DeimosC2
- First seen
- 2020-06-01 00:00:00
- Malware type
- rat
- Family
- Malware family
- Last IoC activity
- 2026-07-18 23:44:53
- Profile updated
- 2026-07-07 14:53:23
Context
Trend Micro describes DeimosC2 as an open-source C&C framework that was released in June 2020. It is a fully-functional framework that allows for multiple attackers to access, create payloads for, and interact with victim computers. As a post-exploitation C&C framework, DeimosC2 will generate the payloads that need to be manually executed on computer servers that have been compromised through other means such as social engineering, exploitation, or brute-force attacks. Once it is deployed, the threat actors will gain the same access to the systems as the user account that the payload was executed as, either as an administrator or a regular user. Note that DeimosC2 does not perform active or privilege escalation of any kind.
Reports & references
- 5851803.fs1.hubspotusercontent-na1.net — Russian%20Ransomware%20C2%20Network%20Discovered%20In%20Censys%20Data (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Deimos C2 (report)
- Trend Micro — Deimosc2 What Soc Analysts And Incident Responders Need To Know (report)
- censys.com — Russian Ransomware C2 Network Discovered In Censys Data (report)