  • Proxy (attack-pattern)
  • Brute Force (attack-pattern)
  • LSASS Memory (attack-pattern)
  • Process Injection (attack-pattern)
  • Exploitation of Remote Services (attack-pattern)

Used by threat actors

Detection rules

  • SIGNATURE_BASE_HKTL_NET_GUID_Poshc2_Misc (yara-rule)

Reports & references

  • secureworks.com — Cobalt Trinity (report)
  • research.checkpoint.com — Dangeroussavanna Two Year Long Campaign Targets Financial Institutions In French Speaking Africa (report)
  • jsac.jpcert.or.jp — Jsac2020 0 Jpcert En (report)
  • go.recordedfuture.com — Cta 2021 0107 (report)
  • Mandiant — Scandalous External Detection Using Network Scan Data And Automation (report)
  • Mandiant — Overruled Containing A Potentially Destructive Adversary (report)
  • blogs.vmware.com — Detecting Threats In Real Time With Active C2 Information (report)
  • jsac.jpcert.or.jp — Jsac2024 1 9 Takeda Furukawa En (report)
  • michaelkoczwara.medium.com — Hunting C2 With Shodan 223Ca250D06F (report)
  • paper.seebug.org — 1301 (report)
  • 5851803.fs1.hubspotusercontent-na1.net — Russian%20Ransomware%20C2%20Network%20Discovered%20In%20Censys%20Data (report)
  • redcanary.com — Getsystem Offsec (report)
  • censys.com — Russian Ransomware C2 Network Discovered In Censys Data (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Poshc2 (report)
  • rewterz.com — Rewterz Threat Alert Iranian Apt Uses Job Scams To Lure Targets (report)
  • github.com — Poshc2 Python (report)
  • github.com — Poshc2 Apt 33.Md (report)
  • labs.nettitude.com — Detecting Poshc2 Indicators Of Compromise (report)
  • ti.dbappsecurity.com.cn — Operation Maskface (report)
  • MITRE ATT&CK — S0378 (report)

External references