ArenaC2 is a Python-based command-and-control framework attributed with high confidence to the Iranian state-linked espionage group MuddyWater (also tracked as Static Kitten, Mango Sandstorm, Earth Vetala, Seedworm, and TA450). Reporting states that it was recovered from exposed MuddyWater infrastructure alongside other custom frameworks including KeyC2 and PersianC2. ArenaC2 operates over HTTP POST using a FastAPI/uvicorn web server, encrypts traffic with AES-256-CBC, and presents a decoy website named ArenaReport. Separate reporting noted communication patterns closely aligning with ArenaC2 in a broader campaign targeting primarily aviation, energy, and government organizations in the Middle East, with additional targeting in Portugal and India. That campaign involved large-scale reconnaissance and exploitation of internet-facing systems, Outlook Web Access brute-force activity, credential theft, and confirmed data exfiltration. High-confidence associated activity includes MuddyWater operations against organizations in Israel, Jordan, Egypt, the UAE, Portugal, and the United States. No malware-specific infection vector for ArenaC2 itself is directly described beyond its use as part of MuddyWater post-compromise C2 infrastructure.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Ctrl-Alt-Intel identified an additional Python-based C2 framework on the MuddyWater server, which we have coined ArenaC2. Unlike Key C2’s custom UDP protocol or PersianC2’s JSON API polling, ArenaC2 operates over HTTP POST using a FastAPI/uvicorn web server and encrypts all traffic with AES-256-CBC.
9 distinct techniques documented for this family, organized by ATT&CK tactic.
More advanced HTTP-based controllers were also found, managing encrypted client sessions through API-style endpoints such as /command, /result, /signup, and /feed.
PersianC2 used standard HTTP polling... This bot communicates over WebSocket to retrieve commands.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A command-and-control framework associated in the content with MuddyWater. The observed campaign’s multi-layered TCP, UDP, and HTTP-based controllers, encrypted communications, and host tracking patterns were said to align closely with ArenaC2.
Named command-and-control framework/tool associated with MuddyWater infrastructure and a multi-framework Express/Node.js server.
A Python FastAPI-based encrypted HTTP C2 framework that uses AES-256-CBC, presents a decoy website, supports staging, victim registration, tasking, shell output handling, uploads, and secondary payload delivery.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.