Bandook C2 Outbound Traffic - Dark Caracal (AlexHost Infra)
This rule detects outbound network connections from internal hosts to specific IP addresses associated with known AlexHost infrastructure identified as command-and-control (C2) servers for the Bandook Remote Access Trojan (RAT), which is utilized by the threat actor Dark Caracal.
Suricata

