PULSE NAME
New Botnet Emerges from the Shadows: NightshadeC2
WHITE AlienVault 2025-09-05 Modified: 2025-10-05
76
IOCs
HIGH VOLUME
A new botnet called NightshadeC2 has been identified, employing sophisticated techniques to bypass malware analysis sandboxes and exclude itself from Windows Defender. It uses a 'UAC Prompt Bombing' technique and has both C and Python variants. The botnet's capabilities include reverse shell, file execution, self-deletion, remote control, screen capture, hidden web browsers, and keylogging. It's being distributed through ClickFix attacks and trojanized legitimate software. The botnet uses encryption for C2 communication and gathers victim information. It also employs various persistence mechanisms and can bypass certain sandbox environments. The discovery highlights the evolving sophistication of malware and the need for advanced detection and response capabilities.
Indicators of Compromise (15 / 76 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 domain hostname
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 03935f58d2d3efb35c1ddaafb6d90b98 2025-09-05
FileHash-MD5 185fcf0307266e4852432ca35aee0d9a 2025-09-05
FileHash-MD5 4b139d1e079eb10ffd2543e22ea438dd 2025-09-05
FileHash-MD5 66b2d356076a39300abc31abfe8cfea8 2025-09-05
FileHash-MD5 67deffe47d3cd06280a8ed4c45732ad8 2025-09-05
FileHash-MD5 8193d8266f7e1c6b9224ac9da2fbf990 2025-09-05
FileHash-MD5 82c7d087f69e5594489ea1be1755e829 2025-09-05
FileHash-MD5 87f7c07fec9cf5396e09b19b56f9be2c 2025-09-05
FileHash-MD5 a1652546e05709972a040dcf2f452b82 2025-09-05
FileHash-MD5 aa6c3ddf1ca9fccc6e9518a9b004f4ee 2025-09-05
FileHash-MD5 ac77ab1a3f5a3691e23265bc495e84e8 2025-09-05
FileHash-MD5 b8ddd22670522a352a7586303c785d62 2025-09-05
FileHash-MD5 c16d822930acf6e2f788e98966a69d80 2025-09-05
FileHash-MD5 cf4958e8024e9071b540eacee8b3e424 2025-09-05
FileHash-MD5 f8fae59f47f269cb4ee50e701fddc76c 2025-09-05