A Language Model Now Drives the Command and Control (08/22/2026)
- › Fourteen trojanized npm packages deliver RedC2 4.0, a cross-platform command and control framework that sells for $99.99.
- › Its Red Agent layer is backed by a language model and turns plain-English intent into beacon commands, which lowers the skill floor for operating it.
- › A supply chain compromise of a DoFun system app put a reverse-proxy module on Android car head units, turning them into residential proxy nodes running click fraud.
- › Kaspersky calls it the first documented infection chain built specifically for car head units, and attributes it to the MoYu group.
- › Lawmakers are calling for an investigation into the effect of CISA staffing cuts.
The interesting part of the RedC2 story is not the backdoor, which is ordinary, but the interface sitting on top of it. Version 4.0 ships with a layer that takes an operator’s plain-English intent and turns it into beacon commands, so running a multi-host intrusion no longer requires knowing the framework’s syntax. The whole thing sells for $99.99.
Top 5 Critical Security Alerts
1. RedC2 4.0 Arrives Through 14 npm Packages, With a Language Model on the Console
TrendAI and researcher Aliakbar Zahravi documented 14 trojanized npm packages delivering RedC2 4.0, a cross-platform framework covering Windows, macOS, and Linux with surveillance, credential theft, staged payload delivery, multi-beacon operation, host-to-host tunneling, and in-memory execution. Its Red Agent component is backed by a language model and converts natural-language intent into framework commands. The version history runs 2.0 in August 2025, 3.0 sold in January 2026, and 4.0 advertised in June 2026 on Hack Forums by an operator using the handle MarlboroMan, at a price of $99.99. The Hacker News
Operator Note: Price the skill floor rather than the tooling. A hundred dollars has bought a capable multi-platform framework for years, and what changed is that operating it no longer requires learning it, which widens the pool of people who can run a competent intrusion. Your detection assumption that unusual operator behaviour indicates unfamiliarity gets weaker as the console does the translating.
2. A Supply Chain Attack Put a Proxy Botnet in Car Head Units
Kaspersky traced a compromise of TWCore, a legitimate system app from head unit manufacturer DoFun, which pulls a rogue package containing JarService and then runs a second-stage loader. The payload is a reverse-proxy module named zhima that turns the vehicle’s infotainment system into a residential proxy node and runs advertising and click fraud. Researchers describe it as the first documented infection chain built specifically for car head units, and attribute it to the MoYu group, previously linked to the BadBox botnet. DoFun says the issue is resolved. BleepingComputer
Operator Note: These are generic aftermarket units that arrive in a vehicle through an installer rather than a manufacturer, which means no fleet inventory has them and no patch programme covers them. If you run vehicles with aftermarket infotainment, the practical exposure is that your company address becomes a residential proxy exit for somebody else’s traffic, and the first you hear of it is an abuse complaint.
3. Lawmakers Want an Investigation Into CISA Staffing Cuts
Members of Congress are calling for an investigation into what the staffing reductions at CISA have done to the agency’s capability. This lands in a month where CISA issued a three-day emergency directive on an exploited Ray flaw and co-signed the joint advisory on AI-written tooling against Siemens controllers. The Record
Operator Note: Private organizations lean on that agency more than they usually notice, through the Known Exploited Vulnerabilities catalogue, the joint advisories, and the sector alerting most vulnerability programmes are quietly built around. If the output slows, the gap lands on your own triage rather than on anybody in Washington.
4. Named Pipes Are Under Attack
Windows interprocess communication through named pipes is drawing attacker attention, and it is a channel most monitoring never looks at because the traffic never leaves the host to be inspected. BleepingComputer
Operator Note: Lateral movement and privilege escalation both run through this, and the reason it stays quiet is that a named pipe generates no network traffic for anyone to inspect. Ask your endpoint vendor what visibility you have into pipe creation and connection, because the honest answer is often less than you assumed.
5. Frontier Labs Will Not Say How They Would Contain a Rogue Model
Asked how they would contain a model behaving outside its intended bounds, the major AI labs have not given an answer. The question follows a month that included an autonomous agent incident at Hugging Face and a disclosed classifier outage running eleven months. TechCrunch
Operator Note: Read it as a vendor risk answer rather than a philosophical one. If you have an agent with credentials in your environment, the containment question belongs to you regardless of what the lab publishes, which means knowing what it can reach, holding a kill path you have tested, and scoping the credential to the task rather than to the team.
Additional Security Alerts
Threat Intelligence
- Rust crates are still being poisoned to steal developer credentials: The campaign we noted yesterday continues, with North Korean actors tied to it. The Register
Security Tools & Best Practices
- The case for using AI to attack your own systems before somebody else does: Offensive tooling is getting cheaper for both sides, and the side that runs it against itself first gets the findings. The Register
- A look at Wazuh and AI in security operations workflows: Practical rather than promotional, and worth reading if you run an open-source detection stack. The Hacker News
- AWS made a security choice that has practitioners puzzled: Corey Quinn walks through the reasoning and where it falls down. The Register
The Axe Report is a daily briefing from Grab The Axe. Need help assessing your organization’s security posture? Take our free Human Attack Surface Score assessment.
Operating on the philosophy that 'you can't build a secure system if you don't know how to break it,' Chris leads our engineering division. A top 1% National Cyber League competitor, he hardens our digital infrastructure against the very exploits he has mastered.
View Profile →Media Inquiries
For expert commentary, interview requests, or high-res assets regarding this announcement, initialize the terminal.