Technique with 5 sub-techniques.View on attack.mitre.org
Adversaries may communicate using OSI application layer protocols to avoid detection/network filtering by blending in with existing traffic. Commands to the remote system, and often the results of those commands, will be embedded within the protocol traffic between the client and server.
Adversaries may utilize many different protocols, including those used for web browsing, transferring files, electronic mail, DNS, or publishing/subscribing. For connections that occur internally within an enclave (such as those between a proxy or pivot node and other nodes), commonly used protocols are SMB, SSH, or RDP.
Rules on DetectionCode tagged with T1071 or one of its sub-techniques.
| Used by | Procedure example |
|---|---|
| GroupINC Ransom | INC Ransom has used valid accounts over RDP to connect to targeted systems. |
| GroupMagic Hound | Magic Hound malware has used IRC for C2. |
| GroupRocke | Rocke issued wget requests from infected systems to the C2. |
| GroupTeamTNT | TeamTNT has used an IRC bot for C2 communications. |
| GroupVelvet Ant | Velvet Ant has used reverse SSH tunnels to communicate to victim devices. |
| Used by | Procedure example |
|---|---|
| MalwareClambling | Clambling has the ability to use Telnet for communication. |
| MalwareDuqu | Duqu uses a custom command and control protocol that communicates over commonly used ports, and is frequently encapsulated by application layer protocols. |
| MalwareHildegard | Hildegard has used an IRC channel for C2 communications. |
| MalwareLucifer | Lucifer can use the Stratum protocol on port 10001 for communication between the cryptojacking bot and the mining server. |
| MalwareNETEAGLE | Adversaries can also use NETEAGLE to establish an RDP connection with a controller over TCP/7519. |
| MalwareNightdoor | Nightdoor uses TCP and UDP communication for command and control traffic. |
| MalwareQUIETEXIT | QUIETEXIT can use an inverse negotiated SSH connection as part of its C2. |
| MalwareRaspberry Robin | Raspberry Robin is capable of contacting the TOR network for delivering second-stage payloads. |
| Used by | Procedure example |
|---|---|
| CampaignFrostyGoop Incident | During FrostyGoop Incident, the adversary initiated Layer Two Tunnelling Protocol (L2TP) connections to Moscow-based IP addresses. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.