Suspicious File Based C2 Relay via Python Web Panel via process_creation

PremiumReviewedSigma · High · v1
Product
linux
Category
process_creation
Author
HuntRule
Published
2026-06-13
Updated
2026-08-28

ATT&CK techniques

Execution → C2
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Persistence

  5. Priv Esc

  6. Defense Evasion

  7. Cred Access

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. Exfiltration

  12. Impact

What it detects

This rule detects the file based command and control component of the AI assisted intrusions where python3 runs a relay.py or webpanel.py operator panel that dispatches commands through /tmp/cmd_ FIFO files. This lightweight Python relay brokers attacker instructions to the implant on the host. Running these operator scripts from a compromised server is a strong indicator of hands on keyboard control.

Related detections9 linkedT1071.001 — drag to rearrange
Possible Remcos C2 Connection from eilowutil Process
Possible MOVEit Transfer SSRF via MOVEitISAPI action m2
Suspicious Tomcat Campaign Command and Control Domain Resolution (via dns_query)
Suspicious TeamTNT Command and Control Domain Resolution (via dns_query)
Malicious CastleLoader C2 Communication via Hardcoded User-Agent
Suspicious Outbound Connection From CasPol Binary
Suspicious Kimsuky Python Backdoor Staging in Winii Directory (via file_event)
SynkLoader Python Stager Execution from AppData via pythonw (via process_creation)
Suspicious Cobalt Strike Loader C2 Traffic via Forged MSIE yie9 User-Agent (via proxy)
Suspicious File Based C2 Relay via Python Web Panel via process_creation
Pivot detection · T1071.001 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.