GOst in the Protocol
Hunting Ligolo with JARM Fingerprinting in the Wild
Identified three distinct JARM signatures that reliably identify Ligolo proxy servers in the wild. Developed a 4-stage verification methodology using a modified Ligolo agent that tests yamux protocol implementation. Discovered key TLS error differences between Ligolo-MP and Sliver C2.
- 3 JARM signatures for Ligolo 0.7.x, 0.8.x, and Ligolo-MP
- 4-stage yamux protocol verification methodology
- Ligolo-MP vs Sliver C2 distinction via TLS error analysis