Protocol or Service Impersonation

T1001.003

Sub-technique of T1001 Data Obfuscation.View on attack.mitre.org

About this technique

Adversaries may impersonate legitimate protocols or web service traffic to disguise command and control activity and thwart analysis efforts. By impersonating legitimate protocols or web services, adversaries can make their command and control traffic blend in with legitimate network traffic.

Adversaries may impersonate a fake SSL/TLS handshake to make it look like subsequent traffic is SSL/TLS encrypted, potentially interfering with some security tooling, or to make the traffic look like it is related with a trusted entity.

Adversaries may also leverage legitimate protocols to impersonate expected web traffic or trusted services. For example, adversaries may manipulate HTTP headers, URI endpoints, SSL certificates, and transmitted data to disguise C2 communications or mimic legitimate services such as Gmail, Google Drive, and Yahoo Messenger.

Detection rules2

Rules on DetectionCode tagged with T1001.003.

Sigma2

RuleLevelLog source
Suspicious LDAP-Attributes Usedhighwindows / NULL
ADSI-Cache File Creation By Uncommon Toolmediumwindows / file_event

Splunk0

No Splunk rules are mapped to this technique yet.

Groups3

Software18

Campaigns1

Procedure examples22

Groups3

Used byProcedure example
GroupHigaisa

Higaisa used a FakeTLS session for C2 communications.

GroupLazarus Group

Lazarus Group malware also uses a unique form of communication encryption known as FakeTLS that mimics TLS but uses a different encryption method, potentially evading SSL traffic inspection/decryption.

GroupMustang Panda

Mustang Panda has utilized TLS record headers in network packets to impersonate various versions of TLS protocols to blend in with legitimate network traffic. Mustang Panda has used FakeTLS to communicate with its C2 servers.

Software18

Used byProcedure example
MalwareBADCALL

BADCALL uses a FakeTLS method during C2.

MalwareBankshot

Bankshot generates a false TLS handshake using a public certificate to disguise C2 network communications.

MalwareBOOKWORM

BOOKWORM has modified HTTP POST requests to resemble legitimate communications.

MalwareCobalt Strike

Cobalt Strike can leverage the HTTP protocol for C2 communication, while hiding the actual data in either an HTTP header, URI parameter, the transaction body, or appending it to the URI. Cobalt Strike has also added Host: ocsp.verisign.com to HTTP headers to mimic Online Certificate Status Protocol (OCSP) traffic.

MalwareFakeM

FakeM C2 traffic attempts to evade detection by resembling data generated by legitimate messenger applications, such as MSN and Yahoo! messengers. Additionally, some variants of FakeM use modified SSL code for communications back to C2 servers, making SSL decryption ineffective.

MalwareFALLCHILL

FALLCHILL uses fake Transport Layer Security (TLS) to communicate with its C2 server.

MalwareFRAMESTING

FRAMESTING uses a cookie named `DSID` to mimic the name of a cookie used by Ivanti Connect Secure appliances for maintaining VPN sessions.

MalwareHARDRAIN

HARDRAIN uses FakeTLS to communicate with its C2 server.

View all 18 software examples

Campaigns1

Used byProcedure example
CampaignC0017

During C0017, APT41 frequently configured the URL endpoints of their stealthy passive backdoor LOWKEY.PASSIVE to masquerade as normal web application traffic on an infected server.

References2

  1. ESET Okrum July 2019 Open source
    Hromcova, Z. (2019, July). OKRUM AND KETRICAN: AN OVERVIEW OF RECENT KE3CHANG GROUP ACTIVITY. Retrieved May 6, 2020.
  2. Malleable-C2-U42 Open source
    Chris Navarrete Durgesh Sangvikar Andrew Guan Yu Fu Yanhui Jia Siddhart Shibiraj. (2022, March 16). Cobalt Strike Analysis and Tutorial: How Malleable C2 Profiles Make Cobalt Strike Difficult to Detect. Retrieved September 24, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.