HypeAgent
21 addresses convicted as HypeAgent remote-access trojan controllers — 21 still listed, 0 archived. Observed from 2026-08-23.
Detection packs
Rules for the 21 still-listed addresses on this page, regenerated as the archive updates; archived episodes are omitted, and a rule can lag a withdrawal by up to five minutes. Suricata rules are rev:2 — alert tcp on address and port, alert tls where a full certificate fingerprint is published — and carry the archive's own episode ids as sids, so packs load beside each other and beside any per-host file. YARA packs are hash matches only: this site holds no file bytes.
About
A Windows command-and-control agent first seen in August 2026, delivered by purchase-order and invoice-themed script droppers rather than any published tool, and detected by Microsoft as Trojan:Win64/HypeAgent. Its implants beacon over TLS WebSockets to a fixed "/hype/ws" path, and its servers — concentrated on ports 7443 and 7080 across low-cost hosting — present a reusable certificate template distinctive enough that several scanners track them by fingerprint alone. No author, seller or source has been publicly identified; what is recorded here is a control server, not an infected machine. Upstream population estimate: hosts of this family observed moving toward AS36352 on 2026-09-01 (fewer than 10 hosts) — the upstream scanner's estimate from a passive search population, not this archive's observation, and shown only for networks where this archive holds at least one host of this family.
Ports
Addresses
Ordered by when this archive first recorded them, newest first — a stable ordering, so a page holds the same addresses tomorrow. Archived addresses are included and marked; they are the majority of this corpus over time.
Listed in error?
These pages are generated from automated scanning and are publicly available. Write to support@publicmosaic.com — see abuse & takedown, or opt-out to exclude a network range from scanning.