Back Redpacketsecurity Mythic C2 Detected – 159.198.75.180159[.]198[.]75[.]180:7443
The host exposes a Mythic web interface on HTTPS port 7443. It redirects to /new/login and is fronted by nginx 1.25.5.
Why this matters and what to do now
What : An externally reachable C2 management interface is exposed on 159[.]198[.]75[.]180:7443.
Why : Unauthorised access could enable operator authentication attacks, campaign management or control of connected agents.
Do now : Confirm whether 159[.]198[.]75[.]180 and the Mythic deployment are authorised.
Do now : Restrict port 7443 to approved administration networks or VPN access.
Do now : Review Mythic, nginx and host authentication logs for suspicious access.
Do now : Rotate administrative credentials and TLS material if exposure was not intended.
Do now : enterprise telemetry for connections to 159[.]198[.]75[.]180 and the listed TLS fingerprints.
The evidence is strongly consistent with an internet-accessible Mythic command-and-control management interface. The product title, React asset paths, /new/login route, Mythic-branded TLS certificate and dedicated HTTPS port provide mutually supporting indicators. The data does not prove active malicious use, operator identity or current compromise. Mythic can be deployed for authorised security testing. Namecheap hosting and the exposed administrative login increase operational concern, but do not independently establish intent.
Alert on outbound or inbound connections to 159[.]198[.]75[.]180:7443.
Hunt proxy and DNS logs for requests to /new/login, /new/manifest[.]json and /new/favicon[.]ico.
Cluster TLS telemetry using the JARM 1dd40d40d00040d00042d43d000000831b6af40378e2dd35eeac4e9311926e and JA3S 574866101f64002c6421cc329e4d5458.
endpoint and network logs for Mythic agent traffic associated with this address.
Remove direct internet exposure of the Mythic management interface.
Permit administrative access only through a VPN, bastion host or allow-listed source ranges.
Enforce multi-factor authentication and strong unique administrator credentials.
Keep Mythic, nginx and the host operating system patched.
Monitor and retain authentication, reverse-proxy and host telemetry.
High, The product identification is supported by the title, product field, login route, application assets and Mythic-branded TLS certificate.
A considerable amount of time and effort goes into maintaining this website, creating backend automation and creating new features and content for you to make actionable intelligence decisions. Everyone that supports the site helps enable new functionality.
If you like the site, please support us on Patreon or Buy Me A Coffee using the buttons below.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
