Rust svc stealer TLS relay check-in to known C2 IP (GapiUpdate/NeedleStealer chain)
Detects Odyssey Stealer malware communicating with a known C2 infrastructure using TLS and performing data exfiltration via HTTP requests to raw-IP destinations using disguised file names such as analytics.gif, pixel.png, and content.js.
Suricata

