Tool
mega-cmd-server
- First Reported
- Oct 5, 2026
- Latest Reported
- Oct 5, 2026
Reported Context (1)
- Data moved from victim networks to the C2 box, staged on forgitlab, then transferred to MEGA via mega-cmd-server. Three hops between victim and final destination: taking down any single node does not recover the CloudSEK Finds Gentlemen Ransomware Affiliate’s Exposed Servers and Stolen Data
Threat Actors (2)
MITRE ATT&CK (11)
Products (12)
Tools (23)
Industries (6)
Note: Related entities, including threat actors, malware, CVEs, MITRE ATT&CK techniques, vendors, products, tools, countries, and industries, are shown when they appear in the same reporting. Their presence does not necessarily mean they were targeted, compromised, vulnerable, responsible for the activity, or directly involved in the incident.