LLM plus Ghidra extracts 20 protocol elements from Mirai binaries at 100% accuracy and generates pseudo-C2 servers that reproduce 7 of 10 DDoS attack vectors.
C2Miner: Tricking IoT Malware into Revealing Live Command & Control Servers
1 Pith paper cite this work. Polarity classification is still indexing.
1
Pith paper citing it
fields
cs.CR 1years
2026 1verdicts
UNVERDICTED 1representative citing papers
citing papers explorer
-
LLM-assisted Generation of Pseudo-C2 Servers for IoT Malware Dynamic Analysis
LLM plus Ghidra extracts 20 protocol elements from Mirai binaries at 100% accuracy and generates pseudo-C2 servers that reproduce 7 of 10 DDoS attack vectors.