PoshC2
MITRE ATT&CK: S0378 View on attack.mitre.org
Aliases: PoshC2
- First seen
- 2018-01-01 00:00:00
- Malware type
- rat, dropper
- Family
- Malware family
- Operating systems
- windows, linux, macos
- Related IoCs
- 72 (7 malicious)
- Last IoC activity
- 2026-08-26 20:25:05
- Profile updated
- 2026-07-07 12:42:37
Context
PoshC2 is an open source remote administration and post-exploitation framework that is publicly available on GitHub. The server-side components of the tool are primarily written in Python, while the implants are written in PowerShell. Although PoshC2 is primarily focused on Windows implantation, it does contain a basic Python dropper for Linux/macOS.
Recent IoC activity
7 malicious indicators in Maltiverse are attributed to PoshC2 (S0378). The 7 most recently updated:
| Type | Indicator | Updated | Sources |
|---|---|---|---|
| IP address | 52.41.190.254 | 2026-08-26 | 1 |
| IP address | 70.77.124.96 | 2026-08-24 | 3 |
| IP address | 137.184.139.185 | 2026-08-22 | 1 |
| file sample | KTJ8zjM1.posh | 2026-08-19 | 1 |
| IP address | 159.223.145.166 | 2026-08-17 | 2 |
| file sample | e7e7806d23b660ae2b9d59277003677682bf32834882eb3e781ec93d86e09be1.ps1 | 2026-03-24 | 2 |
| hostname | finix.newsnewth365.com | 2025-06-21 | 1 |
Detection coverage
- 1 YARA rules
- 595 Sigma rules
Malware & tools used
- System Network Configuration Discovery (attack-pattern)
- Credentials In Files (attack-pattern)
- Name Resolution Poisoning and SMB Relay (attack-pattern)
- Web Protocols (attack-pattern)
- Windows Management Instrumentation (attack-pattern)
- System Network Connections Discovery (attack-pattern)
- Exploitation for Privilege Escalation (attack-pattern)
- System Service Discovery (attack-pattern)
- Create Process with Token (attack-pattern)
- Bypass User Account Control (attack-pattern)
- Service Execution (attack-pattern)
- Local Account (attack-pattern)
- Automated Collection (attack-pattern)
- System Information Discovery (attack-pattern)
- Keylogging (attack-pattern)
- Domain Account (attack-pattern)
- Archive via Utility (attack-pattern)
- Pass the Hash (attack-pattern)
- Local Groups (attack-pattern)
- File and Directory Discovery (attack-pattern)
- Proxy (attack-pattern)
- Brute Force (attack-pattern)
- LSASS Memory (attack-pattern)
- Process Injection (attack-pattern)
- Exploitation of Remote Services (attack-pattern)
Used by threat actors
- Sandworm Team (threat-actor)
- HEXANE (threat-actor)
- APT33 (threat-actor)
Detection rules
- SIGNATURE_BASE_HKTL_NET_GUID_Poshc2_Misc (yara-rule)
Reports & references
- secureworks.com — Cobalt Trinity (report)
- research.checkpoint.com — Dangeroussavanna Two Year Long Campaign Targets Financial Institutions In French Speaking Africa (report)
- jsac.jpcert.or.jp — Jsac2020 0 Jpcert En (report)
- go.recordedfuture.com — Cta 2021 0107 (report)
- Mandiant — Scandalous External Detection Using Network Scan Data And Automation (report)
- Mandiant — Overruled Containing A Potentially Destructive Adversary (report)
- blogs.vmware.com — Detecting Threats In Real Time With Active C2 Information (report)
- jsac.jpcert.or.jp — Jsac2024 1 9 Takeda Furukawa En (report)
- michaelkoczwara.medium.com — Hunting C2 With Shodan 223Ca250D06F (report)
- paper.seebug.org — 1301 (report)
- 5851803.fs1.hubspotusercontent-na1.net — Russian%20Ransomware%20C2%20Network%20Discovered%20In%20Censys%20Data (report)
- redcanary.com — Getsystem Offsec (report)
- censys.com — Russian Ransomware C2 Network Discovered In Censys Data (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Poshc2 (report)
- rewterz.com — Rewterz Threat Alert Iranian Apt Uses Job Scams To Lure Targets (report)
- github.com — Poshc2 Python (report)
- github.com — Poshc2 Apt 33.Md (report)
- labs.nettitude.com — Detecting Poshc2 Indicators Of Compromise (report)
- ti.dbappsecurity.com.cn — Operation Maskface (report)
- MITRE ATT&CK — S0378 (report)