APT37 Chinotto Python backdoor C2 POST with token cookie and spoofed Chrome UA
Detects outbound HTTP POST requests to a specific URL pattern (/board/fckeditor/userfiles/editor/board.php) associated with the Chinotto backdoor used by the APT37 threat group. The rule monitors for a specific Chrome user agent and a 'token=' cookie value, indicating a potential C2 check-in.
Suricata

