TukTuk Malware Dead-Drop C2 Resolution via Goldsky Arweave Gateway
This rule detects network traffic directed at 'goldsky.arweave.net', a domain known to be used by the TukTuk malware as a dead-drop resolver. Adversaries often use legitimate web services like Arweave to host command-and-control (C2) configuration data, such as secondary C2 IP addresses or domains, allowing them to redirect infected hosts to backend infrastructure while masking the traffic as legitimate web communication.
Suricata

