Alpha Cyber

SecondDate_CnC Equation Group God of Espionage Lurks in Your Network

A highly sophisticated backdoor, SecondDate_CnC, attributed to the elite Equation Group, has resurfaced in targeted infrastructure attacks.

Alpha Cyber Research1 min readupdated 1 Apr 2026
Second Date Backdoor

SecondDate_CnC – The God of Espionage Lurks in Your Network


A highly sophisticated backdoor, SecondDate_CnC, attributed to the elite Equation Group, has resurfaced in targeted infrastructure attacks. This tool, once deployed by one of the most advanced nation-state actors ever discovered, enables remote access, traffic redirection, and deep system manipulation, without leaving a trace.

What We Found


Through deep infrastructure analysis, we uncovered how attackers:

Inject traffic into edge network devices (e.g., routers, firewalls)

Use silent packet redirection to bypass detection

Establish covert channels with Command & Control (C2) infrastructure

Remain embedded for extended periods, surviving reboots and firmware updates

This threat isn’t malware, it’s a network parasite, hiding in plain sight.

Our Defense Strategy


At Alpha Cyber, we:

  • Map data flows to trace hidden redirection and covert channels
  • Detect embedded implants in network hardware
  • Hunt for legacy Equation Group techniques still active in modern networks
  • Isolate C2 pathways and block them at the edge

 Table of IOCs to Block

TypeIOC / ValueDescription
IP Address192.203.230.10Known C2 relay node
Domainupdate.secure-network[.]orgDNS used for traffic redirection
File Namesecnd_ktmod.soSuspected payload module
Port443Encrypted C2 communication
ProtocolICMP TunnelingUsed for stealth data exfiltration

These indicators are linked to historic and ongoing SecondDate_CnC campaigns. Immediate monitoring and blocking are recommended.

Visibility Is Power


SecondDate thrives in invisibility.
We help you reclaim control by uncovering what your firewalls can’t see.

Schedule a Network Threat Audit Today

Keep reading

Related research

Daxin Rootkit
Threat ReportsTLP:AMBER

Daxin Returns: A 13-Year-Old China-Linked Rootkit That Never Called Home

Symantec found the Daxin kernel rootkit still operational on a Taiwan manufacturing subsidiary in 2026, alongside a previously undocumented backdoor, Stupig, that runs SYSTEM commands from the Windows logon screen before anyone signs in.

6 min readAPT

Contact

Talk to someone who has seen this before.

You speak directly to the people doing the work, wherever in the world you operate.

Or email [email protected]