Skip to main content
← Back to Demos
Malware intermediate · 15 min

Sandbox captures periodic C2 beacon network behavior

NightSpire ransomware has compromised at least 64 organizations across healthcare, government, finance, and other sectors in 33 countries, including Taiwan, blending in by abusing legitimate admin tools such as PSExec, Cobalt Strike, and PowerShell. A signature of such intrusions is periodic command-and-control beaconing — compromised hosts phoning home at regular intervals, an application-layer communication pattern mapped to T1071.001. This demo runs a benign executable that sends loopback-only beacon traffic, so no external network is touched. Adaptive Sandbox isolates the sample, captures the beacon's regularity, destinations, and payloads, and surfaces the suspicious C2 behavior in a clear report executives can act on.

Attack Technique

C2 beaconing

MITRE ATT&CK

T1071.001 ↗

Platforms

linuxmacoswindows

File Types

.sh

MetaDefender Capabilities

Adaptive Sandbox

Incident Coverage

This attack technique maps to a real-world security incident — read the daily digest for details: Read the incident digest ↗

--- ---