Threat feed
ViriBack C2 Tracker
Last fetched
C2 Servers · refreshed daily · last verified
ViriBack C2 Tracker is a C2 Servers threat-intelligence feed, refreshed daily, indexed by WhisperGraph.
What is ViriBack C2 Tracker
ViriBack C2 Tracker is a malware-family-tagged command-and-control tracking feed maintained by the ViriBack research project, cataloguing active C2 panels across a range of information-stealer and remote-access-trojan families. Its family-tagging approach is similar to abuse.ch's ThreatFox, giving downstream consumers the ability to filter or prioritise by malware family rather than treating every C2 indicator identically. The project publishes both a live dashboard and a machine-readable feed for direct integration. It is indexed here as a family-tagged C2 reference alongside the larger abuse.ch ThreatFox family in this catalogue.
- Source
- https://viriback.com/
- Refresh cadence
- daily
Category drift. The curated category for this feed is C2 Servers, while WhisperGraph currently files it under c2.
Indicators currently listed
Indicators currently listed is temporarily unavailable.
The graph did not answer within the page budget. Refresh in a moment to retry — fresh data is fetched on the next visit.
Related pages
Pivot from ViriBack C2 Tracker into the indicators it lists.
Queries
Resolves the feed's categories.
MATCH (f:FEED_SOURCE {name: $slug})
OPTIONAL MATCH (f)-[:BELONGS_TO]->(c:CATEGORY)
WITH f, collect(c.name) AS categories
RETURN f.name AS slug, f.id AS id, categoriesRun yourself →The indicator-kind rollup and sample listed above.
MATCH (f:FEED_SOURCE {name: $slug})<-[:LISTED_IN]-(x)
WITH labels(x)[0] AS kind, count(*) AS listed, collect(x.name)[0..5] AS sample
RETURN kind, listed, sample
ORDER BY listed DESCRun yourself →Or query Whisper from your own LLM workflow via the Whisper MCP server.