c2flow is a dark-web malware seller associated with advertising Noobsaibot, a C# Windows malware platform positioned as a combined stealer, hidden virtual network computing tool, and remote access trojan. The actor markets the tool as a stealth-focused, operator-friendly offering and emphasizes exclusive or high-value sale terms, source-code availability, and claimed antivirus and endpoint detection evasion. The malware advertised by c2flow is presented as supporting credential and cookie theft from Chromium-based browsers, including claimed bypass of modern browser protection mechanisms, as well as keylogging, hidden remote desktop access, standard remote administration, file and process management, and encrypted command-and-control communications. Additional advertised deployment and evasion features include reflective in-memory loading, randomized build characteristics, metadata spoofing, certificate cloning, file-size padding, persistence through common Windows mechanisms, and DLL sideloading. The actor also promotes operator control over logs, panels, and deployments. Available information supports c2flow as a malware vendor or developer rather than a clearly attributed state-backed intrusion set. No high-confidence evidence directly ties the actor to specific intrusion campaigns, victim geographies, or sector-focused operations. The observed activity is most consistent with financially motivated cybercrime enablement through the sale of commodity or mid-tier offensive tooling.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
8 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Advertising and developing Noobsaibot, a C# stealer/HVNC/RAT with browser credential and cookie theft, hidden remote access, keylogging, reflective loading, encrypted communications, and evasion features.
c2flow is a dark web actor selling the noobsaiBOT RAT, a modular, stealth-focused remote access trojan (RAT) framework. The actor markets the tool as an all-in-one solution for remote access, credential theft, file management, and persistence, targeting Windows systems. The tool is positioned for use by other cybercriminals, lowering the barrier to entry for conducting espionage, data theft, and potential ransomware staging.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.