ToxC2 Sells a Cross Platform Agent That Runs Its Command Channel Over Tox
A seller posting as Reze is advertising ToxC2, a command and control agent priced at 70 dollars for builds covering Windows, macOS and Linux. The distinguishing feature is the channel: rather than calling home to a server, the implant sends a contact request to the operator over the Tox messaging protocol and is then driven by text commands in an ordinary chat client. The listing describes an interactive shell on each platform, file retrieval, screen, webcam and microphone streaming, autorun persistence on all three operating systems, anti analysis checks and tampering with Windows logging and script scanning interfaces, and self deletion on machines that appear to be in the seller's own region. Capabilities are as advertised and unverified.
▣Listing details
!What the listing claims
- Control through a chat client
- Operator added by contact request
- Persistent interactive shell
- PowerShell on Windows
- Shell on a PTY for Linux and macOS
- File download from the host
- File delivery to the host
- Desktop streaming
- Webcam streaming
- Microphone capture
- System and drive enumeration
- Process and network listing
- Geolocation lookup
- Power and session control
- Logging and script scanning tampering
- Debugger, VM and sandbox checks
- Autorun on all three systems
- Self deletion on command
◱Screenshots
☷Mapped techniques
Mapped from the seller's own description. Advertised, not confirmed.
- Command and control T1071 Application layer protocol Stated Control runs entirely over a peer to peer messaging protocol, with the operator reached as a chat contact rather than through a server the implant connects back to.
- Execution T1059 Command and scripting interpreter Stated A shell is held open for the session, using PowerShell on Windows and a terminal on Linux and macOS.
- Persistence T1547 Boot or logon autostart execution Stated Autorun is established on first execution using the startup folder on Windows, a user service and scheduled task on Linux, and a launch agent on macOS.
- Defense evasion T1562.001 Disable or modify tools Stated The Windows build claims to patch the event tracing and script scanning interfaces that endpoint products rely on for visibility.
- Defense evasion T1497 Virtualisation and sandbox evasion Stated Optional checks for debuggers, virtual machines and analysis sandboxes are offered as a build option.
- Discovery T1614.001 System language discovery Stated Keyboard layout and locale are read to identify machines in the seller's own region, where the implant removes itself.
- Collection T1113 Screen capture Stated Desktop streaming is offered alongside webcam capture and microphone listening, each through the native capture framework of the platform.
⚠Potential impact
The capability list is unremarkable for a remote access tool. The transport is the part worth attention. Because control runs over a peer to peer messaging network, there is no domain to sinkhole, no address to block and no certificate to inspect, and traffic looks like an ordinary chat client rather than beaconing to infrastructure. Defences that lean on network indicators lose most of their grip, which pushes detection back onto host behaviour: an unexpected process holding a shell open, autorun entries in the startup folder, a user level service and scheduled task, or a launch agent that nobody installed. The region check is also informative, since an implant that deletes itself on machines matching the seller's own locale tells you where the operator is and where victims will not be. At 70 dollars for three platforms, the barrier is low enough that this lands with unskilled buyers rather than organised operations, which usually means noisy, opportunistic use against individuals rather than targeted intrusion. One claim in the listing contradicts another: it advertises that nothing is written to disk, while also describing autorun entries and a binary that can later delete itself. Both cannot be true, and the persistence description is the more credible of the two.
iStatus Unverified
Everything here is a sales claim. No sample, hash or build has been published, so none of the evasion or streaming capability can be checked, and there is nothing for defenders to use as a detection artefact beyond the behaviours described. The seller account is new and carries almost no standing, registered within the last six months with a handful of posts and a token deposit, which on this kind of forum is the profile of an untested vendor rather than an established one. The stated test matrix is worth noting: the macOS coverage is described against a release now several major versions old, which predates much of the current consent framework governing camera, microphone and screen recording access. If accurate, that suggests the macOS build is considerably less capable in practice than the listing implies. Dark Web Informer has not obtained the builds and is not linking the seller's contact channel or the hosted screenshots.
Dark Web Informer // Threat Intelligence