T1041Exfiltration Over C2 Channel
T1041 — Exfiltration Over C2 Channel is a MITRE ATT&CK technique in the Exfiltration tactic. Clankerusecase tracks 70 detection use cases covering it and 49 threat-intel articles citing it.
Exfiltration
70Use cases
49Articles
0Sub-techniques
1Tactic
Use cases covering this technique (70)
Application data exfiltration successful [WEEKLY] Cross-category credential-store enumeration with rapid egress to anonymizing tunnel/CDN [WEEKLY] Non-Browser Process Reads Browser Credential / Cookie SQLite Then Egresses to Public Destination Within 10 Minutes [WEEKLY] Package install lifecycle hook spawns interpreter that reads developer credential stores [WEEKLY] Package-install lifecycle script harvests local credentials and beacons to a non-baselined domain [WEEKLY] Package-manager child process credential fan-out with public egress (Mini Shai-Hulud / TeamPCP worm chain) [WEEKLY] Package Manager / Dev-Tool Auto-Execution Triggers Non-Registry Egress or Credential-Store Access [WEEKLY] Package-manager install hook spawns interpreter that beacons to non-registry host within 120s [WEEKLY] Package Manager Install Hook Spawns Scripting Interpreter Then Touches Credential Files or Egresses Off-Registry [WEEKLY] Package-Manager Install -> Interpreter Child -> Non-Registry Egress Within 5 Minutes [WEEKLY] Package-manager install-time interpreter spawn with credential-file read and outbound egress within 120s [WEEKLY] Supply-chain repo credential theft → outbound exfil to attacker infra Cisco ASA - Device File Copy to Remote Location Potential Telegram API Request Via CommandLine Windows Exfiltration Over C2 Via Invoke RestMethod Windows Exfiltration Over C2 Via Powershell UploadString Cisco Secure Firewall - High EVE Threat Confidence Cisco Secure Firewall - Intrusion Events by Threat Activity Cisco Secure Firewall - Lumma Stealer Download Attempt Cisco Secure Firewall - Lumma Stealer Outbound Connection Attempt Cisco Secure Firewall - Potential Data Exfiltration Detect SNICat SNI Exfiltration [LLM] Shai-Hulud worm exfil — outbound to webhook.site/bb8ca5f6 from developer or CI process [LLM] Agentjacking C2/exfiltration to advisory-tracker.com (Tenet Sentry-MCP attack) [LLM] Outbound public network from LangGraph runtime to non-allowlisted destination [LLM] OpenClaw agent runtime reads secrets store (.env / .aws / id_rsa) followed by external network egress [LLM] AI-agent-driven mailbox auto-forwards messages to first-time-seen external recipient [LLM] npm/node install-time process beaconing to webhook.site, sfrclak.com or 142.11.206.73 [LLM] Meta Graph API request with access_token in URL query string (CVE-2026-48039 leak signature) [LLM] build.rs invoking curl POST to Sentry envelope endpoint with code diff payload [LLM] Outbound DNS / HTTP to Miasma C2 (git-service.com / m-kosche.com) [LLM] Node child of node-gyp/python making outbound to GitHub dead-drop or anomalous web service during install [LLM] GitHub Actions runner: node from Claude Code Action egresses to non-Anthropic/non-GitHub endpoint [LLM] Mini Shai-Hulud npm worm exfiltration to t.m-kosche.com OpenTelemetry endpoint [LLM] C2 beacon to audit.checkmarx[.]cx /v1/telemetry (TeamPCP Shai-Hulud Third Coming) [LLM] Egress to typosquatted C2 flipboxstudio.info (Laravel-Lang Composer SC) [LLM] Shai-Hulud exfiltration: node.exe POSTs to api.github.com creating public repo [LLM] HTTPS POST to /startlog with codexui User-Agent (Codex exfil over the wire) [LLM] Outbound recon callback from Yamcs host (curl/shell child of JVM to public IP) [LLM] Laravel-Lang supply chain C2/exfil to flipboxstudio.info [LLM] C2 egress to flipboxstudio.info from Laravel-Lang composer dropper [LLM] Megalodon CI/CD exfil: outbound HTTPS to C2 216.126.225.129:8443 [LLM] Megalodon harvester: curl POST to C2 /collect endpoint on Linux runner [LLM] Mini Shai-Hulud C2 callback to zero.masscan.cloud / 94.154.172.43 [LLM] Mini Shai-Hulud / TeamPCP C2 beacon to api.masscan.cloud / git-tanstack.com / *.getsession.org [LLM] Mini Shai-Hulud C2 exfil to t.m-kosche.com disguised as OpenTelemetry collector [LLM] node-ipc C2 callback to sh.azurestaticprovider.net (May 2026 npm supply-chain) [LLM] Arcane backend host outbound Git/HTTPS to non-allowlisted host on port 22/443 (CVE-2026-45625 credential sink) [LLM] Outbound connection to Gremlin Stealer exfiltration host 194.87.92.109 [LLM] Outbound egress to node-ipc stealer infrastructure (azurestaticprovider[.]net / 37.16.75.69) [LLM] DNS lookup for azurestaticprovider[.]net node-ipc exfil domain [LLM] Rust cargo-test binary in target/debug/deps spawning shell or network tool (CVE-2026-45311 exploitation) [LLM] Session/Oxen P2P exfil DNS or TCP to getsession.org from build/CI host [LLM] Outbound to elementary-data exfil C2 igotnofriendsonlineorirl-imgonnakmslmao.sky [LLM] Stage-3 exfil archive trin.tar.gz POST via curl --data-binary [LLM] TeamPCP @bitwarden/cli stealer exfil to audit.checkmarx.cx (94.154.172.43) [LLM] Mini Shai-Hulud: Bun runtime executing `router_runtime.js` (2nd-stage stealer) [LLM] Exfil to skyhanni.cloud C2 with X-Rise-To-The-Trinny header [LLM] Trust Wallet Shai-Hulud C2 callback to metrics-trustwallet.com / 138.124.70.40 [LLM] TeamPCP exfiltration archive tpcp.tar.gz created on disk [LLM] TeamPCP C2 / exfil egress to models.litellm.cloud, checkmarx.zone and AS205759 nodes [LLM] Outbound DNS/HTTPS to TeamPCP exfil domain models.litellm.cloud (litellm PyPI compromise) [LLM] TeamPCP tpcp.tar.gz exfil POST signature on egress proxy / WAF [LLM] DNS / HTTPS egress to TeamPCP exfil infra (models.litellm.cloud, checkmarx.zone) [LLM] GlassWorm hardcoded C2 IP egress (45.32.150.251 / 217.69.3.152) for Stage-2 fetch and exfil [LLM] Outbound traffic to *.oastify.com (BurpSuite Collaborator) from corporate endpoint [LLM] GhostChat C2 beacon URL pattern: hitpak.org/page.php?tynor=<host>sss<user> [LLM] MuddyViper C2 fingerprint: 'A WinHTTP Example Program/1.0' UA + distinctive URI paths [LLM] Scavenger Stealer C2 beacon to corroborated infrastructure (datahog.su / datalytica.su / smartscreen-api.com) [LLM] Moq SponsorLink email exfil egress to cdn.devlooped.com / SponsorLink blobArticles citing this technique (49)
crit [GHSA / CRITICAL] GHSA-jpvj-wpmj-h7rv: Supply chain compromise via malicious @cap-js/openapi art-123
crit Malicious node-ipc versions published to npm in suspected maintainer account compromise art-284