Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Exfiltration/ T1041

T1041Exfiltration Over C2 Channel

T1041 — Exfiltration Over C2 Channel is a MITRE ATT&CK technique in the Exfiltration tactic. Clankerusecase tracks 88 detection use cases covering it and 62 threat-intel articles citing it.

Exfiltration
View on the matrix → Filter Detection Library MITRE official spec ↗
88Use cases
62Articles
0Sub-techniques
1Tactic

Use cases covering this technique (88)

Application data exfiltration successful Internal actions · alerting DD [WEEKLY] Cross-category credential-store enumeration with rapid egress to anonymizing tunnel/CDN Internal actions · alerting DSP [WEEKLY] Non-Browser Process Reads Browser Credential / Cookie SQLite Then Egresses to Public Destination Within 10 Minutes Internal actions · alerting DSPDD [WEEKLY] Package install lifecycle hook spawns interpreter that reads developer credential stores Internal install · alerting DSPCS [WEEKLY] Package-install lifecycle script harvests local credentials and beacons to a non-baselined domain Internal install · alerting DSPDD [WEEKLY] Package-manager child process credential fan-out with public egress (Mini Shai-Hulud / TeamPCP worm chain) Internal install · alerting DSPDD [WEEKLY] Package Manager / Dev-Tool Auto-Execution Triggers Non-Registry Egress or Credential-Store Access Internal install · alerting DSPDD [WEEKLY] Package-manager install hook spawns interpreter that beacons to non-registry host within 120s Internal install · alerting DSPDD [WEEKLY] Package Manager Install Hook Spawns Scripting Interpreter Then Touches Credential Files or Egresses Off-Registry Internal install · alerting DSPDD [WEEKLY] Package-Manager Install -> Interpreter Child -> Non-Registry Egress Within 5 Minutes Internal install · alerting DSPDD [WEEKLY] Package-manager install-time interpreter spawn with credential-file read and outbound egress within 120s Internal install · alerting DSPDD [WEEKLY] Supply-chain repo credential theft → outbound exfil to attacker infra Internal actions · alerting DSPDD Cisco ASA - Device File Copy to Remote Location ESCU actions · hunting P Potential Telegram API Request Via CommandLine ESCU actions · hunting P Windows Exfiltration Over C2 Via Invoke RestMethod ESCU actions · alerting P Windows Exfiltration Over C2 Via Powershell UploadString ESCU actions · alerting P Cisco Secure Firewall - High EVE Threat Confidence ESCU actions · hunting P Cisco Secure Firewall - Intrusion Events by Threat Activity ESCU actions · hunting P Cisco Secure Firewall - Lumma Stealer Download Attempt ESCU actions · hunting P Cisco Secure Firewall - Lumma Stealer Outbound Connection Attempt ESCU actions · hunting P Cisco Secure Firewall - Potential Data Exfiltration ESCU actions · hunting P Detect SNICat SNI Exfiltration ESCU actions · alerting P [LLM] Shell/curl spawned under Fluentd aggregator makes external network egress (post-RCE C2/exfil) Bespoke c2 · hunting DSPDDCS [LLM] Outbound beacon/callback from internal host to VeloCloud Orchestrator attacker IPs (CVE-2026-16812) Bespoke c2 · alerting DSΣPDDCS [LLM] curl/wget/nc spawned by n8n/Node reaching external hosts (post-escape C2/exfil) Bespoke c2 · hunting DSPDDCS [LLM] TELESHIM/MIXEDKEY sideload host binary beacons to Telegram (C2 + exfil) Bespoke actions · alerting DSΣPDDCS [LLM] Network connections to Cl0p CVE-2026-12569 C2 / staging infrastructure Bespoke c2 · hunting DSΣPDDCS [LLM] mrmustard stealer C2 exfil