Thursday, September 10, 2026

GreyNoise Launches C2 Detection for Exploited Edge Devices

GreyNoise has introduced a new capability, C2 Detection, to identify compromised edge devices such as firewalls, routers, and VPN systems assets that are increasingly targeted but often lack visibility in traditional security tools.

Unlike endpoints, these devices rarely generate alerts when exploited. There are no EDR agents, minimal logging, and almost no obvious signs of compromise.

Instead, once breached, they silently connect to attacker-controlled infrastructure, download malicious payloads, and wait for further instructions. From a defender’s perspective, nothing appears wrong while attackers quietly maintain access.

Edge and perimeter devices are now among the most actively exploited systems on the internet. Yet, security teams struggle to monitor them effectively.

GreyNoise’s C2 Detection addresses this gap by focusing on outbound traffic, which is often the only indicator of compromise.

According to the report, the system works by analyzing exploit payloads observed across GreyNoise’s global sensor network. Instead of waiting for attacks to succeed in the wild, GreyNoise extracts embedded callback destinations directly from these payloads.

It then collects and studies malware hosted at those locations, mapping out the attacker’s infrastructure from initial payload delivery to command-and-control (C2) servers.

This approach, described as payload-derived intelligence, allows GreyNoise to build a continuously updated dataset of malicious callback IPs and associated malware hashes.

Turning Outbound Traffic

Security teams can use this intelligence to detect compromised devices by correlating outbound traffic logs with GreyNoise callback dataset.

For example, if a firewall in an organization initiates a connection to a known malicious callback IP, that activity becomes a strong indicator of compromise. GreyNoise enhances this with context, helping analysts understand the attack stage and respond accordingly.

The platform integrates with SIEM and SOAR tools via API, enabling automated workflows:

  • A match with a file download server may trigger an investigation.
  • A match with suspected C2 infrastructure can prompt immediate containment actions.

Additionally, because attacker infrastructure often remains active longer than scanning sources, teams can perform historical analysis to trace when the compromise may have started.

GreyNoise classifies callback IPs into three stages to provide clear severity levels:

  • Unconfirmed: Observed in payloads but no confirmed malware delivery.
  • Stage 1 (File Downloaded): Confirmed hosting of malicious payloads.
  • Stage 2 (C2 Suspected): Strong evidence of active command-and-control activity.

This model aligns detection with the attacker’s position in the kill chain, allowing defenders to prioritize responses based on real risk.

Expanding Beyond Inbound Threats

Previously, GreyNoise focused on inbound scanning activity tracking IPs probing the internet for vulnerable systems. With C2 Detection, the company moves into post-exploitation visibility, offering insight into outbound communications from compromised devices.

The new capability introduces:

Importantly, it complements GreyNoise’s existing signal: identifying when an organization’s device is scanning the internet as part of a botnet.

Now, with outbound callback detection, security teams gain a second, independent confirmation of compromise.

In practice, this means defenders no longer have to rely solely on limited logs or indirect indicators.

By turning outbound traffic into a high-confidence detection signal, GreyNoise provides a clearer answer to a previously silent problem GreyNoise Launches C2 Detection for Exploited Edge Deviceswhether a critical network device has already been breached.

Follow us on Google NewsLinkedIn, and X to Get Instant Updates and Set GBH as a Preferred Source in Google.

Mayura Kathir
Mayura Kathirhttps://gbhackers.com/
Mayura Kathir is a cybersecurity reporter at GBHackers News, covering daily incidents including data breaches, malware attacks, cybercrime, vulnerabilities, zero-day exploits, and more.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

OpenMatter Network Realigns Leadership Team to Accelerate Global Commercial Growth

Melbourne, Florida, September 10th, 2026, CyberNewswire With its Verification Architecture...

Hackers Can Turn Vulnerable LiteLLM AI Gateways Into Root Access and Cloud Credential Theft

Nearly one in 10 internet-exposed LiteLLM AI gateways accepted...

Skullcandy Dime 3 Bluetooth Flaw Lets Nearby Attackers Hijack Audio and Microphone

Skullcandy Dime 3 wireless earbuds have a serious vulnerability...

Hackers Steal Active Directory Password Hashes Without Attacking Domain Controllers Directly

Threat actors are increasingly exploiting Active Directory replication mechanisms...

Fake GTA 6 Installer Steals Browser Passwords, Discord Tokens and Crypto Data From Gamers

Threat actors are exploiting anticipation around Grand Theft Auto...

Apple Xcode Integer Underflow Flaw Lets Crafted Archives Leak Memory and Crash Builds

A recently disclosed integer-underflow vulnerability in Apple’s modern Mach-O...

Palo Alto PAN-OS Buffer Overflow Lets Attackers Execute Arbitrary Code as Root

Palo Alto Networks has announced a high-severity buffer overflow...

New Phishing Attack Uses Blob URLs to Hide Malicious Pages From Security Scanners

A phishing campaign that moves the credential-harvesting page out...

Related Articles

Recent News