Technique with 3 sub-techniques.View on attack.mitre.org
Adversaries may use an existing, legitimate external Web service as a means for relaying data to/from a compromised system. Popular websites, cloud services, and social media acting as a mechanism for C2 may give a significant amount of cover due to the likelihood that hosts within a network are already communicating with them prior to a compromise. Using common services, such as those offered by Google, Microsoft, or Twitter, makes it easier for adversaries to hide in expected noise. Web service providers commonly use SSL/TLS encryption, giving adversaries an added level of protection.
Use of Web services may also protect back-end C2 infrastructure from discovery through malware binary analysis while also enabling operational resiliency (since this infrastructure may be dynamically changed).
Rules on DetectionCode tagged with T1102 or one of its sub-techniques.
| Rule | Type | Risk | Data source | Technique |
|---|---|---|---|---|
| Linux Ngrok Reverse Proxy Usage | Anomaly | NULL | Sysmon for Linux EventID 1 | T1102 |
| Ngrok Reverse Proxy on Network | Anomaly | NULL | Sysmon EventID 22 | T1102 |
| Potential Telegram API Request Via CommandLine | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1102.002 |
| Windows Abused Web Services | Anomaly | NULL | Sysmon EventID 22 | T1102 |
| Windows DNS Query Request by Telegram Bot API | Anomaly | NULL | Sysmon EventID 22 | T1102.002 |
| Windows Ngrok Reverse Proxy Usage | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1102 |
| Used by | Procedure example |
|---|---|
| GroupAPT32 | APT32 has used Dropbox, Amazon S3, and Google Drive to host malicious downloads. |
| GroupAPT42 | APT42 has used various links, such as links with typo-squatted domains, links to Dropbox files and links to fake Google sites, in spearphishing operations. |
| GroupEXOTIC LILY | EXOTIC LILY has used file-sharing services including WeTransfer, TransferNow, and OneDrive to deliver payloads. |
| GroupFIN6 | FIN6 has used Pastebin and Google Storage to host content for their operations. |
| GroupFIN8 | FIN8 has used |
| GroupFox Kitten | Fox Kitten has used Amazon Web Services to host C2. |
| GroupGamaredon Group | Gamaredon Group has used GitHub repositories for downloaders which will be obtained by the group's .NET executable on the compromised system. |
| GroupInception | Inception has incorporated at least five different cloud service providers into their C2 infrastructure including CloudMe. |
| Used by | Procedure example |
|---|---|
| MalwareAshTag | AshTag can download malicious payloads from file sharing services. |
| MalwareBADHATCH | BADHATCH can be utilized to abuse `sslip.io`, a free IP to domain mapping service, as part of actor-controlled C2 channels. |
| MalwareBazar | Bazar downloads have been hosted on Google Docs. |
| MalwareBoomBox | BoomBox can download files from Dropbox using a hardcoded access token. |
| MalwareBRICKSTORM | BRICKSTORM has leveraged DNS web services to resolve C2 IP addresses including sslip.io and nip.io. BRICKSTORM has also utilized Cloudflare Workers for C2 communications. |
| ToolBrute Ratel C4 | Brute Ratel C4 can use legitimate websites for external C2 channels including Slack, Discord, and MS Teams. |
| MalwareBumblebee | Bumblebee has been downloaded to victim's machines from OneDrive. |
| MalwareCarbon | Carbon can use Pastebin to receive C2 commands. |
| Used by | Procedure example |
|---|---|
| CampaignAPT41 DUST | APT41 DUST used compromised Google Workspace accounts for command and control. |
| CampaignC0017 | During C0017, APT41 used the Cloudflare services for C2 communications. |
| CampaignC0027 | During C0027, Scattered Spider downloaded tools from sites including file.io, GitHub, and paste.ee. |
| CampaignOperation Spalax | During Operation Spalax, the threat actors used OneDrive and MediaFire to host payloads. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.