Open Source
C2
Python
Octopus
Octopus
Octopus is a Python-based command-and-control (C2) server used to control a PowerShell agent over HTTP/S. It is part of the Phobos ransomware family and is designed to encrypt files and prevent access.
Known Variants
Known Variants
Includes modular versions adapted for targeted campaigns.
Includes modular versions adapted for targeted campaigns.
Mitigation Strategies
Mitigation Strategies
Deploy endpoint monitoring tools to detect malicious PowerShell activity, segment networks to prevent lateral movement, and use multi-factor authentication to secure access points.
Targeted Industries or Sectors
Targeted Industries or Sectors
Often targets telecommunications and government entities in Eastern Europe, focusing on espionage and data theft.
Often targets telecommunications and government entities in Eastern Europe, focusing on espionage and data theft.
Associated Threat Actors
Associated Threat Actors
Frequently associated with Russian-speaking threat groups conducting targeted attacks.
Frequently associated with Russian-speaking threat groups conducting targeted attacks.
References
Threat Hunting Platform - Hunt.io
Products
Hunt Intelligence, Inc.
Threat Hunting Platform - Hunt.io
Products
Hunt Intelligence, Inc.
Threat Hunting Platform - Hunt.io
Products
Hunt Intelligence, Inc.