c2 framework
A2A C2
A bespoke Python agent-to-agent C2 built by a Russian-speaking operator, with an LLM-assisted credential pipeline behind it. Named by 2 reports, 5 detection rules, 0 IOC feeds and 1 tracked actor.
Also written as: Russian-A2A-C2, A2A-C2-Client-Console, A2A-C2-Server-Unauthenticated, A2A-C2-PowerShell-Loader, A2A-C2-Operator-Attribution, custom Python C2. These are the spellings the rules, feeds and profiles use; the page collects all of them.
Reports
Detection rules
YARA rules whose family metadata names this family, by detection page.
Detection rules
Multi-Actor AI-Agent Framework Abuse (8 Operators)
MAL_Python_Russian_A2A_C2_BaseHTTPServer
Detection rules
Russian Gemini CLI Credential Mill (213.165.51.115)
MAL_Python_A2A_C2_Server_Unauthenticated
Detection rules
Russian Gemini CLI Credential Mill (213.165.51.115)
MAL_Python_A2A_C2_Client_Console
Detection rules
Russian Gemini CLI Credential Mill (213.165.51.115)
MAL_PowerShell_WindowsUpdateManager_Stealer_Loader
Detection rules
Russian Gemini CLI Credential Mill (213.165.51.115)
MAL_Russian_Operator_Persona_Strings
Tracked actors
Designations whose profile lists this family as tooling.
- UTA-2026-012: AI-augmented credential-mill operator using an LLM for per-target password mutation
A family name here is the label the linked rule, feed or profile carries, normalised to one spelling by _data/families.yml. Where a report declines to name a family, this page does not either.