Intrinsec
IP Cluster Linking Ransomware Activity and Eye Pyramid C2
Pages
22
Time to read
18 mins
Publication
Language
English
Pages
22
Time to read
18 mins
Publication
Language
English
This technical report presents findings related to the linking of ransomware activity and the Eye Pyramid command and control (C2) framework. The report details how a Python backdoor used by RansomHub affiliates facilitates access to compromised networks and utilizes offensive tools for post-compromise exploitation. The analysis illustrates the discovery of infrastructure associated with Eye Pyramid, including the identification of IP addresses linked to this tool since January 2025. The report further explains the functionality of Eye Pyramid, which is an open-source C2 framework that leverages Python to deploy offensive tools and payloads from within the legitimate python.exe process. Through the examination of banners and IP addresses, the report corroborates the relationship between these IP addresses and Eye Pyramid, distinguishing them from those associated with RansomHub’s Python backdoor. The findings underscore the need to enhance defensive measures against this evolving threat landscape, providing insights into specific indicators of compromise and recommendations for mitigation.