NimPlant is a lightweight first-stage command-and-control implant and server framework associated with red team use and post-exploitation activity. The provided content describes two related usages under the same name: an open-source cross-platform implant for Linux and Windows written in Nim and designed for Mythic C2, and a publicly released lightweight C2 framework by Cas van Cooten implemented with Nim, Rust, and Python that currently supports x64 Windows implants. Reported payload formats include .exe, self-deleting .exe, .dll, and .bin shellcode. Documented capabilities include encrypted and compressed C2 traffic, string obfuscation, file operations, process and job management, shell execution, environment variable access, file upload and download, local enumeration, registry management, web requests, BOF execution, shellcode injection, PowerShell execution in a custom runspace, and in-memory .NET assembly execution. The Mythic-oriented variant is described as deprecated, compatible only with Mythic 2.1, and currently using an HTTP C2 profile; planned features mentioned in the content include WebSocket communications, screenshotting, remote process injection, Objective-C compilation for macOS, and Donut integration.
The content also places NimPlant in real-world intrusion activity. Cisco Talos reported a Nim-based backdoor likely based on NimPlant in Cluster 8 activity exploiting Cisco Catalyst SD-WAN vulnerabilities in 2026. That backdoor was described as capable of file operations, executing files via bash, and collecting system information. Talos also reported a modified Nim-based implant named "agent1" that was most likely based on the open-source tool Nimplant. Associated activity included deployment alongside the KScan asset mapping tool and other post-compromise tooling. The content further references NimPlant C2 infrastructure in hunting research. The NimPlant documentation explicitly warns that its web frontend and API do not support authentication and advises against exposing them to untrusted networks.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Cluster 8 (Active since at least March 10, 2026), which deploys the KScan asset mapping tool and Nim-based backdoor that's likely based on NimPlant and comes with capabilities to perform file operations, execute files using bash, and collect system information
Cluster 8 (Active since at least March 10, 2026), which deploys the KScan asset mapping tool and Nim-based backdoor that's likely based on NimPlant and comes with capabilities to perform file operations, execute files using bash, and collect system information
Cluster 8 (Active since at least March 10, 2026), which deploys the KScan asset mapping tool and Nim-based backdoor that's likely based on NimPlant and comes with capabilities to perform file operations, execute files using bash, and collect system information
CVE-2026-20182 carries a CVSSv3.1 score of 10.0 (Critical) and is classified under CWE-287: Improper Authentication. The flaw affects the Cisco Catalyst SD-WAN Controller (formerly vSmart)... The peering authentication mechanism is not functioning correctly, allowing an unauthenticated, remote attacker to bypass authentication and obtain administrative privileges on the affected system.
24 distinct techniques documented for this family, organized by ATT&CK tactic.
shell shell [command] Run a shell command which will translate to a process being spawned with command line: cmd.exe /r[command]
shinject (GUI) [targetpid] [localfilepath] Load raw shellcode from a file and inject it into the specified process's memory space using dynamic invocation.
cp cp [source] [destination] Copy a file from source to destination... mv mv [source] [destination] Move a file from source to destination... rm rm [path] Remove a file specified by [path]
ipconfig List IP address information of the currently selected NimPlant.
getenv getenv Get all of the current environment variables.
Hunting C2/Adversaries Infrastructure with Shodan and Censys ... My research Cobalt Strike C2 Metasploit/MSF Covenant C2 Deimos C2 Posh C2 Brute Ratel C4 Mythic C2 Sliver C2 ... Night Hawk C2 NimPlant C2 ShadowPad C2 Infrastructure Async Rat C2 Infrastructure Meterpreter C2 Infrastructure
7 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Nim-based backdoor, or likely derivative, used for file operations, bash execution, and system information collection on compromised devices.
A Nim-based backdoor used in post-exploitation against Cisco Catalyst SD-WAN targets.
An open-source Nim-based implant/backdoor referenced as the likely basis for a modified post-compromise implant with expanded file, execution, and system reconnaissance capabilities.
The content references NimPlant C2 infrastructure as part of adversary infrastructure hunting.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.