T1041Exfiltration Over C2 Channel
T1041 — Exfiltration Over C2 Channel is a MITRE ATT&CK technique in the Exfiltration tactic. Clankerusecase tracks 88 detection use cases covering it and 62 threat-intel articles citing it.
Exfiltration
88Use cases
62Articles
0Sub-techniques
1Tactic
Use cases covering this technique (88)
Application data exfiltration successful [WEEKLY] Cross-category credential-store enumeration with rapid egress to anonymizing tunnel/CDN [WEEKLY] Non-Browser Process Reads Browser Credential / Cookie SQLite Then Egresses to Public Destination Within 10 Minutes [WEEKLY] Package install lifecycle hook spawns interpreter that reads developer credential stores [WEEKLY] Package-install lifecycle script harvests local credentials and beacons to a non-baselined domain [WEEKLY] Package-manager child process credential fan-out with public egress (Mini Shai-Hulud / TeamPCP worm chain) [WEEKLY] Package Manager / Dev-Tool Auto-Execution Triggers Non-Registry Egress or Credential-Store Access [WEEKLY] Package-manager install hook spawns interpreter that beacons to non-registry host within 120s [WEEKLY] Package Manager Install Hook Spawns Scripting Interpreter Then Touches Credential Files or Egresses Off-Registry [WEEKLY] Package-Manager Install -> Interpreter Child -> Non-Registry Egress Within 5 Minutes [WEEKLY] Package-manager install-time interpreter spawn with credential-file read and outbound egress within 120s [WEEKLY] Supply-chain repo credential theft → outbound exfil to attacker infra Cisco ASA - Device File Copy to Remote Location Potential Telegram API Request Via CommandLine Windows Exfiltration Over C2 Via Invoke RestMethod Windows Exfiltration Over C2 Via Powershell UploadString Cisco Secure Firewall - High EVE Threat Confidence Cisco Secure Firewall - Intrusion Events by Threat Activity Cisco Secure Firewall - Lumma Stealer Download Attempt Cisco Secure Firewall - Lumma Stealer Outbound Connection Attempt Cisco Secure Firewall - Potential Data Exfiltration Detect SNICat SNI Exfiltration [LLM] Shell/curl spawned under Fluentd aggregator makes external network egress (post-RCE C2/exfil) [LLM] Outbound beacon/callback from internal host to VeloCloud Orchestrator attacker IPs (CVE-2026-16812) [LLM] curl/wget/nc spawned by n8n/Node reaching external hosts (post-escape C2/exfil) [LLM] TELESHIM/MIXEDKEY sideload host binary beacons to Telegram (C2 + exfil) [LLM] Network connections to Cl0p CVE-2026-12569 C2 / staging infrastructure [LLM] mrmustard stealer C2 exfil to metrics.femboy.energy [LLM] CL-STA-1114 (Void Blizzard) Zimbra espionage C2/exfil infrastructure contact [LLM] Browser-initiated webmail data exfiltration to CL-STA-1114 C2 [LLM] Network egress from CI/build host to GhostAction secret-exfil infrastructure [LLM] Telegram bot C2 / crypto-wallet exfiltration from script-host process [LLM] Build runner beacon/exfil to Velora backdoor C2 (89.36.224.5 / datahub.ink) [LLM] CI runner egress to Megalodon secret-exfil C2 216.126.225.129:8443 [LLM] C2 beacon to audit.checkmarx[.]cx /v1/telemetry (TeamPCP Shai-Hulud Third Coming) [LLM] DIRAC dirac.cfg/proxy access followed by outbound egress from service process (exfiltration) [LLM] Injective SDK wallet-key exfil to lookalike domain testnet.archival.chain.grpc-web.injective.network [LLM] Outbound network connection from a child process of SiYuan.exe (post-RCE C2/exfil) [LLM] Exfil to lookalike Injective gRPC-web subdomain (@injectivelabs stealer C2) [LLM] TeamPCP Trivy/KICS supply-chain credential exfil to scan.aquasecurtiy.org & 45.148.10.212 [LLM] DNS resolution of TeamPCP typosquat exfil domain scan.aquasecurtiy.org [LLM] First-seen external egress from GitHub Actions Runner.Worker child process [LLM] JetBrains IDE process beaconing to malicious plugin C2 39.107.60.51 [LLM] JetBrains IDE JVM plaintext HTTP POST to AI-key stealer endpoint /api/software/ [LLM] JetBrains IDE plugin AI-key exfil: endpoint egress to C2 39.107.60.51 [LLM] JetBrains AI-key stealer HTTP