• CommunityEnterprisePlans
  • Intel Exchange
    Intel ExchangeDetections
  • Resources
  • About
  • Leaderboard
Join CommunitySign In
    All Detections

    Bird Agent MQTT C2 Beaconing via HiveMQ Broker Infrastructure

    avatar
    GlassDiceBearhttps://www.dicebear.comhttps://creativecommons.org/publicdomain/zero/1.0/„Glass” (https://www.dicebear.com) by „DiceBear”, licensed under „CC0 1.0” (https://creativecommons.org/publicdomain/zero/1.0/)
    Ibrahim Saud@tektrix
    •updated 22 days ago•0•0•3

    This rule detects outbound network communications (TLS, MQTT, and HTTP) to HiveMQ infrastructure. The pattern of activity suggests the presence of 'Bird Agent' malware utilizing the MQTT protocol for command and control (C2) communication, as well as periodic HTTP beaconing to HiveMQ broker endpoints.

    Suricata

    Tags

    TA0011 - Command and ControlT1071.001 - Web ProtocolsNetwork Connection OutboundIDS IPS AlertNetwork Data TransferNetwork GenericSuricata IDSSnort IDSTlsTrojan Activity

    Found in

    • Three Threat Groups Target Russian Enterprises with BackdoorsLast updated 23 days ago
    • Three Threat Groups Target Russian Enterprises with BackdoorsLast updated 23 days ago
    • Three Threat Groups Target Russian Enterprises with BackdoorsLast updated 23 days ago
    • Three Threat Groups Target Russian Enterprises with BackdoorsLast updated 23 days ago
    • Three Threat Groups Target Russian Enterprises with BackdoorsLast updated 23 days ago

    Community Inspired.
    AI Enhanced.
    Better Detections.

    Follow Us

    Company

    • About
    • Leaderboard

    Product

    • Community
    • Enterprise
    • Plans

    © 2026 Copyright. All Rights Reserved.

    Privacy PolicyTerms of Service

    Sign up to view this detection

    or

    Already have an account?