Exfiltration Over Unencrypted Non-C2 Protocol

T1048.003

Sub-technique of T1048 Exfiltration Over Alternative Protocol.View on attack.mitre.org

About this technique

Adversaries may steal data by exfiltrating it over an un-encrypted network protocol other than that of the existing command and control channel. The data may also be sent to an alternate network location from the main command and control server.

Adversaries may opt to obfuscate this data, without the use of encryption, within network protocols that are natively unencrypted (such as HTTP, FTP, or DNS). This may include custom or publicly available encoding/compression algorithms (such as base64) as well as embedding data within protocol headers and fields.

Detection rules22

Rules on DetectionCode tagged with T1048.003.

Sigma8

RuleLevelLog source
Suspicious WebDav Client Execution Via Rundll32.EXEhighwindows / process_creation
Data Exfiltration with Wgetmediumlinux / NULL
PowerShell ICMP Exfiltrationmediumwindows / ps_script
Python WebServer Execution - Linuxmediumlinux / process_creation
Suspicious DNS Query with B64 Encoded StringmediumNULL / dns
Suspicious Outbound SMTP Connectionsmediumwindows / network_connection
WebDav Client Execution Via Rundll32.EXEmediumwindows / process_creation
WebDav Put Requestlowzeek / NULL

Splunk14

RuleTypeRiskData source
Cisco ASA - Device File Copy to Remote LocationAnomalyNULLCisco ASA Logs
Cisco Secure Firewall - Potential Data ExfiltrationAnomalyNULLCisco Secure Firewall Threat Defense Connection Event
Clients Connecting to Multiple DNS ServersTTPNULL
Detect DNS Data Exfiltration using pretrained model in DSDLAnomalyNULL
Detect Long DNS TXT Record ResponseTTPNULL
Detection of DNS TunnelsTTPNULL
DNS Query Length With High Standard DeviationAnomalyNULLSysmon EventID 22
Gsuite Outbound Email With Attachment To External DomainHuntingNULLG Suite Gmail
Linux Shell Pseudo Device Reverse ShellAnomalyNULLSysmon for Linux EventID 1
Multiple Archive Files Http Post TrafficTTPNULLSplunk Stream HTTP
Plain HTTP POST Exfiltrated DataTTPNULLSplunk Stream HTTP
Protocol or Port MismatchAnomalyNULLCisco Secure Firewall Threat Defense Connection Event
Windows Rundll32 WebDAV RequestHuntingNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Windows Rundll32 WebDav With Network ConnectionTTPNULLSysmon EventID 1 AND Sysmon EventID 3

Groups11

Software22

Campaigns2

Procedure examples35

Groups11

Used byProcedure example
GroupAPT32

APT32's backdoor can exfiltrate data by encoding it in the subdomain field of DNS packets.

GroupAPT33

APT33 has used FTP to exfiltrate files (separately from the C2 channel).

GroupContagious Interview

Contagious Interview has exfiltrated victim information using FTP.

GroupFIN6

FIN6 has sent stolen payment card data to remote servers via HTTP POSTs.

GroupFIN8

FIN8 has used FTP to exfiltrate collected data.

GroupLazarus Group

Lazarus Group malware SierraBravo-Two generates an email message via SMTP containing information about newly infected victims.

GroupMustang Panda

Mustang Panda has used FTP to exfiltrate archive files.

GroupOilRig

OilRig has exfiltrated data via Microsoft Exchange and over FTP separately from its primary C2 channel over DNS.

View all 11 groups examples

Software22

Used byProcedure example
MalwareAgent Tesla

Agent Tesla has routines for exfiltration over SMTP, FTP, and HTTP.

ToolBITSAdmin

BITSAdmin can be used to create BITS Jobs to upload files from a compromised host.

MalwareBrave Prince

Some Brave Prince variants have used South Korea's Daum email service to exfiltrate information, and later variants have posted the data to a web server via an HTTP post command.

MalwareCarbon

Carbon uses HTTP to send data to the C2 server.

Malwareccf32

ccf32 can upload collected data and files to an FTP server.

MalwareCharmPower

CharmPower can send victim data via FTP with credentials hardcoded in the script.

MalwareCherry Picker

Cherry Picker exfiltrates files over FTP.

MalwareCookieMiner

CookieMiner has used the curl --upload-file command to exfiltrate data over HTTP.

View all 22 software examples

Campaigns2

Used byProcedure example
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, the adversaries exfiltrated data to an actor-controlled infrastructure using HTTP POSTs.

CampaignC0017

During C0017, APT41 exfiltrated victim data via DNS lookups by encoding and prepending it as subdomains to the attacker-controlled domain.

References1

  1. copy_cmd_cisco Open source
    Cisco. (2022, August 16). copy - Cisco IOS Configuration Fundamentals Command Reference . Retrieved July 13, 2022.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.