Publish/Subscribe Protocols

T1071.005

Sub-technique of T1071 Application Layer Protocol.View on attack.mitre.org

About this technique

Adversaries may communicate using publish/subscribe (pub/sub) application layer protocols to avoid detection/network filtering by blending in with existing traffic. Commands to the remote system, and often the results of those commands, will be embedded within the protocol traffic between the client and server.

Protocols such as MQTT, XMPP, AMQP, and STOMP use a publish/subscribe design, with message distribution managed by a centralized broker. Publishers categorize their messages by topics, while subscribers receive messages according to their subscribed topics. An adversary may abuse publish/subscribe protocols to communicate with systems under their control from behind a message broker while also mimicking normal, expected traffic.

Detection rules0

Rules on DetectionCode tagged with T1071.005.

Sigma0

No Sigma rules are mapped to this technique yet.

Splunk0

No Splunk rules are mapped to this technique yet.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples1

Software1

Used byProcedure example
MalwareGLOOXMAIL

GLOOXMAIL communicates to servers operated by Google using the Jabber/XMPP protocol for C2.

References2

  1. Mandiant APT1 Appendix Open source
    Mandiant. (n.d.). Appendix C (Digital) - The Malware Arsenal. Retrieved July 18, 2016.
  2. wailing crab sub/pub Open source
    Hammond, Charlotte. Villadsen, Ole. Metrick, Kat.. (2023, November 21). Stealthy WailingCrab Malware misuses MQTT Messaging Protocol. Retrieved August 28, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.