public mosaic llc support@publicmosaic.com
malware family

HypeAgent

21 addresses convicted as HypeAgent remote-access trojan controllers — 21 still listed, 0 archived. Observed from 2026-08-23.

TLP:CLEAR
addresses 21 21 still listed
observations 35 address and port pairs
networks 12 distinct ASNs
first seen 2026-08-23 oldest observation

Detection packs

Rules for the 21 still-listed addresses on this page, regenerated as the archive updates; archived episodes are omitted, and a rule can lag a withdrawal by up to five minutes. Suricata rules are rev:2 — alert tcp on address and port, alert tls where a full certificate fingerprint is published — and carry the archive's own episode ids as sids, so packs load beside each other and beside any per-host file. YARA packs are hash matches only: this site holds no file bytes.

About

A Windows command-and-control agent first seen in August 2026, delivered by purchase-order and invoice-themed script droppers rather than any published tool, and detected by Microsoft as Trojan:Win64/HypeAgent. Its implants beacon over TLS WebSockets to a fixed "/hype/ws" path, and its servers — concentrated on ports 7443 and 7080 across low-cost hosting — present a reusable certificate template distinctive enough that several scanners track them by fingerprint alone. No author, seller or source has been publicly identified; what is recorded here is a control server, not an infected machine. Upstream population estimate: hosts of this family observed moving toward AS36352 on 2026-09-01 (fewer than 10 hosts) — the upstream scanner's estimate from a passive search population, not this archive's observation, and shown only for networks where this archive holds at least one host of this family.

Ports

:744318:708014:70401:326051:326351

Addresses

Ordered by when this archive first recorded them, newest first — a stable ordering, so a page holds the same addresses tomorrow. Archived addresses are included and marked; they are the majority of this corpus over time.