Mark RadarMARK RADAR
About
EN
Sign in

RedC2 4.0 Uses LLM Command Layer to Target Linux Developers

1 reports · First detected 2026-08-25 · Last active 2026-08-25

Software supply-chain attacks increasingly exploit package ecosystems trusted by developers. Trend Micro said RedC2 4.0 targets Linux development environments with capabilities including credential theft, persistent access and lateral movement. The malicious framework also incorporates an LLM-based command layer, potentially making it easier for operators to control compromised systems and coordinate post-exploitation tasks through natural-language instructions.

Trend Micro identified 14 malicious NPM packages that abused dependency workflows to load ELF executables and install the RedShell backdoor on victims’ machines. RedC2 4.0 includes a component called Red Agent, which converts natural-language requests into attack commands. The feature can direct tasks such as credential theft, system reconnaissance and lateral movement, broadening the supply-chain threat facing Linux developers and organizations that rely on open-source packages.

All Coverage

1 original reports

The Backstory

The history behind this event

No historical echoes for this signal

Mark Radar|MARK RADAR

If you search news on Google, you can set Mark Radar as a preferred source—our coverage will show up more often in your results. Set as preferred source on Google →

All times are in Taipei time (GMT+8)