NightShade C2 (also known as NightShade, NightShadeC2) is a c2 framework active since 2023. Emerging C2 framework. Key characteristics include: emerging framework, Go-based agents, web dashboard.
Overview & Background
Emerging C2 framework. First identified in 2023, this threat is attributed to Open source / eCrime.
Threat Assessment
NightShade C2 remains an active threat. Organizations should implement detection rules and monitor for indicators associated with this c2 framework.
- Category: C2 Framework
- Active since: 2023
- Attribution: Open source / eCrime
- Also known as: NightShade, NightShadeC2
Technical Analysis
NightShade C2 employs the following capabilities and techniques:
- Emerging Framework: Core functionality
- Go-Based Agents: Core functionality
- Web Dashboard: Core functionality
MITRE ATT&CK Mapping
| Tactic | Technique | Usage |
|---|---|---|
| Initial Access | T1566.001 Phishing Attachment | Common delivery vector |
| Execution | T1204.002 Malicious File | User-triggered execution |
| Persistence | T1547.001 Registry Run Keys | Autostart persistence |
| Defense Evasion | T1027 Obfuscated Files | Payload obfuscation |
| C2 | T1071.001 Web Protocols | HTTP/HTTPS C2 |
Detection & Defense
- Endpoint detection: Deploy behavioral detection rules for NightShade C2 indicators
- Network monitoring: Monitor for C2 traffic patterns and anomalous connections
- Threat intelligence: Track NightShade C2 IOCs and campaign updates
- Security awareness: Train users to recognize phishing and social engineering
- Patch management: Keep systems updated to prevent exploitation
Defend Against NightShade C2
Mjolnir Security provides detection and response capabilities against NightShade C2 and similar threats.
Threat DetectionIncident ResponseThreat HuntingMDR ServicesThreat Intelligence
- Proactive Threat Hunting Hunt for NightShade C2 indicators and TTPs within your environment.
- Threat Intelligence Monitor NightShade C2 campaigns and infrastructure changes.
- 24/7 Incident Response Rapid containment and forensic investigation. Call +1 833 403 5875.
Written by: Mjolnir Security | Published: October 18, 2025
Stay ahead of emerging threats. Get notified when we publish new intelligence reports and advisories.
Subscribe to Alerts