A cluster of trojanized npm packages is delivering the RedC2 4.0 Linux implant, providing operators with a pathway from a seemingly harmless dependency import to internal network pivoting via SOCKS5 proxies and TCP forwarding. The campaign disguises malicious code inside functional calendar and streak-calculation utilities, underscoring how supply-chain abuse can bypass controls focused only on […]
The post RedC2 Turns Compromised Linux Machines Into SOCKS5 Proxies for Internal Network Pivoting appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Mayura Kathir
Source: gbHackers
Source Link: https://gbhackers.com/redc2-4-0-linux-implant/