DetectionDetectors written for your environment Environment IntelligenceA living model of your environment Threat HuntingThreat report to finished hunt in minutes InvestigateEvery alert investigated on arrival ResponseContainment staged, checked and auditable AI ModeThe whole platform in natural language Incident ReadinessSee coverage gaps and close them QueryFast search across all your telemetry MDRArtemis analysts operating on your behalf Connectors150+ sources, ingested or queried in place Why Artemis Resources Attack StoriesReal attacks, reconstructed step by step BlogResearch and product updates Company About ArtemisThe team and the story behind Artemis CareersOpen roles at Artemis Book a Demo A Protocol From 1977 Is Still Delivering Malware in 2026 Hadar Waldman July 15, 2026 The finger protocol is older than the web, disabled on every server that matters, and still a working malware delivery channel on a default Windows install. Here it planted a Python RAT that was alerting the whole time. One genuine compromise, drowned in thousands of benign look-alikes, invisible until something cut through the noise.

A compiled-Python remote-access trojan was re-launching on an employee’s laptop on every login, and the company’s endpoint agent was alerting on it the entire time. Every alert was configured alert-only, so it flagged and never contained. None were acted on.

The delivery mechanism was the giveaway: an obfuscated finger command, caret-escaped to read f^i^n^g^e^r, abusing the ancient Finger protocol to pull attacker commands off a remote host and run them inline.

From there the chain is modern and mundane: a signed Python interpreter dropped as a living-off-the-land binary, a .pyc payload staged in C:\ProgramData\, a registry Run key for persistence, and a second-stage module dropped by PowerShell an hour later. None of it was novel. All of it matches an active 2025–2026 campaign cluster.

What was missing was anyone connecting the alerts into a story. Which is where this one gets interesting: the customer had connected their endpoint telemetry to Artemis two days before it surfaced. 

This article was aggregated automatically by CyberWire Daily's newsfeed engine. Original reporting: artemissecurity.com.