DeimosC2 is an open-source, GoLang-based command-and-control framework with RAT-like capabilities comparable to Cobalt Strike and Sliver. In the provided reporting, it is associated with DPRK-linked Lazarus Group / Andariel activity and is explicitly listed by U.S. and partner agencies as an open-source or dual-use tool used and/or customized by the actors. In one documented Lazarus campaign exploiting CVE-2022-47966 in ManageEngine ServiceDesk, researchers observed an unmodified DeimosC2 agent deployed as a Linux ELF implant for initial or persistent access on compromised Linux servers. The beacon was described as generated by the DeimosC2 server and using out-of-the-box URI paths. The same campaign reused infrastructure that also hosted QuiteRAT, CollectionRAT, and a trojanized PuTTY Plink utility, and the shared infrastructure was used for command-and-control. More broadly, joint government reporting includes DeimosC2 among the open-source and dual-use tools used by Andariel alongside utilities such as 3Proxy, Impacket, PLINK, Stunnel, and web shells. The surrounding reporting states Andariel targets defense, aerospace, nuclear, engineering, medical, and energy sectors, typically gaining access through exploitation of public-facing applications and known vulnerabilities including Log4Shell and other CVEs.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The authoring agencies have identified the following open source and dual-use tools as used and/or customized by the actors: ▪ DeimosC2
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Open-source Go-based C2 framework; Lazarus used an apparently unmodified Linux ELF beacon/agent for initial and persistent access. Supports typical RAT functions (command execution, file transfer, credential/registry dumping, shellcode execution, uninstall).
Command-and-control framework used to manage compromised hosts.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.