Supershell C2 - Tool

Threat entity extracted from intelligence sources

Frequency
2
occurrences
First Seen
January 13, 2026
Last Seen
January 13, 2026

Supershell C2 appears in the context of campaigns exploiting a zero-day in the Gogs self-hosted Git service.

Overview

Supershell C2 appears in the context of campaigns exploiting a zero-day in the Gogs self-hosted Git service. The activity has drawn CISA’s attention, with the zero-day added to the Known Exploited Vulnerabilities list and federal agencies urged to patch or retire Gogs to prevent compromise. This underscores the risk of exposed self-hosted services and the role of C2-like tooling in post-exploitation, marking Supershell C2 as a significant concern for cybersecurity defense, particularly in federal environments.

Related Threat Clusters

Recent Intelligence Reports

  • Fed agencies urged to ditch Gogs as zero-day makes CISA list — Theregister · January 13, 2026
  • Federal agencies told to fix or ditch Gogs as exploited zero — Theregister · January 13, 2026

CVSS v3.1 Breakdown