securityonline.info 9/1/2026, 2:30:57 PM · external

Miraak Post Exploitation Framework Adopts Database C2

Miraak Post Exploitation Framework Adopts Database C2

THE article discusses the discovery of the Miraak post-exploitation framework by Blackpoint's Adversary Pursuit Group. This malware, identified after an operational security failure, leverages Trojanized .NET dependencies for delivery and establishes a command-and-control (C2) channel via cloud-hosted PostgreSQL databases, evading traditional detection methods. Miraak can execute commands and transfer files while maintaining a low profile by disguising malicious activities within normal database traffic.

The framework's modular nature allows for extensive operator actions, including file management and process enumeration. Defense strategies include monitoring for unusual database connections and suspicious behavior involving .NET runtimes.

View full article

Article by CyberSIXT