One Day Sec

What are the main differences in C2 communication between PoisonFrog and Glimpse?

PoisonFrog's agent uses HTTP to download commands and DNS A records for control, while Glimpse expands C2 channels by using both DNS A records and DNS TXT records for data exfiltration and command delivery. Additionally, Glimpse provides a C#-based graphical control panel, whereas PoisonFrog relies on a Node.js server, as outlined in the Analysis of APT34 Leaked Tools - PoisonFrog and Glimpse article.
C2 communicationDNS tunnelingDNS TXT recordsPoisonFrogGlimpse

Browse all Q&A →