RedHydra Adaptix & Cobalt Strike Cluster

Targeted reconnaissance, access brokerage, and exploitation of public health and municipal infrastructure.

Key Operational Findings

  • Infrastructure Staging: Host 101[.]42[.]255[.]92 operates as a centralized Command & Control hub and offensive staging node hosted on Tencent Cloud.
  • Dual C2 Backbone: Runs Cobalt Strike 4.9.1 on port 8081 alongside the modern AdaptixC2 and customized RRR_C2_v1.2 frameworks.
  • Specialized Protocol Attack: The cluster leverages Rogue MySQL Server (port 3306) to abuse MySQL’s LOCAL INFILE protocol feature, forcing connected Java/Spring clients to exfiltrate arbitrary files (application-dev.yml, internal .jar packages).
  • Targeting Vertical: Direct reconnaissance against municipal and public health administration infrastructure (卫生健康委员会).

Technical Telemetry & Indicators

Indicator TypeDefanged ValueOperational Role
IPv4 Address101[.]42[.]255[.]92Staging, Cobalt Strike & Adaptix C2 Node
Port / Service101[.]42[.]255[.]92:8081Cobalt Strike TeamServer Listener
Port / Service101[.]42[.]255[.]92:3306Rogue MySQL Arbitrary File Exfiltration Listener
Port / Service101[.]42[.]255[.]92:8555JNDI / HTTP Payload Delivery
Port / Service101[.]42[.]255[.]92:8857Interactive Reverse Shell Listener
Tool ArtifactgenCrossC2.LinuxCross-platform Linux ELF Cobalt Strike Beacon Compiler
Tool Artifactrogue_mysql_serverJDBC Protocol Arbitrary Client File Extraction Tool

Companion Investigation Reports