Skip to Content

Inside a Threat Actors AI-Generated C2 Panel: What It Looks Like and How It Was Used

10:00 AM BST  |  1:00 PM EDT

During an investigation, the ReliaQuest Threat Hunting team identified an AI-generated C2 panel being used by a threat actor in a campaign targeting Windows hosts and browser-stored cryptocurrency exchange credentials. The panel allowed the threat actor to manage compromised systems, deploy scripts, remove rival remote-access tools, and monitor activity across the campaign. The underlying framework was also built to maintain access and recover when individual components were disrupted.    

Join ReliaQuest Director of GreyMatter Operations Brandon Tirado and Technical Product Marketing Manager Dylan Deane as they review what the team uncovered and walk through a recreated version of the attacker’s C2 panel. The session will examine how the threat actor used the tool, how the framework changed during the campaign, and the persistence mechanisms defenders need to account for during containment and remediation.  

Attendees will learn:  

  • What the AI-generated C2 panel looked like and how the threat actor used it to manage compromised hosts, deploy scripts, and monitor the campaign.  

  • How the underlying framework maintained access, restored disrupted tools, and changed over the course of the campaign.  

  • How AI can shorten the development and modification time for attacker tooling.  

  • Key detection, containment, and remediation lessons from the investigation.