Suspicious Infostealer C2 Heartbeat to bot heartbeat Endpoint

PremiumReviewedSigma · Medium · v1
Category
proxy
Author
HuntRule
Published
2026-09-15
Updated
2026-09-15

ATT&CK techniques

Exfiltration
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Discovery

  10. Lateral Movement

  11. Collection

  12. C2

  13. Impact

What it detects

This rule detects outbound POST requests to a bot heartbeat command and control endpoint used by the macOS infostealer to check in with its operator. The implant beacons to a heartbeat path to receive tasking and confirm the victim is live. Regular POST traffic to this endpoint indicates an active infostealer implant maintaining C2.

Related detections9 linkedT1041 — drag to rearrange
Malicious NPM Backdoor C2 Beacon to Injective Telemetry Endpoint via Proxy
Suspicious Exfiltration of Environment File via wget POST
Suspicious Data Exfiltration via curl Multipart Upload to Gate Endpoint
Suspicious DNS Exfiltration to azurestaticprovider Backdoor Domain
Suspicious UAT-10608 Credential Harvesting C2 Beacon via HTTP
Malicious Vice Society Directory Crawling Script for Data Exfiltration - Via Ps_script (via ps_script)
Malicious PowerShell Exfiltration to webhook.site Following WSUS Exploitation
Suspicious InvisibleFerret C2 Endpoints over Port 1224 (via proxy)
Suspicious CurKeep Backdoor C2 API Endpoints (via proxy)
Suspicious Infostealer C2 Heartbeat to bot heartbeat Endpoint
Pivot detection · T1041 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.