exfil: cleartext POST to /api/software/ path [LLM] Outbound DNS / HTTP to Miasma C2 (git-service.com / m-kosche.com) [LLM] Node child of node-gyp/python making outbound to GitHub dead-drop or anomalous web service during install [LLM] Egress to typosquatted C2 flipboxstudio.info (Laravel-Lang Composer SC) [LLM] node child of npm install initiating outbound network to non-registry destination [LLM] HTTPS POST to /startlog with codexui User-Agent (Codex exfil over the wire) [LLM] Laravel-Lang supply chain C2/exfil to flipboxstudio.info [LLM] C2 egress to flipboxstudio.info from Laravel-Lang composer dropper [LLM] Megalodon CI/CD exfil: outbound HTTPS to C2 216.126.225.129:8443 [LLM] Megalodon harvester: curl POST to C2 /collect endpoint on Linux runner [LLM] Mini Shai-Hulud C2 exfil to t.m-kosche.com disguised as OpenTelemetry collector [LLM] node-ipc C2 callback to sh.azurestaticprovider.net (May 2026 npm supply-chain) [LLM] Outbound egress to node-ipc stealer infrastructure (azurestaticprovider[.]net / 37.16.75.69) [LLM] DNS lookup for azurestaticprovider[.]net node-ipc exfil domain [LLM] Session/Oxen P2P exfil DNS or TCP to getsession.org from build/CI host [LLM] Outbound to elementary-data exfil C2 igotnofriendsonlineorirl-imgonnakmslmao.sky [LLM] Stage-3 exfil archive trin.tar.gz POST via curl --data-binary [LLM] TeamPCP @bitwarden/cli stealer exfil to audit.checkmarx.cx (94.154.172.43) [LLM] Mini Shai-Hulud: Bun runtime executing `router_runtime.js` (2nd-stage stealer) [LLM] Exfil to skyhanni.cloud C2 with X-Rise-To-The-Trinny header [LLM] Trust Wallet Shai-Hulud C2 callback to metrics-trustwallet.com / 138.124.70.40 [LLM] TeamPCP exfiltration archive tpcp.tar.gz created on disk [LLM] TeamPCP C2 / exfil egress to models.litellm.cloud, checkmarx.zone and AS205759 nodes [LLM] Outbound DNS/HTTPS to TeamPCP exfil domain models.litellm.cloud (litellm PyPI compromise) [LLM] TeamPCP tpcp.tar.gz exfil POST signature on egress proxy / WAF [LLM] DNS / HTTPS egress to TeamPCP exfil infra (models.litellm.cloud, checkmarx.zone) [LLM] GlassWorm hardcoded C2 IP egress (45.32.150.251 / 217.69.3.152) for Stage-2 fetch and exfil [LLM] Outbound traffic to *.oastify.com (BurpSuite Collaborator) from corporate endpoint [LLM] GhostChat C2 beacon URL pattern: hitpak.org/page.php?tynor=<host>sss<user> [LLM] MuddyViper C2 fingerprint: 'A WinHTTP Example Program/1.0' UA + distinctive URI paths [LLM] Scavenger Stealer C2 beacon to corroborated infrastructure (datahog.su / datalytica.su / smartscreen-api.com) [LLM] Moq SponsorLink email exfil egress to cdn.devlooped.com / SponsorLink blob [LLM] npm/PyPI install-script beacon to hardcoded C2 3.72.6.53 (django-yauth supply chain) [LLM] Package-manager install hook spawning host-recon curl/wget exfil (pre.sh pattern) [LLM] npm dropper exfiltration to pkgio.com telemetry server [LLM] gxm-reference second-stage backdoor C2 to 82.196.7.23 / 82.196.15.238 (/callbackupload) [LLM] CodeCov Bash Uploader CI env-var exfiltration via curl (<<<<<< ENV marker) [LLM] CodeCov uploader egress to non-CodeCov host (surfaces exfil server IP) [LLM] Environment-variable exfiltration to hacktask C2 (npm.hacktask.net) [LLM] Exfil to jeIlyfish C2 68.183.212.246:32258 [LLM] Exfiltration callback to mironanoru.zzz.com.ua (rest-client backdoor C2) [LLM] Copay wallet-stealer C2 exfil to copayapi.host / 111.90.151.134 [LLM] Node.js process spawning shell/curl to read and exfiltrate /etc/passwd (Dust.js post-exploit)Articles citing this technique (62)
crit Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE art-75
high Find Unused, Stale, and OIDC-Replaceable GitHub Actions Secrets Across Your GitHub Organization art-114
crit 10 Layers Deep: How StepSecurity Stops TeamPCP's Trivy Supply Chain Attack on GitHub Actions art-253
crit Malicious node-ipc versions published to npm in suspected maintainer account compromise art-431
high Malicious Release of elementary-data PyPI Package Steals Cloud Credentials from Data Engineers art-475