Imikom Ghost: Cloud Dead-Drop & Mythic C2 Operation

Targeted infiltration of hardened corporate perimeters using cloud dead-drop channels and driver-level EDR blinding.

Key Operational Findings

  • Cloud Dead-Drop Egress Bypasses: Imikom replaces direct outbound connections with trusted CDN endpoints:
    • GitHub Contents API (github_c2.c): Relays commands via repository derwingoww/edge-nodes (nodes/{id}/out and nodes/{id}/in) using authenticated PAT tokens to defeat Next-Gen Firewall (FortiGate/Palo Alto) inspection.
    • Google Sheets API (deploy_google_sheets.c): Bi-directional command exchange via sheets[.]googleapis[.]com over OAuth2.
  • Kernel EDR Blinding (BYOVD): Staging signed drivers HWiNFO_x64_206.sys and TRIXX.sys to execute ring-0 kernel writes that disable PspCreateProcessNotifyRoutine callbacks.
  • Evasion & Masquerading: Obfuscated binaries disguise as OfficeSupport.exe and WindowsTelemetry.exe, using in-memory process hollowing and XOR stack string decryption.

Technical Telemetry & Indicators

Indicator TypeDefanged ValueOperational Role
IPv4 Address2[.]27[.]63[.]244Staging & Compilation Node (Fastweb, Italy)
Port / Service2[.]27[.]63[.]244:9999Exposed Tooling & Staging Repository
Domaincdn-staticfiles[.]comDefault Fallback HTTPS C2 Domain
GitHub Relayderwingoww/edge-nodesCovert Dead-Drop Relay Repository
Driver (BYOVD)HWiNFO_x64_206.sysVulnerable Signed Driver for Kernel Callback Unhooking
Driver (BYOVD)TRIXX.sysVulnerable Signed Driver for Kernel EDR Blinding
PersistenceOfficeSupportScheduled Task (%APPDATA%\Microsoft\Office\OfficeSupport.exe)

Companion Investigation Reports