Digital illustration of a trojan horse icon integrated with code snippets and a Linux terminal, symbolizing a stealthy AI-powered cyber threat.
Uncategorized

AI-Powered Linux Backdoor Unleashed: The Stealthy Threat of RedC2 4.0 in npm Packages

Share
Share
Pinterest Hidden

In a significant development for the cybersecurity landscape, researchers have unveiled a sophisticated new threat: 14 trojanized npm packages designed to masquerade as benign utilities while secretly deploying an advanced, AI-powered Linux implant known as RedC2 4.0.

The Trojan’s Deceptive Disguise

These malicious packages, deceptively appearing as functional calendar and streak utilities, leverage a cunning method of infection. Unlike typical malware that relies on explicit installation hooks, RedC2 4.0’s payload activates with a mere import. “When the module loads, it locates the bundled binary, marks it executable, and launches it as a detached background process,” explains TrendAI, Trend Micro’s enterprise cybersecurity arm. This means even a transitive dependency can trigger the execution, making detection challenging.

The identified packages include:

  • streak-metrics-math@1.0.0, 1.0.1
  • kit-map-vim@1.0.0
  • streak-map-cache@1.0.0
  • streak-map-kit@1.0.0
  • map-streak-kit@1.0.0
  • streak-cache-map@1.0.0
  • streak-calc-metrics@1.0.0
  • streak-calc-math@1.0.0
  • streak-math-abz@1.0.0
  • streak-metricsaz@1.0.0
  • streak-math-metrics@1.0.0
  • streak-metricazbd@1.0.0
  • streak-metricsazb@1.0.0
  • streak-kit-map@1.0.0

Beneath their innocuous facade, these packages conceal a Linux backdoor, cleverly disguised as a “native math accelerator.” The embedded binary, with names like math-core.bin or calc.bin, is the notorious RedShell Linux beacon, the core component of RedC2 4.0. This beacon establishes communication with a remote command-and-control (C2) server, paving the way for extensive post-exploitation activities on compromised systems.

RedC2 4.0: A Multi-Platform Menace

Evolution of a Sophisticated C2 Framework

RedC2 4.0 is not a nascent threat; it’s the latest iteration of a rapidly evolving cross-platform toolkit advertised on cybercrime forums. Marketed by a threat actor known as “MarlboroMan” on Hack Forums in early June 2026, it boasts “evasion” as a core design principle. Its predecessors, RedC2 3.0 (sold earlier this January) and RedC2 2.0 (released in August 2025), indicate a year of active, aggressive development.

This feature-rich C2 framework offers a comprehensive suite of capabilities, including:

  • Terminal access and file transfer
  • Staged payload delivery and data collection
  • Multi-beacon operation and network visualization
  • Host-to-host tunneling and in-memory execution of various binaries (BOFs, .NET assemblies, shellcode)
  • Surveillance and credential theft
  • Mass-operation capabilities

The RedShell Linux Beacon in Action

Once deployed, the RedShell Linux beacon provides an interactive shell, granting attackers profound control. It facilitates system discovery, file operations, and critical data collection, such as SSH keys and browser credentials. It also enables persistence, in-memory ELF execution, SOCKS5 proxying, and network pivoting. Upon establishing contact with its C2 server, the beacon registers the compromised system with a “check-in message” and enters a command-processing loop, ready to execute instructions and relay results.

While the Linux variant is potent, RedC2 4.0 also targets Windows and macOS. The Windows beacon, in particular, includes advanced features like User Account Control (UAC) bypass, antivirus tampering, and lateral movement capabilities, which are absent in the macOS version.

The Irony of “Ethical” Hacking Tools

Intriguingly, RedC2 is sold on a clearnet website, Red Offsec, for $99.99. The site’s terms of service paradoxically prohibit its use for “unauthorized computer access” and “hacking without explicit permission,” claiming the tools are “intended for red team professionals and users who understand external offensive security tooling within legal and ethical boundaries.” This highlights the blurred lines and inherent risks associated with powerful offensive security tools falling into the wrong hands.

AI: The New Frontier of Cyber Exploitation

Perhaps the most alarming feature of RedC2 4.0 is its integration of an AI-powered component called Red Agent. This large language model (LLM)-driven extension, coupled with the command-line interface RedC2 EXT, empowers operators to orchestrate complex post-exploitation tasks using natural language commands. This represents a significant leap in the sophistication and accessibility of cyber exploitation, making advanced attacks easier to execute for a broader range of threat actors.

Staying Vigilant in an Evolving Threat Landscape

The discovery of these trojanized npm packages and the capabilities of RedC2 4.0 underscore the critical need for robust supply chain security and vigilant monitoring. Developers must exercise extreme caution when incorporating third-party packages, and organizations must implement advanced endpoint detection and response (EDR) solutions to identify and neutralize such stealthy, AI-assisted threats.


For more details, visit our website.

Source: Link

Share

Leave a comment

Leave a Reply

Your email address will not be published. Required fields are marked *