Technique.View on attack.mitre.org
Adversaries may use an OSI non-application layer protocol for communication between host and C2 server or among infected hosts within a network. The list of possible protocols is extensive. Specific examples include use of network layer protocols, such as the Internet Control Message Protocol (ICMP), transport layer protocols, such as the User Datagram Protocol (UDP), session layer protocols, such as Socket Secure (SOCKS), as well as redirected/tunneled protocols, such as Serial over LAN (SOL).
ICMP communication between hosts is one example. Because ICMP is part of the Internet Protocol Suite, it is required to be implemented by all IP-compatible hosts. However, it is not as commonly monitored as other Internet Protocols such as TCP or UDP and may be used by adversaries to hide communications.
In ESXi environments, adversaries may leverage the Virtual Machine Communication Interface (VMCI) for communication between guest virtual machines and the ESXi host. This traffic is similar to client-server communications on traditional network sockets but is localized to the physical machine running the ESXi host, meaning it does not traverse external networks (routers, switches). This results in communications that are invisible to external monitoring and standard networking tools like tcpdump, netstat, nmap, and Wireshark. By adding a VMCI backdoor to a compromised ESXi host, adversaries may persistently regain access from any guest VM to the compromised ESXi host’s backdoor, regardless of network segmentation or firewall rules in place.
Rules on DetectionCode tagged with T1095.
| Rule | Level | Log source |
|---|---|---|
| PUA - Netcat Suspicious Execution | high | windows / process_creation |
| Netcat The Powershell Version | medium | windows / ps_classic_start |
| Suspicious DNS Z Flag Bit Set | medium | zeek / NULL |
| Rule | Type | Risk | Data source |
|---|---|---|---|
| Detect Large ICMP Traffic | TTP | NULL | Palo Alto Network Traffic, Cisco Secure Access Firewall |
| Detect Large Outbound ICMP Packets | TTP | NULL | Palo Alto Network Traffic |
| Linux Proxy Socks Curl | TTP | NULL | Sysmon for Linux EventID 1 |
| Used by | Procedure example |
|---|---|
| GroupAPT3 | An APT3 downloader establishes SOCKS5 connections for its initial C2. |
| GroupBackdoorDiplomacy | BackdoorDiplomacy has used EarthWorm for network tunneling with a SOCKS5 server and port transfer functionalities. |
| GroupBITTER | BITTER has used TCP for C2 communications. |
| GroupEmber Bear | Ember Bear uses socket-based tunneling utilities for command and control purposes such as NetCat and Go Simple Tunnel (GOST). These tunnels are used to push interactive command prompts over the created sockets. Ember Bear has also used reverse TCP connections from Meterpreter installations to communicate back with C2 infrastructure. |
| GroupFIN6 | FIN6 has used Metasploit Bind and Reverse TCP stagers. |
| GroupGamaredon Group | Gamaredon Group has used SOCKS5 over port 9050 for C2 communication. |
| GroupHAFNIUM | HAFNIUM has used TCP for C2. |
| GroupMetador | Metador has used TCP for C2. |
| Used by | Procedure example |
|---|---|
| MalwareAnchor | Anchor has used ICMP in C2 communications. |
| MalwareAria-body | Aria-body has used TCP in C2 communications. |
| MalwareAuTo Stealer | AuTo Stealer can use TCP to communicate with command and control servers. |
| MalwareBandook | Bandook has a command built in to use a raw TCP socket. |
| MalwareBisonal | Bisonal has used raw sockets for network communication. |
| ToolBrute Ratel C4 | Brute Ratel C4 has the ability to use TCP for external C2. |
| MalwareBUBBLEWRAP | BUBBLEWRAP can communicate using SOCKS. |
| MalwareCarbon | Carbon uses TCP and UDP for C2. |
| Used by | Procedure example |
|---|---|
| Campaign2022 Ukraine Electric Power Attack | During the 2022 Ukraine Electric Power Attack, Sandworm Team proxied C2 communications within a TLS-based tunnel. |
| CampaignC0021 | During C0021, the threat actors used TCP for some C2 communications. |
| CampaignCutting Edge | During Cutting Edge, threat actors used the Unix socket and a reverse TCP shell for C2 communications. |
| CampaignKV Botnet Activity | KV Botnet Activity command and control traffic uses a non-standard, likely custom protocol for communication. |
| CampaignOperation Wocao | During Operation Wocao, threat actors used a custom protocol for command and control. |
| CampaignRedDelta Modified PlugX Infection Chain Operations | Mustang Panda communicated over TCP 5000 from adversary administrative servers to adversary command and control nodes during RedDelta Modified PlugX Infection Chain Operations. |
| CampaignRedPenguin | During RedPenguin, UNC3886 leveraged malware that used UDP and TCP sockets for C2. |
| CampaignVersa Director Zero Day Exploitation | Versa Director Zero Day Exploitation used a non-standard TCP session to initialize communication prior to establishing HTTPS command and control. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.