Technique.View on attack.mitre.org
Adversaries may use fallback or alternate communication channels if the primary channel is compromised or inaccessible in order to maintain reliable command and control and to avoid data transfer thresholds.
Rules on DetectionCode tagged with T1008.
| Rule | Level | Log source |
|---|---|---|
| Outlook Macro Execution Without Warning Setting Enabled | high | windows / registry_set |
| Potential Persistence Via Outlook LoadMacroProviderOnBoot Setting | high | windows / registry_set |
| Suspicious Outlook Macro Created | high | windows / file_event |
| New Outlook Macro Created | medium | windows / file_event |
| Rule | Type | Risk | Data source |
|---|---|---|---|
| Windows Outlook Macro Security Modified | TTP | NULL | Sysmon EventID 13 |
| Used by | Procedure example |
|---|---|
| GroupAPT41 | APT41 used the Steam community page as a fallback mechanism for C2. |
| GroupFIN7 | FIN7's Harpy backdoor malware can use DNS as a backup channel for C2 if HTTP fails. |
| GroupLazarus Group | Lazarus Group malware SierraAlfa sends data to one of the hard-coded C2 servers chosen at random, and if the transmission fails, chooses a new C2 server to attempt the transmission again. |
| GroupOilRig | OilRig malware ISMAgent falls back to its DNS tunneling mechanism if it is unable to reach the C2 server over HTTP. |
| GroupUNC3886 | UNC3886 has employed layers of redundancy to maintain access to compromised environments including network devices, hypervisors, and virtual machines. |
| Used by | Procedure example |
|---|---|
| MalwareAnchor | Anchor can use secondary C2 servers for communication after establishing connectivity and relaying victim information to primary C2 servers. |
| MalwareAppleSeed | AppleSeed can use a second channel for C2 when the primary channel is in upload mode. |
| MalwareBazar | Bazar has the ability to use an alternative C2 server if the primary server fails. |
| MalwareBISCUIT | BISCUIT malware contains a secondary fallback command and control server that is contacted after the primary command and control server. |
| MalwareBlackEnergy | BlackEnergy has the capability to communicate over a backup channel via plus.google.com. |
| MalwareBumblebee | Bumblebee can use backup C2 servers if the primary server fails. |
| MalwareCardinal RAT | Cardinal RAT can communicate over multiple C2 host and port combinations. |
| MalwareCharmPower | CharmPower can change its C2 channel once every 360 loops by retrieving a new domain from the actors’ S3 bucket. |
| Used by | Procedure example |
|---|---|
| CampaignNight Dragon | During Night Dragon, threat actors used company extranet servers as secondary C2 servers. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.