216.73.216.6

New Botnet Emerges from the Shadows: NightshadeC2

· Published 05/09/2025 10:46 · Modified 05/09/2025 14:46

Export JSON

Essential information

Published
05/09/2025 10:46
Modified
05/09/2025 14:46
Tags
2025-09-05 botnet c2 communication keylogging lumma stealer nightshadec2 sandbox evasion trojanized software uac bypass
Related entities
14 techniques (mitre)

Description

A new called has been identified, employing sophisticated techniques to bypass malware analysis sandboxes and exclude itself from Windows Defender. It uses a 'UAC Prompt Bombing' technique and has both C and Python variants. The 's capabilities include reverse shell, file execution, self-deletion, remote control, screen capture, hidden web browsers, and . It's being distributed through ClickFix attacks and trojanized legitimate software. The uses encryption for and gathers victim information. It also employs various persistence mechanisms and can bypass certain sandbox environments. The discovery highlights the evolving sophistication of malware and the need for advanced detection and response capabilities.

External references