Overlord
117 addresses convicted as Overlord command-and-control servers — 116 still listed, 1 archived. Observed from 2026-08-25.
Detection packs
Rules for the 116 still-listed addresses on this page, regenerated as the archive updates; archived episodes are omitted, and a rule can lag a withdrawal by up to five minutes. Suricata rules are rev:2 — alert tcp on address and port, alert tls where a full certificate fingerprint is published — and carry the archive's own episode ids as sids, so packs load beside each other and beside any per-host file. YARA packs are hash matches only: this site holds no file bytes.
About
An open-source, Go-based C2 framework published on GitHub — by the handle "vxaboveground", since taken down — that builds native implants for Windows, macOS and Linux and extends through operator-supplied modules. It drew notice in mid-2026 when Proofpoint documented a North-Korea-aligned actor using it to phish developers with malicious code repositories and steal cryptocurrency. What is listed here is the control server — an identifiable TLS listener, frequently on port 5173 — not any particular implant, so a listing identifies the C2 infrastructure rather than a compromised developer's machine. Recently first observed in AS152194 on 2026-09-10 (3 hosts); AS136209 on 2026-09-08 (1 host); AS209630 on 2026-09-08 (1 host) — networks this family had not appeared in before, as seen by this archive. Upstream population estimate: hosts of this family observed moving toward AS55933 on 2026-09-04 (fewer than 10 hosts) — the upstream scanner's estimate from a passive search population, not this archive's observation, and shown only for networks where this archive holds at least one host of this family.
Ports
Addresses · page 1 of 2
Ordered by when this archive first recorded them, newest first — a stable ordering, so a page holds the same addresses tomorrow. Archived addresses are included and marked; they are the majority of this corpus over time.
Listed in error?
These pages are generated from automated scanning and are publicly available. Write to support@publicmosaic.com — see abuse & takedown, or opt-out to exclude a network range from scanning.