Team Cymru - S2 Research

Follow us for the latest blogs and IOCs from Team Cymru's S2 Research team.

Team Cymru - S2 Researchteamcymru_S2@infosec.exchange
2023-01-24

Bonjour #IcedID #BackConnect!

We've spotted a new C2 server being set up on:

5.196.196.252 (🇫🇷)

Expect to see this IP in infection chains in the coming days / hours.

#Recon 👀

cc @netresec

Team Cymru - S2 Researchteamcymru_S2@infosec.exchange
2023-01-19

January's #OST (Offensive Security Tool) snapshot 📊. The numbers have generally remained the same since December.

We've added #Gophish to our tracking as another tool which we've seen growing in prominence during recent months.

Team Cymru - S2 Researchteamcymru_S2@infosec.exchange
2023-01-16

Adding to this SentinelLabs research:

sentinelone.com/labs/noname057

The backend infra~ for this group appears to be located in Russia 😲

Target info also hosted on 87.121.52.9 🇧🇬; same URL path as previously '/client/get_targets'... known C2s are mirrors?

Attack infra~ largely hosted at Stark Industries 🇬🇧

NoName057(16) Infrastructure

Client Info

Server: https://mastodon.social
Version: 2025.04
Repository: https://github.com/cyevgeniy/lmst