Skip to content
C2 Servers

Introducing Cavalier’s ‘New Threat’ Feeds: Deep Dive into Infostealer C2 Intelligence

InfoStealers
3 min read

Introducing Cavalier’s New Threat Feeds: Deep Dive into Infostealer C2 Intelligence

We are thrilled to introduce three new Threat Feed modules in Cavalier: C2 Data, ClickFix, and PhaaS (Phishing-as-a-service). Together, they give security teams comprehensive visibility into active attacker infrastructure – from infostealer command-and-control (C2) servers to malicious ClickFix pages executing clipboard injection, to turnkey Phishing-as-a-service (PhaaS) kits targeting corporate credentials.

Overview of the Threat Feeds monitoring options
Overview of the new Threat Feeds monitoring options available inside Cavalier.

What’s New: Infostealers C2 Data

The new C2 Data module provides unprecedented access to observed command-and-control (C2) hosts associated directly with active infostealer campaigns. This empowers security teams to transition from reactive incident response to preemptive blocking.

Overview of the infostealers C2 monitoring
A high-level overview of the Infostealers C2 monitoring dashboard, displaying active threat infrastructure.

Inside Cavalier, you can seamlessly review:

  • Daily Infostealers C2 host feeds
  • Activity trends over time
  • Top countries where C2 hosts are observed
  • Malware family breakdowns
  • Detailed host information, including infrastructure type, ASN, AS organization, ports, tags, first seen, and last seen

Uncovering Initial Access with Correlated Intelligence

One of the most powerful features of the C2 Intelligence Feed is the integration of Infostealer credential telemetry linked to the hosting platform. This shows compromised employee or user credentials that likely enabled the threat actors to gain initial access to the server in the first place.

Specific infostealers C2 examples with correlated infection data
Specific infostealer C2 examples (Redline, Vidar, Stealc, etc.) enriched with correlated infection data from Hudson Rock’s cybercrime intelligence database, revealing compromises associated with the server.

For example, you can open a host such as myrtler(.)biz and immediately see that it’s associated with the Vidar malware family, along with its DNS activity, first-seen date, and critical infrastructure details as they are actively observed.

Overview of various families sorted by 30 days volume
An overview of various infostealer families, sorted by 30-day activity volume to help prioritize defense efforts.

Seamless API Integration for Proactive Defense

To truly block active command-and-control channels at the firewall or proxy level – stopping infected endpoints from exfiltrating credentials, receiving instructions, or dropping secondary payloads – automation is key.

API overview
Overview of the C2 Host Feed REST API endpoint for seamless integration.

All C2 datasets are fully accessible via REST API endpoints for seamless integration into your existing security stack. Using the GET /json/v3/threat-feeds/c2 endpoint, teams can retrieve observed infostealer C2 hosts with granular filters for host, malware family, country, ASN, feed type, date, and pagination.

Protect Your Organization from Imminent Intrusions

With our new Threat Feeds, cybersecurity teams can monitor live C2 infrastructure from infostealer campaigns, ClickFix networks, and PhaaS (Phishing-as-a-service) operations to proactively block malicious communications.

To learn more about how Hudson Rock protects companies from intrusions caused by info-stealer infections of employees, partners, and users, and how we enrich existing cybersecurity solutions with our cybercrime intelligence API, please schedule a call with us, here:
https://www.hudsonrock.com/schedule-demo

We also provide access to various free cybercrime intelligence tools that you can find here:
www.hudsonrock.com/free-tools

Thanks for reading, Rock Hudson Rock!
Follow us on LinkedIn: https://www.linkedin.com/company/hudson-rock
Follow us on Twitter: https://www.twitter.com/RockHudsonRock

Continue reading

Related articles

Free Tools Check your exposure