Fallback Channels

T1008

Technique.View on attack.mitre.org

About this technique

Adversaries may use fallback or alternate communication channels if the primary channel is compromised or inaccessible in order to maintain reliable command and control and to avoid data transfer thresholds.

Detection rules5

Rules on DetectionCode tagged with T1008.

Sigma4

RuleLevelLog source
Outlook Macro Execution Without Warning Setting Enabledhighwindows / registry_set
Potential Persistence Via Outlook LoadMacroProviderOnBoot Settinghighwindows / registry_set
Suspicious Outlook Macro Createdhighwindows / file_event
New Outlook Macro Createdmediumwindows / file_event

Splunk1

RuleTypeRiskData source
Windows Outlook Macro Security ModifiedTTPNULLSysmon EventID 13

Groups5

Software51

Show 27 more

Campaigns1

Procedure examples57

Groups5

Used byProcedure example
GroupAPT41

APT41 used the Steam community page as a fallback mechanism for C2.

GroupFIN7

FIN7's Harpy backdoor malware can use DNS as a backup channel for C2 if HTTP fails.

GroupLazarus Group

Lazarus Group malware SierraAlfa sends data to one of the hard-coded C2 servers chosen at random, and if the transmission fails, chooses a new C2 server to attempt the transmission again.

GroupOilRig

OilRig malware ISMAgent falls back to its DNS tunneling mechanism if it is unable to reach the C2 server over HTTP.

GroupUNC3886

UNC3886 has employed layers of redundancy to maintain access to compromised environments including network devices, hypervisors, and virtual machines.

Software51

Used byProcedure example
MalwareAnchor

Anchor can use secondary C2 servers for communication after establishing connectivity and relaying victim information to primary C2 servers.

MalwareAppleSeed

AppleSeed can use a second channel for C2 when the primary channel is in upload mode.

MalwareBazar

Bazar has the ability to use an alternative C2 server if the primary server fails.

MalwareBISCUIT

BISCUIT malware contains a secondary fallback command and control server that is contacted after the primary command and control server.

MalwareBlackEnergy

BlackEnergy has the capability to communicate over a backup channel via plus.google.com.

MalwareBumblebee

Bumblebee can use backup C2 servers if the primary server fails.

MalwareCardinal RAT

Cardinal RAT can communicate over multiple C2 host and port combinations.

MalwareCharmPower

CharmPower can change its C2 channel once every 360 loops by retrieving a new domain from the actors’ S3 bucket.

View all 51 software examples

Campaigns1

Used byProcedure example
CampaignNight Dragon

During Night Dragon, threat actors used company extranet servers as secondary C2 servers.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.