Third piece in the pitboss series: the second wave's collector at 213.209.159.55 is still live, still serving per-target droppers, and its code evolved from gen-3 to v19-plus while I watched. Full teardown of the forced HA-failover logic and the three-channel C2 (one-shot relay, 15-second pull tasking with output return, HTTP front), why the exfil side is write-only and what that means for victims, the nine-month attack history of the address (January port scans, February .env probes, March .git probes via Go-http-client, Ligolo-ng tunnels in October), a correction to my own domain-aging claim, and the detection set that matters now.
grep -rl "Threat Hunting" ./posts
#Threat Hunting
2 matches
A follow-up investigation to the pitboss teardown: pivoting the public malware corpus on the passwords, tokens, and placeholder strings extracted from the campaign samples turns two copycat bundles into a twenty-deployment operation with three code generations, surfaces chisel on the exfil host, doubles the Platypus enrollment count, and recovers a victim's implant config that phoned a lab address that does not exist. With the pivot methodology, its traps (the MD5 test vector that fakes attribution), and expanded IOCs.