Possible SPECTRALVIPER C2 Communication via Crafted Consent Cookie Values

PremiumReviewedSigma · Medium · v1
Category
proxy
Author
HuntRule
Published
2026-09-24
Updated
2026-09-24

ATT&CK techniques

C2
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Discovery

  10. Lateral Movement

  11. Collection

  12. Exfiltration

  13. Impact

What it detects

This rule detects HTTP requests whose Cookie header simultaneously carries the euconsent-v2 and zd_cs_pm values used by the SPECTRALVIPER backdoor to smuggle command-and-control host information. The technique is tied to the OceanLotus (APT32) espionage campaign that masquerades C2 metadata inside cookies resembling GDPR consent and support tracking tokens. Identifying this combined cookie pattern matters because it exposes encrypted C2 traffic hidden inside otherwise benign-looking web requests.

Related detections9 linkedT1071.001 — drag to rearrange
Malicious OysterLoader C2 Beacon Using WordPressAgent User Agent
Windows curl.exe SOCKS Proxy and .onion Command-Line Execution
Malicious Winter Vivern C2 Endpoint saveMessage via Proxy (via proxy)
Suspicious Whisper Backdoor Log File in Windows Temp
Suspicious Lunar Backdoor State File Creation via File System
Malicious OilRig OAuth Application Sign-In via Azure (via azure)
Malicious FIN7 DiceLoader C2 via Placeholder User-Agent (via proxy)
Malicious D3f@ck Loader C2 via Java User-Agent Ready Beacon (via proxy)
Suspicious AddInProcess32 Outbound Connection after Process Hollowing
Possible SPECTRALVIPER C2 Communication via Crafted Consent Cookie Values
Pivot detection · T1071.001 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.