#C2

Command and Control infrastructure (URLs, IPs, domains) hosting attacker servers and beacons

Subscribe (RSS)


#C2

Command and Control servers (URLs, IPs, domains)

Subscribe (RSS)


IOCs by window

Today

0

IOCs tagged #C2

Week

32

IOCs tagged #C2

Month

397

IOCs tagged #C2

Year

11,666

IOCs tagged #C2

Counts as of 2026-08-09. Regenerated daily.

About #C2

  • Definition: infrastructure that an adversary uses to maintain a covert channel with compromised hosts. MITRE ATT&CK tracks it as Tactic TA0011 (Command and Control), with techniques covering application-layer protocols, encrypted channels, fast flux DNS, domain fronting and many others.
  • Common variants: Cobalt Strike Beacon, Sliver, Mythic, Havoc, Empire, plus bespoke implants. Infrastructure ranges from single-VPS HTTP listeners to complex chains with redirectors, fronting domains and CDN-hidden ingress.
  • Detection: DNS reputation, JA3/JA4 TLS fingerprinting, beacon-jitter analysis, sinkhole + traffic-analytics, certificate transparency for short-lived certs, and YARA on memory-resident agents.
  • References: MITRE ATT&CK TA0011 · see also tag-specific pages for #cobaltstrike, #sliver, #mythic, #havoc.

Recent IOCs tagged #C2

Latest 10 IOCs from the past 30 days. Live JSON: api.tweetfeed.live/v1/month/c2.

Date Type Value Source
Aug 07, 08:42 ip 37.60.250.63 @Fact_Finder03
Aug 07, 08:42 sha256 0f94b72741ecedb2ff640497d0f3cf10fcbc851ccf7c93e9b17f8f6d4475... @Fact_Finder03
Aug 07, 07:26 ip 31.77.156.5 @Fact_Finder03
Aug 07, 07:26 sha256 e42fece328b2bb6b8ff36703313ae64634e57c10c3de5c437fb9a86e7f69... @Fact_Finder03
Aug 07, 07:26 sha256 bd8bf5c443279cf1a87f7b3b469d052396df8773451262af01369242c0df... @Fact_Finder03
Aug 07, 07:26 sha256 700a83012a83b14d0f8c9b931b5b0a41e47f89710f6c565d8d0846200e64... @Fact_Finder03
Aug 07, 07:14 ip 182.92.180.194 @Fact_Finder03
Aug 06, 03:24 ip 212.119.42.58 @Fact_Finder03
Aug 06, 02:21 ip 171.229.217.2 @Fact_Finder03
Aug 05, 14:14 ip 104.239.66.61 @teamcymru_S2

Related tags

Tags that frequently co-occur with #C2.

See all tags on the Dashboard or browse the full IOC feed.

Frequently asked questions

What is C2 (Command and Control)?

Command and Control is the channel adversaries use to communicate with compromised hosts during an intrusion. The MITRE ATT&CK framework groups all related techniques under tactic TA0011. C2 infrastructure can be a single VPS hosting an HTTP listener, or a long chain involving redirectors, fronting domains and CDN-hidden ingress to evade detection.

Which C2 frameworks generate the most IOCs on TweetFeed?

Cobalt Strike, Sliver, Mythic, Havoc and bespoke implants dominate the corpus. Each has its own dedicated tag on TweetFeed for finer filtering: see #cobaltstrike, #sliver, #mythic, #havoc. The #c2 umbrella tag is broader and includes everything researchers flag as C2 infrastructure regardless of framework.

How is this list updated?

Every 15 minutes. The TweetFeed pipeline scrapes RSS feeds from public Twitter/X security researcher accounts and lists, extracts IOCs, tags them with the relevant malware family or threat actor, and republishes the result in CSV, JSON and RSS. C2-tagged IOCs are surfaced on this page within the next 15-minute tick. The page itself is regenerated daily by a GitHub Action.

What is the license? Can I use this commercially?

All TweetFeed IOC data, including this C2 subset, is released under CC0 1.0 Universal (Public Domain Dedication). No attribution required, no warranty. Commercial use is allowed. The TweetFeed website code and branding are not covered by CC0.

License

C2 IOC data: CC0 1.0 Public Domain. No attribution required, no warranty. Source code for the pipeline: github.com/0xDanielLopez/TweetFeed (MIT).