MarlboroMan ecosystem shift changes threat-actor operations
Threat Actor Meta
Summary
Hide ▲
Show ▼
MarlboroMan publicly marketed RedC2 4.0 as a cross-platform C2 framework, widening access to evasion-focused intrusion tooling across Windows, macOS, and Linux. The offering packages surveillance, credential theft, payload loading, and mass-operation functions into a purchasable underground product. Its Red Agent layer adds LLM-driven command execution, reducing operator effort and increasing task speed. The result is a more commercialized and scalable offensive-tool ecosystem.
Related Happenings
Trojanized npm packages deliver RedC2 4.0 Linux implant
Malware Activity
H score31
First: 21.08.2026 21:53
Last: 21.08.2026 21:53
Sources 1
How related:
Cybersecurity researchers have discovered a set of trojanized npm packages that masquerade as working calendar and streak utilities but are engineered to stealthily deliver an artificial intelligence (AI)-powered Linux implant dubbed RedC2 4.0.
About this happening:
Trojanized npm packages are now delivering the RedC2 4.0 Linux implant through a supply-chain execution path, turning a routine package import into remote malware depl...
Trojanized npm packages deliver RedC2 4.0 Linux implant
Malware ActivityHow related: Cybersecurity researchers have discovered a set of trojanized npm packages that masquerade as working calendar and streak utilities but are engineered to stealthily deliver an artificial intelligence (AI)-powered Linux implant dubbed RedC2 4.0.
About this happening: Trojanized npm packages are now delivering the RedC2 4.0 Linux implant through a supply-chain execution path, turning a routine package import into remote malware depl...
Armored Likho spear-phishing and malware-delivery campaign targeting government and power sectors
Campaign
H score37
First: 03.07.2026 16:36
Last: 03.07.2026 16:36
Sources 1
About this happening:
The Armored Likho campaign is using spear-phishing and malware-delivery chains to target government agencies and the electric power sector across Russia, Brazil,...
Armored Likho spear-phishing and malware-delivery campaign targeting government and power sectors
CampaignAbout this happening: The Armored Likho campaign is using spear-phishing and malware-delivery chains to target government agencies and the electric power sector across Russia, Brazil,...
The Gentlemen affiliate-driven RaaS expansion and enterprise scale-up
Threat Actor Meta
H score57
First: 21.04.2026 17:00
Last: 21.04.2026 17:00
Sources 1
About this happening:
The Gentlemen ransomware-as-a-service operation is using an operator-maintained EDR-killer portfolio, led by GentleKiller, to disable security software before encrypti...
The Gentlemen affiliate-driven RaaS expansion and enterprise scale-up
Threat Actor MetaAbout this happening: The Gentlemen ransomware-as-a-service operation is using an operator-maintained EDR-killer portfolio, led by GentleKiller, to disable security software before encrypti...
Shadow-Void-044 and Shadow-Earth-045 PeckBirdy cyber-espionage campaigns
Campaign
H score34
First: 28.01.2026 18:19
Last: 28.01.2026 18:19
Sources 1
About this happening:
Two China-aligned PeckBirdy espionage campaigns were identified, widening risk to Chinese gambling websites, Asian government entities, and a Philippine educatio...
Shadow-Void-044 and Shadow-Earth-045 PeckBirdy cyber-espionage campaigns
CampaignAbout this happening: Two China-aligned PeckBirdy espionage campaigns were identified, widening risk to Chinese gambling websites, Asian government entities, and a Philippine educatio...
Timeline
-
21.08.2026 21:53 2 articles · 2h ago
MarlboroMan ecosystem shift changes threat-actor operations
Initial DisclosureIn early June 2026, MarlboroMan promoted RedC2 4.0 on Hack Forums as an evasion-focused framework for Windows, Linux, and macOS. The listing positioned the toolkit as a purchasable underground product rather than a one-off payload.
Show sources
- 14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2 — thehackernews.com — 21.08.2026 21:53
- 14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2 — thehackernews.com — 21.08.2026 21:53