Exfiltration Over C2 Channel

T1041

Technique.View on attack.mitre.org

About this technique

Adversaries may steal data by exfiltrating it over an existing command and control channel. Stolen data is encoded into the normal communications channel using the same protocol as command and control communications.

Detection rules12

Rules on DetectionCode tagged with T1041.

Sigma2

RuleLevelLog source
OpenCanary - TFTP Requesthighopencanary / application
Network Communication Initiated To Portmap.IO Domainmediumwindows / network_connection

Splunk10

RuleTypeRiskData source
Cisco ASA - Device File Copy to Remote LocationAnomalyNULLCisco ASA Logs
Cisco Secure Firewall - High EVE Threat ConfidenceAnomalyNULLCisco Secure Firewall Threat Defense Connection Event
Cisco Secure Firewall - Intrusion Events by Threat ActivityAnomalyNULLCisco Secure Firewall Threat Defense Intrusion Event
Cisco Secure Firewall - Lumma Stealer Download AttemptAnomalyNULLCisco Secure Firewall Threat Defense Intrusion Event
Cisco Secure Firewall - Lumma Stealer Outbound Connection AttemptAnomalyNULLCisco Secure Firewall Threat Defense Intrusion Event
Cisco Secure Firewall - Potential Data ExfiltrationAnomalyNULLCisco Secure Firewall Threat Defense Connection Event
Detect SNICat SNI ExfiltrationTTPNULL
Potential Telegram API Request Via CommandLineAnomalyNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Windows Exfiltration Over C2 Via Invoke RestMethodTTPNULLPowershell Script Block Logging 4104
Windows Exfiltration Over C2 Via Powershell UploadStringTTPNULLPowershell Script Block Logging 4104

Groups27

Show 3 more

Software166

Show 142 more

Campaigns10

Procedure examples203

Groups27

Used byProcedure example
GroupAgrius

Agrius exfiltrated staged data using tools such as Putty and WinSCP, communicating with command and control servers.

GroupAPT3

APT3 has a tool that exfiltrates data over the C2 channel.

GroupAPT32

APT32's backdoor has exfiltrated data using the already opened channel with its C&C server.

GroupAPT39

APT39 has exfiltrated stolen victim data through C2 communications.

GroupBlackByte

BlackByte transmitted collected victim host information via HTTP POST to command and control infrastructure.

GroupChimera

Chimera has used Cobalt Strike C2 beacons for data exfiltration.

GroupConfucius

Confucius has exfiltrated stolen files to its C2 server.

GroupContagious Interview

Contagious Interview has exfiltrated data from a compromised host to actor-controlled C2 servers.

View all 27 groups examples

Software166

Used byProcedure example
MalwareADVSTORESHELL

ADVSTORESHELL exfiltrates data over the same channel used for C2.

MalwareAmadey

Amadey has sent victim data to its C2 servers.

MalwareAppleJeus

AppleJeus has exfiltrated collected host information to a C2 server.

MalwareAppleSeed

AppleSeed can exfiltrate files via the C2 channel.

MalwareAshTag

AshTag has exfiltrated reconnaissance data on targeted systems to C2 servers.

MalwareAstaroth

Astaroth exfiltrates collected information from its r1.log file to the external C2 server.

MalwareAttor

Attor has exfiltrated data over the C2 channel.

MalwareAuTo Stealer

AuTo Stealer can exfiltrate data over actor-controlled C2 servers via HTTP or TCP.

View all 166 software examples

Campaigns10

Used byProcedure example
CampaignArcaneDoor

ArcaneDoor included use of existing command and control channels for data exfiltration.

CampaignC0017

During C0017, APT41 used its Cloudflare services C2 channels for data exfiltration.

CampaignFrankenstein

During Frankenstein, the threat actors collected information via Empire, which sent the data back to the adversary's C2.

CampaignHomeLand Justice

During HomeLand Justice, threat actors used HTTP to transfer data from compromised Exchange servers.

CampaignLeviathan Australian Intrusions

Leviathan exfiltrated collected data over existing command and control channels during Leviathan Australian Intrusions.

CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group exfiltrated data from a compromised host to actor-controlled C2 servers.

CampaignOperation Honeybee

During Operation Honeybee, the threat actors uploaded stolen files to their C2 servers.

CampaignOperation Wocao

During Operation Wocao, threat actors used the XServer backdoor to exfiltrate data.

View all 10 campaigns examples

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.