T1041 Exfiltration Over C2 Channel — ATT&CK Technique
Adversaries may steal data by exfiltrating it over an existing command and control channel. Stolen data is encoded into the normal communications channel using the same protocol as command and control communications.
Detection coverage (15)
- Equation Group C2 Communication high
- Shai-Hulud NPM Package Malicious Exfiltration via Curl high
- Tunneling Tool Execution medium
- OpenCanary - TFTP Request high
- Network Communication Initiated To Portmap.IO Domain medium
- Cisco ASA - Device File Copy to Remote Location
- Potential Telegram API Request Via CommandLine
- Windows Exfiltration Over C2 Via Powershell UploadString
- Windows Exfiltration Over C2 Via Invoke RestMethod
- Cisco Secure Firewall - Lumma Stealer Download Attempt
- Cisco Secure Firewall - High EVE Threat Confidence
- Cisco Secure Firewall - Intrusion Events by Threat Activity
- Cisco Secure Firewall - Lumma Stealer Outbound Connection Attempt
- Cisco Secure Firewall - Potential Data Exfiltration
- Detect SNICat SNI Exfiltration
Malware using this technique
- OilBooster
- MechaFlounder
- LAMEHUG
- PoetRAT
- ShimRatReporter
- Shark
- Sagerunex
- HOPLIGHT
- SLOTHFULMEDIA
- StrelaStealer
- OutSteel
- BeaverTail
- Bandook
- BRICKSTORM
- HTTPTroy
- SharpDisco
- HotCroissant
- DnsSystem
- Machete
- Bumblebee
- AppleJeus
- NightClub
- Line Runner
- WarzoneRAT
- Torisma
- SUGARDUMP
- Squirrelwaffle
- FoggyWeb
- Carberp
- Misdat
- LunarMail
- Woody RAT
- StrongPity
- NETEAGLE
- LightSpy
- XCSSET
- Empire
- Pupy
- LightNeuron
- Grandoreiro
- TRANSLATEXT
- Line Dancer
- TrickBot
- STARWHALE
- BLUELIGHT
- QakBot
- Ursnif
- PowerExchange
- LODEINFO
- AshTag