Suspicious InvisibleFerret C2 Endpoints over Port 1224 (via proxy)

PremiumReviewedSigma · High · v1
Category
proxy
Author
HuntRule
Published
2026-07-19
Updated
2026-08-28

ATT&CK techniques

Exfiltration
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Discovery

  10. Lateral Movement

  11. Collection

  12. C2

  13. Impact

What it detects

This rule detects HTTP requests to the InvisibleFerret command and control server that exposes payload, browser, clipboard and key exfiltration endpoints over TCP port 1224. The Lazarus backdoor cycles through fixed URI paths such as payload, brow, mclip and keys on this port. The pairing of the non-standard port with these named resources reveals the backdoor traffic.

Related detections9 linkedT1041 — drag to rearrange
Malicious Vice Society Directory Crawling Script for Data Exfiltration - Via Ps_script (via ps_script)
Malicious PowerShell Exfiltration to webhook.site Following WSUS Exploitation
Suspicious CurKeep Backdoor C2 API Endpoints (via proxy)
Suspicious DEEPPOST Data Exfiltration URI Pattern via BrazenBamboo
Suspicious Error 524 Decoy Smishing Phishing Endpoint Access (via proxy)
Suspicious COOKIE SPIDER macOS Data Exfiltration via curl Archive Upload (via process_creation)
Suspicious Watering Hole Exfiltration to Fake wp-includes Endpoint via SilentSelfie
Linux Process Creation: curl Exfiltration from Malicious NPM Package Webhook.site
Windows Executable Connects to portmap.io Domain Over Network
Suspicious InvisibleFerret C2 Endpoints over Port 1224 (via proxy)
Pivot detection · T1041 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.