<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/one-c2-kit-30-customers-2-governments-paxnp2bqi" -->

---
title: One C2 kit. 30 customers. 2 governments | daily.dev
description: A threat intelligence researcher discovered that a blockchain-based C2 kit was shared among roughly 30 operators — including two plausibly state-aligned actors...
canonical: https://daily.dev/posts/one-c2-kit-30-customers-2-governments-paxnp2bqi
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: One C2 kit. 30 customers. 2 governments | daily.dev
og:description: A threat intelligence researcher discovered that a blockchain-based C2 kit was shared among roughly 30 operators — including two plausibly state-aligned actors...
og:url: https://daily.dev/posts/one-c2-kit-30-customers-2-governments-paxnp2bqi
og:image: https://api.daily.dev/og/posts/pAXNp2bqI.png
og:image:alt: One C2 kit. 30 customers. 2 governments
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# One C2 kit. 30 customers. 2 governments

**[CSO Online](https://daily.dev/sources/csoonline)** · 7 min read · 0 upvotes · 0 comments

## Summary

A threat intelligence researcher discovered that a blockchain-based C2 kit was shared among roughly 30 operators — including two plausibly state-aligned actors and ~28 criminal groups — all sourced from the same builder. This structural convergence of nation-state and criminal infrastructure undermines traditional SOC triage logic, which routes severity based on presumed actor identity. The post argues that shared tooling is an anti-signal for attribution, not a weak one, and recommends three practical changes: sever severity from attribution, anchor detections on durable technical constants rather than rotating infrastructure, and cap attribution confidence explicitly in reports. Supporting evidence from Mandiant, Microsoft, CISA, and FBI shows Russia, China, Iran, and North Korea all reaching the same destination — rented or stolen criminal infrastructure — via different routes.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://www.csoonline.com/article/4205129/one-c2-kit-30-customers-2-governments.html>

## Similar posts on daily.dev

- [Threat intelligence supply chain is full of weak links](https://daily.dev/posts/threat-intelligence-supply-chain-is-full-of-weak-links-o5sstfxpk) · The Register · 0 upvotes · 0 comments
- [Response to CISA Advisory \(AA25-343A\): Pro-Russia Hacktivists Conduct Opportunistic Attacks Against US and Global Critical Infrastructure](https://daily.dev/posts/response-to-cisa-advisory-aa25-343a-pro-russia-hacktivists-conduct-opportunistic-attacks-against--etypghjmt) · Security Boulevard · 0 upvotes · 0 comments
- [The espionage reality: Your infrastructure is already in the collection path](https://daily.dev/posts/the-espionage-reality-your-infrastructure-is-already-in-the-collection-path-d0b0xclte) · CSO Online · 0 upvotes · 0 comments

---

Tags: [#malware](https://daily.dev/tags/malware)

[View this post on daily.dev](https://daily.dev/posts/one-c2-kit-30-customers-2-governments-paxnp2bqi)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"One C2 kit. 30 customers. 2 governments","url":"https://daily.dev/posts/one-c2-kit-30-customers-2-governments-paxnp2bqi","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/one-c2-kit-30-customers-2-governments-paxnp2bqi"},"datePublished":"2026-08-05T10:07:28.847Z","dateModified":"2026-08-05T10:07:56.994Z","description":"A threat intelligence researcher discovered that a blockchain-based C2 kit was shared among roughly 30 operators — including two plausibly state-aligned actors...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/0775f79fc92411aaecb9885c3109ca78?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/0775f79fc92411aaecb9885c3109ca78?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"CSO Online","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"CSO Online","logo":"https://media.daily.dev/image/upload/t_logo,f_auto/v1/logos/98667e4b5cac46cf9c470819c6cf71cd","url":"https://daily.dev/sources/csoonline"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/one-c2-kit-30-customers-2-governments-paxnp2bqi","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"malware","timeRequired":"PT7M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"CSO Online","item":"https://daily.dev/sources/csoonline"},{"@type":"ListItem","position":3,"name":"One C2 kit. 30 customers. 2 governments"}]}
```