to metrics.femboy.energy Bespoke c2 · alerting DSΣPCS [LLM] CL-STA-1114 (Void Blizzard) Zimbra espionage C2/exfil infrastructure contact Bespoke c2 · hunting DSΣPDDCS [LLM] Browser-initiated webmail data exfiltration to CL-STA-1114 C2 Bespoke actions · hunting DSΣPDDCS [LLM] Network egress from CI/build host to GhostAction secret-exfil infrastructure Bespoke c2 · hunting DSΣPDDCS [LLM] Telegram bot C2 / crypto-wallet exfiltration from script-host process Bespoke actions · hunting DSΣPDDCS [LLM] Build runner beacon/exfil to Velora backdoor C2 (89.36.224.5 / datahub.ink) Bespoke c2 · hunting DSΣPDDCS [LLM] CI runner egress to Megalodon secret-exfil C2 216.126.225.129:8443 Bespoke actions · hunting DSΣPDDCS [LLM] C2 beacon to audit.checkmarx[.]cx /v1/telemetry (TeamPCP Shai-Hulud Third Coming) Bespoke c2 · alerting DSΣPDDCS [LLM] DIRAC dirac.cfg/proxy access followed by outbound egress from service process (exfiltration) Bespoke actions · alerting DSPCS [LLM] Injective SDK wallet-key exfil to lookalike domain testnet.archival.chain.grpc-web.injective.network Bespoke actions · alerting DSΣPDDCS [LLM] Outbound network connection from a child process of SiYuan.exe (post-RCE C2/exfil) Bespoke c2 · alerting DSPCS [LLM] Exfil to lookalike Injective gRPC-web subdomain (@injectivelabs stealer C2) Bespoke c2 · alerting DSΣPDDCS [LLM] TeamPCP Trivy/KICS supply-chain credential exfil to scan.aquasecurtiy.org & 45.148.10.212 Bespoke c2 · hunting DSΣPCS [LLM] DNS resolution of TeamPCP typosquat exfil domain scan.aquasecurtiy.org Bespoke c2 · alerting DSΣPCS [LLM] First-seen external egress from GitHub Actions Runner.Worker child process Bespoke actions · hunting DSPCS [LLM] JetBrains IDE process beaconing to malicious plugin C2 39.107.60.51 Bespoke c2 · alerting DSΣPDDCS [LLM] JetBrains IDE JVM plaintext HTTP POST to AI-key stealer endpoint /api/software/ Bespoke actions · hunting DSPDDCS [LLM] JetBrains IDE plugin AI-key exfil: endpoint egress to C2 39.107.60.51 Bespoke actions · hunting DSΣPDDCS [LLM] JetBrains AI-key stealer HTTP exfil: cleartext POST to /api/software/ path Bespoke c2 · hunting DSΣP [LLM] Outbound DNS / HTTP to Miasma C2 (git-service.com / m-kosche.com) Bespoke c2 · alerting DSΣPDDCS [LLM] Node child of node-gyp/python making outbound to GitHub dead-drop or anomalous web service during install Bespoke exfil · hunting DSPDDCS [LLM] Egress to typosquatted C2 flipboxstudio.info (Laravel-Lang Composer SC) Bespoke c2 · alerting DSΣPDDCS [LLM] node child of npm install initiating outbound network to non-registry destination Bespoke c2 · hunting DSPDDCS [LLM] HTTPS POST to /startlog with codexui User-Agent (Codex exfil over the wire) Bespoke actions · alerting DSΣPDDCS [LLM] Laravel-Lang supply chain C2/exfil to flipboxstudio.info Bespoke c2 · alerting DSΣPDDCS [LLM] C2 egress to flipboxstudio.info from Laravel-Lang composer dropper Bespoke c2 · alerting DSΣPDDCS [LLM] Megalodon CI/CD exfil: outbound HTTPS to C2 216.126.225.129:8443 Bespoke c2 · hunting DSΣPDDCS [LLM] Megalodon harvester: curl POST to C2 /collect endpoint on Linux runner Bespoke actions · alerting DSΣPDDCS [LLM] Mini Shai-Hulud C2 exfil to t.m-kosche.com disguised as OpenTelemetry collector Bespoke c2 · alerting DSΣPDDCS [LLM] node-ipc C2 callback to sh.azurestaticprovider.net (May 2026 npm supply-chain) Bespoke c2 · alerting DSΣPDDCS [LLM] Outbound egress to node-ipc stealer infrastructure (azurestaticprovider[.]net / 37.16.75.69) Bespoke actions · alerting DSΣPDDCS [LLM] DNS lookup for azurestaticprovider[.]net node-ipc exfil domain Bespoke c2 · alerting DSΣPDDCS [LLM] Session/Oxen P2P exfil DNS or TCP to getsession.org from build/CI host Bespoke c2 · alerting DSΣPDD [LLM] Outbound to elementary-data exfil C2 igotnofriendsonlineorirl-imgonnakmslmao.sky Bespoke c2 · alerting DSΣPDDCS [LLM] Stage-3 exfil archive trin.tar.gz POST via curl --data-binary Bespoke actions · alerting DSΣPDDCS [LLM] TeamPCP @bitwarden/cli stealer exfil to audit.checkmarx.cx (94.154.172.43) Bespoke c2 · hunting DSΣPDDCS [LLM] Mini Shai-Hulud: Bun runtime executing `router_runtime.js` (2nd-stage stealer) Bespoke actions · alerting DSΣPDD [LLM] Exfil to skyhanni.cloud C2 with X-Rise-To-The-Trinny header Bespoke c2 · alerting DSΣPDDCS [LLM] Trust Wallet Shai-Hulud C2 callback to metrics-trustwallet.com / 138.124.70.40 Bespoke c2 · alerting DSΣPDDCS [LLM] TeamPCP exfiltration archive tpcp.tar.gz created on disk Bespoke actions · alerting DSΣPDDCS [LLM] TeamPCP C2 / exfil egress to models.litellm.cloud, checkmarx.zone and AS205759 nodes Bespoke c2 · hunting DSΣPDDCS [LLM] Outbound DNS/HTTPS to TeamPCP exfil domain models.litellm.cloud (litellm PyPI compromise) Bespoke c2 · alerting DSΣPDDCS [LLM] TeamPCP tpcp.tar.gz exfil POST signature on egress proxy / WAF Bespoke actions · alerting DSΣPDDCS [LLM] DNS / HTTPS egress to TeamPCP exfil infra (models.litellm.cloud, checkmarx.zone) Bespoke c2 · hunting DSΣPDDCS [LLM] GlassWorm hardcoded C2 IP egress (45.32.150.251 / 217.69.3.152) for Stage-2 fetch and exfil Bespoke c2 · hunting DSΣPDDCS [LLM] Outbound traffic to *.oastify.com (BurpSuite Collaborator) from corporate endpoint Bespoke exfiltration · alerting DSΣPDDCS [LLM] GhostChat C2 beacon URL pattern: hitpak.org/page.php?tynor=<host>sss<user> Bespoke exfil · alerting DSΣPDDCS [LLM] MuddyViper C2 fingerprint: 'A WinHTTP Example Program/1.0' UA + distinctive URI paths Bespoke c2 · alerting DSΣPDDCS [LLM] Scavenger Stealer C2 beacon to corroborated infrastructure (datahog.su / datalytica.su / smartscreen-api.com) Bespoke c2 · alerting DSΣPDDCS [LLM] Moq SponsorLink email exfil egress to cdn.devlooped.com / SponsorLink blob Bespoke c2 · hunting DSΣPDDCS [LLM] npm/PyPI install-script beacon to hardcoded C2 3.72.6.53 (django-yauth supply chain) Bespoke c2 · alerting DSΣPDDCSCW [LLM] Package-manager install hook spawning host-recon curl/wget exfil (pre.sh pattern) Bespoke install · alerting DSΣPDDCS [LLM] npm dropper exfiltration to pkgio.com telemetry server Bespoke exfil · alerting DSΣPDDCS [LLM] gxm-reference second-stage backdoor C2 to 82.196.7.23 / 82.196.15.238 (/callbackupload) Bespoke c2 · hunting DSΣPDDCS [LLM] CodeCov Bash Uploader CI env-var exfiltration via curl (<<<<<< ENV marker) Bespoke actions · alerting DSΣPDDCS [LLM] CodeCov uploader egress to non-CodeCov host (surfaces exfil server IP) Bespoke c2 · hunting DSPCS [LLM] Environment-variable exfiltration to hacktask C2 (npm.hacktask.net) Bespoke c2 · alerting DSΣPDDCS [LLM] Exfil to jeIlyfish C2 68.183.212.246:32258 Bespoke actions · hunting DSΣPDDCS [LLM] Exfiltration callback to mironanoru.zzz.com.ua (rest-client backdoor C2) Bespoke actions · alerting DSΣPDDCS [LLM] Copay wallet-stealer C2 exfil to copayapi.host / 111.90.151.134 Bespoke c2 · hunting DSΣPDDCS [LLM] Node.js process spawning shell/curl to read and exfiltrate /etc/passwd (Dust.js post-exploit) Bespoke actions · alerting DSΣPDDCS

Articles citing this technique (62)