Non-Application Layer Protocol

T1095

Technique.View on attack.mitre.org

About this technique

Adversaries may use an OSI non-application layer protocol for communication between host and C2 server or among infected hosts within a network. The list of possible protocols is extensive. Specific examples include use of network layer protocols, such as the Internet Control Message Protocol (ICMP), transport layer protocols, such as the User Datagram Protocol (UDP), session layer protocols, such as Socket Secure (SOCKS), as well as redirected/tunneled protocols, such as Serial over LAN (SOL).

ICMP communication between hosts is one example. Because ICMP is part of the Internet Protocol Suite, it is required to be implemented by all IP-compatible hosts. However, it is not as commonly monitored as other Internet Protocols such as TCP or UDP and may be used by adversaries to hide communications.

In ESXi environments, adversaries may leverage the Virtual Machine Communication Interface (VMCI) for communication between guest virtual machines and the ESXi host. This traffic is similar to client-server communications on traditional network sockets but is localized to the physical machine running the ESXi host, meaning it does not traverse external networks (routers, switches). This results in communications that are invisible to external monitoring and standard networking tools like tcpdump, netstat, nmap, and Wireshark. By adding a VMCI backdoor to a compromised ESXi host, adversaries may persistently regain access from any guest VM to the compromised ESXi host’s backdoor, regardless of network segmentation or firewall rules in place.

Detection rules6

Rules on DetectionCode tagged with T1095.

Sigma3

RuleLevelLog source
PUA - Netcat Suspicious Executionhighwindows / process_creation
Netcat The Powershell Versionmediumwindows / ps_classic_start
Suspicious DNS Z Flag Bit Setmediumzeek / NULL

Splunk3

RuleTypeRiskData source
Detect Large ICMP TrafficTTPNULLPalo Alto Network Traffic, Cisco Secure Access Firewall
Detect Large Outbound ICMP PacketsTTPNULLPalo Alto Network Traffic
Linux Proxy Socks CurlTTPNULLSysmon for Linux EventID 1

Groups12

Software88

Show 64 more

Campaigns8

Procedure examples108

Groups12

Used byProcedure example
GroupAPT3

An APT3 downloader establishes SOCKS5 connections for its initial C2.

GroupBackdoorDiplomacy

BackdoorDiplomacy has used EarthWorm for network tunneling with a SOCKS5 server and port transfer functionalities.

GroupBITTER

BITTER has used TCP for C2 communications.

GroupEmber Bear

Ember Bear uses socket-based tunneling utilities for command and control purposes such as NetCat and Go Simple Tunnel (GOST). These tunnels are used to push interactive command prompts over the created sockets. Ember Bear has also used reverse TCP connections from Meterpreter installations to communicate back with C2 infrastructure.

GroupFIN6

FIN6 has used Metasploit Bind and Reverse TCP stagers.

GroupGamaredon Group

Gamaredon Group has used SOCKS5 over port 9050 for C2 communication.

GroupHAFNIUM

HAFNIUM has used TCP for C2.

GroupMetador

Metador has used TCP for C2.

View all 12 groups examples

Software88

Used byProcedure example
MalwareAnchor

Anchor has used ICMP in C2 communications.

MalwareAria-body

Aria-body has used TCP in C2 communications.

MalwareAuTo Stealer

AuTo Stealer can use TCP to communicate with command and control servers.

MalwareBandook

Bandook has a command built in to use a raw TCP socket.

MalwareBisonal

Bisonal has used raw sockets for network communication.

ToolBrute Ratel C4

Brute Ratel C4 has the ability to use TCP for external C2.

MalwareBUBBLEWRAP

BUBBLEWRAP can communicate using SOCKS.

MalwareCarbon

Carbon uses TCP and UDP for C2.

View all 88 software examples

Campaigns8

Used byProcedure example
Campaign2022 Ukraine Electric Power Attack

During the 2022 Ukraine Electric Power Attack, Sandworm Team proxied C2 communications within a TLS-based tunnel.

CampaignC0021

During C0021, the threat actors used TCP for some C2 communications.

CampaignCutting Edge

During Cutting Edge, threat actors used the Unix socket and a reverse TCP shell for C2 communications.

CampaignKV Botnet Activity

KV Botnet Activity command and control traffic uses a non-standard, likely custom protocol for communication.

CampaignOperation Wocao

During Operation Wocao, threat actors used a custom protocol for command and control.

CampaignRedDelta Modified PlugX Infection Chain Operations

Mustang Panda communicated over TCP 5000 from adversary administrative servers to adversary command and control nodes during RedDelta Modified PlugX Infection Chain Operations.

CampaignRedPenguin

During RedPenguin, UNC3886 leveraged malware that used UDP and TCP sockets for C2.

CampaignVersa Director Zero Day Exploitation

Versa Director Zero Day Exploitation used a non-standard TCP session to initialize communication prior to establishing HTTPS command and control.

References4

  1. Cisco Synful Knock Evolution Open source
    Graham Holmes. (2015, October 8). Evolution of attacks on Cisco IOS devices. Retrieved October 19, 2020.
  2. Google Cloud Threat Intelligence VMWare ESXi Zero-Day 2023 Open source
    Alexander Marvi, Brad Slaybaugh, Ron Craft, and Rufus Brown. (2023, June 13). VMware ESXi Zero-Day Used by Chinese Espionage Actor to Perform Privileged Guest Operations on Compromised Hypervisors. Retrieved March 26, 2025.
  3. Microsoft ICMP Open source
    Microsoft. (n.d.). Internet Control Message Protocol (ICMP) Basics. Retrieved December 1, 2014.
  4. Wikipedia OSI Open source
    Wikipedia. (n.d.). List of network protocols (OSI model). Retrieved December 4, 2014.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.