Possible Gamaredon Dead-Drop C2 via Telegraph and GoFile Web Services

PremiumReviewedSigma · Medium · v1
Product
windows
Category
dns_query
Author
HuntRule
Published
2026-09-23
Updated
2026-09-23

ATT&CK techniques

C2 → Exfiltration
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Discovery

  10. Lateral Movement

  11. Collection

  12. Impact

What it detects

This rule detects DNS resolution of api.telegra.ph and gofile.io, legitimate web services abused by Gamaredon in 2025 as dead-drop resolvers and exfiltration channels through its PteroOdd and PteroEffigy tools. The group stores C2 configuration and stages stolen data on these platforms to blend with normal web traffic. Detecting these lookups is important because they reveal web-service based command-and-control and data exfiltration that evades domain reputation controls.

Related detections9 linkedT1567.002 — drag to rearrange
Suspicious PowerShell Communication with Dropbox API (via ps_script)
Possible Gamaredon C2 via Ephemeral Tunneling and Worker Services
Suspicious Data Exfiltration via Rclone Remote Copy
Suspicious Data Exfiltration via rclone
Suspicious APT29 Zulip C2 Communication via curl User-Agent (via proxy)
Suspicious Data Exfiltration to Telegram or Discord Web Service
Suspicious ALPHA SPIDER Rclone Exfiltration Tool Masquerading as System Binary (via process_creation)
Malicious GhostLocker2 C2 Communication via HTTP POST (via proxy)
Suspicious Rclone Exfiltration Masquerading as wininit.exe
Possible Gamaredon Dead-Drop C2 via Telegraph and GoFile Web Services
Pivot detection · T1567.002 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.