216.73.217.22

A First Look at a New Post-Exploitation Red Team Tool

· Published 09/06/2026 06:14 · Modified 09/06/2026 08:57

Export JSON

Essential information

Published
09/06/2026 06:14
Modified
09/06/2026 08:57
Tags
2026-06-09 c2 communication penetration-testing post-exploitation process injection red team tool rust splinter task-based
Related entities
1 observables, 20 techniques (mitre), 1 malware

Description

A new named has been discovered on customer systems through Advanced WildFire's memory scanning capabilities. Developed in programming language, is exceptionally large at around 7MB due to statically linked libraries. The tool uses a JSON configuration structure containing implant ID, C2 server details, and operational parameters. It operates through a model with capabilities including Windows command execution, remote , file upload/download, cloud service information gathering, and self-deletion. Communication with the C2 server occurs via HTTPS using specific URL paths for task synchronization, heartbeat connections, and file transfers. While not as sophisticated as Cobalt Strike, represents a growing variety of penetration testing tools that could potentially be misused by threat actors.

External references