PhonyC2 Malware — Analysis, Campaigns & Threat Activity

Threat entity extracted from intelligence sources

Frequency
1
occurrences
First Seen
January 12, 2026
Last Seen
January 12, 2026

PhonyC2 is a malware family that provides a command-and-control framework to manage implants.

Overview

PhonyC2 is a malware family that provides a command-and-control framework to manage implants. The referenced article describes Iran-linked MuddyWater deploying Rust-based tooling, which aligns with PhonyC2’s C2 architecture and highlights the actor’s shift toward Rust-enabled, modular malware campaigns in modern threat landscapes.

Related Threat Clusters

Recent Intelligence Reports

  • Iran-linked MuddyWater APT deploys Rust — Csoonline · January 12, 2026

CVSS v3.1 Breakdown