Multiple Mythic C2 Interfaces Exposed on Port 7443

Multiple Mythic C2 Interfaces Exposed on Port 7443

First seen 7 Sep 2026, 09:23 UTC Redpacketsecurity 65.2

Article Content

Browse articles
ThreatCluster

Three separate Mythic command-and-control (C2) web interfaces have been detected exposed on port 7443, located at IP addresses 20.115.227.161, 142.93.52.11, and 159.198.75.180. Each interface is served through nginx and redirects unauthenticated HTTP requests to a login page. The exposure of these interfaces poses significant risks, including unauthorized access to C2 administration, agent control, and data management. The services are hosted on Microsoft Azure and DigitalOcean, raising concerns about potential operator control or misuse. Security professionals are advised to restrict access to these ports, review logs, and rotate credentials if unauthorized access is suspected. No active exploitation or specific payload activity has been confirmed at this time, but the risk remains high due to the public exposure of these management interfaces.

Key Points: • Three Mythic C2 interfaces publicly exposed on port 7443. • Unauthorized access could lead to significant operational risks. • Immediate action required to restrict access and review logs.

Ask AI about this cluster

Timeline

2026-09-07
Mythic C2 detected at 20.115.227.161
An exposed Mythic management portal was identified, posing risks of unauthorized access and data exposure.
Redpacketsecurity
2026-09-07
Mythic C2 detected at 142.93.52.11
Another Mythic C2 interface was found, also exposing sensitive management capabilities over the internet.
Redpacketsecurity
2026-09-07
Mythic C2 detected at 159.198.75.180
A third Mythic C2 interface was reported, increasing concerns about potential unauthorized access.
Redpacketsecurity