Web Service

T1102

Technique with 3 sub-techniques.View on attack.mitre.org

About this technique

Adversaries may use an existing, legitimate external Web service as a means for relaying data to/from a compromised system. Popular websites, cloud services, and social media acting as a mechanism for C2 may give a significant amount of cover due to the likelihood that hosts within a network are already communicating with them prior to a compromise. Using common services, such as those offered by Google, Microsoft, or Twitter, makes it easier for adversaries to hide in expected noise. Web service providers commonly use SSL/TLS encryption, giving adversaries an added level of protection.

Use of Web services may also protect back-end C2 infrastructure from discovery through malware binary analysis while also enabling operational resiliency (since this infrastructure may be dynamically changed).

Detection rules24

Rules on DetectionCode tagged with T1102 or one of its sub-techniques.

Sigma18

RuleLevelLog sourceTechnique
PwnDrp AccesscriticalNULL / proxyT1102.001 T1102.003
Communication To LocaltoNet Tunneling Service Initiatedhighwindows / network_connectionT1102
Communication To LocaltoNet Tunneling Service Initiated - Linuxhighlinux / network_connectionT1102
Communication To Ngrok Tunneling Service - Linuxhighlinux / network_connectionT1102
Communication To Ngrok Tunneling Service Initiatedhighwindows / network_connectionT1102
New Connection Initiated To Potential Dead Drop Resolver Domainhighwindows / network_connectionT1102 T1102.001
Process Initiated Network Connection To Ngrok Domainhighwindows / network_connectionT1102
Raw Paste Service AccesshighNULL / proxyT1102.001 T1102.003
Suspicious Child Process Of Manage Engine ServiceDeskhighwindows / process_creationT1102
Cloudflared Tunnel Connections Cleanupmediumwindows / process_creationT1102
Cloudflared Tunnel Executionmediumwindows / process_creationT1102
Github Self-Hosted Runner Executionmediumwindows / process_creationT1102.002
Network Connection Initiated To AzureWebsites.NET By Non-Browser Processmediumwindows / network_connectionT1102 T1102.001
Suspicious Non-Browser Network Communication With Google APImediumwindows / network_connectionT1102
Suspicious Non-Browser Network Communication With Telegram APImediumwindows / network_connectionT1102

Splunk6

RuleTypeRiskData sourceTechnique
Linux Ngrok Reverse Proxy UsageAnomalyNULLSysmon for Linux EventID 1T1102
Ngrok Reverse Proxy on NetworkAnomalyNULLSysmon EventID 22T1102
Potential Telegram API Request Via CommandLineAnomalyNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2T1102.002
Windows Abused Web ServicesAnomalyNULLSysmon EventID 22T1102
Windows DNS Query Request by Telegram Bot APIAnomalyNULLSysmon EventID 22T1102.002
Windows Ngrok Reverse Proxy UsageAnomalyNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2T1102

Sub-techniques3

IDNameExamples
T1102.001Dead Drop Resolver27
T1102.002Bidirectional Communication56
T1102.003One-Way Communication9

Groups15

Software31

Show 7 more

Campaigns4

Procedure examples50

Groups15

Used byProcedure example
GroupAPT32

APT32 has used Dropbox, Amazon S3, and Google Drive to host malicious downloads.

GroupAPT42

APT42 has used various links, such as links with typo-squatted domains, links to Dropbox files and links to fake Google sites, in spearphishing operations.

GroupEXOTIC LILY

EXOTIC LILY has used file-sharing services including WeTransfer, TransferNow, and OneDrive to deliver payloads.

GroupFIN6

FIN6 has used Pastebin and Google Storage to host content for their operations.

GroupFIN8

FIN8 has used sslip.io, a free IP to domain mapping service that also makes SSL certificate generation easier for traffic encryption, as part of their command and control.

GroupFox Kitten

Fox Kitten has used Amazon Web Services to host C2.

GroupGamaredon Group

Gamaredon Group has used GitHub repositories for downloaders which will be obtained by the group's .NET executable on the compromised system.

GroupInception

Inception has incorporated at least five different cloud service providers into their C2 infrastructure including CloudMe.

View all 15 groups examples

Software31

Used byProcedure example
MalwareAshTag

AshTag can download malicious payloads from file sharing services.

MalwareBADHATCH

BADHATCH can be utilized to abuse `sslip.io`, a free IP to domain mapping service, as part of actor-controlled C2 channels.

MalwareBazar

Bazar downloads have been hosted on Google Docs.

MalwareBoomBox

BoomBox can download files from Dropbox using a hardcoded access token.

MalwareBRICKSTORM

BRICKSTORM has leveraged DNS web services to resolve C2 IP addresses including sslip.io and nip.io. BRICKSTORM has also utilized Cloudflare Workers for C2 communications.

ToolBrute Ratel C4

Brute Ratel C4 can use legitimate websites for external C2 channels including Slack, Discord, and MS Teams.

MalwareBumblebee

Bumblebee has been downloaded to victim's machines from OneDrive.

MalwareCarbon

Carbon can use Pastebin to receive C2 commands.

View all 31 software examples

Campaigns4

Used byProcedure example
CampaignAPT41 DUST

APT41 DUST used compromised Google Workspace accounts for command and control.

CampaignC0017

During C0017, APT41 used the Cloudflare services for C2 communications.

CampaignC0027

During C0027, Scattered Spider downloaded tools from sites including file.io, GitHub, and paste.ee.

CampaignOperation Spalax

During Operation Spalax, the threat actors used OneDrive and MediaFire to host payloads.

References1

  1. Broadcom BirdyClient Microsoft Graph API 2024 Open source
    Broadcom. (2024, May 2). BirdyClient malware leverages Microsoft Graph API for C&C communication. Retrieved July 1, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.