Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Command and Control/ T1071.001

T1071.001Web Protocols

T1071.001 — Web Protocols is a MITRE ATT&CK technique in the Command and Control tactic. Clankerusecase tracks 218 detection use cases covering it and 197 threat-intel articles citing it.

Command and Control
View on the matrix → Filter Detection Library MITRE official spec ↗
218Use cases
197Articles
0Sub-techniques
1Tactic

Use cases covering this technique (218)

Beaconing — periodic outbound to small set of destinations Internal c2 · alerting DSP [WEEKLY] Brand-Impersonation Domain Fetch Followed by User-Context Loader Within 10 Minutes Internal delivery · alerting DSPDD [WEEKLY] Developer/AI tooling runtime spawns shell or egress LOLBin (unauth RCE post-expl) Internal exploit · alerting DSPDDCS [WEEKLY] Developer package install spawning script-host with non-registry C2 within 5 minutes Internal install · alerting DSPDD [WEEKLY] Internet-facing server process spawns interpreter then beacons to first-seen external host within 5 minutes Internal install · alerting DSPDD [WEEKLY] Internet-facing service process spawns shell/LOLBin within minutes of public inbound connection — post-RCE command execution Internal exploit · alerting DSΣPDD [WEEKLY] Non-Browser Process Reads Browser Credential / Cookie SQLite Then Egresses to Public Destination Within 10 Minutes Internal actions · alerting DSPDD [WEEKLY] npm Install-Time Lifecycle Hook Triggers Outbound Egress to Newly-Seen Domain (Shai-Hulud/Miasma/IronWorm pattern) Internal install · alerting DSPDD [WEEKLY] Package Manager / Dev-Tool Auto-Execution Triggers Non-Registry Egress or Credential-Store Access Internal install · alerting DSPDD [WEEKLY] Package-manager install hook spawns interpreter that beacons to non-registry host within 120s Internal install · alerting DSPDD [WEEKLY] Package Manager Install Hook Spawns Scripting Interpreter Then Touches Credential Files or Egresses Off-Registry Internal install · alerting DSPDD [WEEKLY] Package Manager Install Spawning Outbound Egress to Non-Registry Infrastructure Within 5 Minutes Internal install · alerting DSPDD [WEEKLY] Package manager lifecycle hook spawns network-fetching shell or runtime Internal install · alerting DSΣPDD [WEEKLY] Package manager lifecycle hook spawns runtime with outbound egress to non-registry host within 5 minutes Internal install · alerting DSPDD [WEEKLY] Package manager spawns network-fetching child to public code-hosting within minutes of install Internal install · alerting DSPDD [WEEKLY] Script Interpreter or Package-Install Hook Egress to Free-Tier Edge SaaS Within 5 Minutes of Process Start Internal c2 · alerting DSΣPDD [WEEKLY] Self-hosted application service spawns shell or SSH within seconds of inbound unauthenticated API write Internal exploit · alerting DSPDD [WEEKLY] Server / AI-agent process spawns shell or LOLBIN with public egress — post-RCE behavioural chain Internal exploit · alerting DSΣPDD [WEEKLY] Supply-chain repo credential theft → outbound exfil to attacker infra Internal actions · alerting DSPDD Windows ConvertTo-AADIntBackdoor Execution Via PowerShell Script ESCU actions · alerting P Cisco Secure Firewall - Blacklisted SSL Certificate Fingerprint ESCU actions · alerting P Cisco Secure Firewall - Connection to File Sharing Domain ESCU actions · hunting P Cisco Secure Firewall - High EVE Threat Confidence ESCU actions · hunting P Cisco Secure Firewall - Wget or Curl Download ESCU actions · hunting P HTTP C2 Framework User Agent ESCU actions · alerting P HTTP Malware User Agent ESCU actions · alerting P HTTP PUA User Agent ESCU actions · hunting P HTTP RMM User Agent ESCU actions · hunting P HTTP Duplicated Header ESCU actions · hunting P HTTP Possible Request Smuggling ESCU actions · alerting P HTTP Rapid POST with Mixed Status Codes ESCU actions · hunting P HTTP Request to Reserved Name on IIS Server ESCU actions · alerting P HTTP Scripting Tool User Agent ESCU actions · hunting P Detect web traffic to dynamic domain providers ESCU actions · alerting P HTTP Suspicious Tool User Agent ESCU actions · hunting P [LLM] Velvet Ant air-gap bridge — fcgiwrap/uptime spawning SSH from HTTP-driven FastCGI Bespoke actions · alerting DSΣPDDCS [LLM] GS-Netcat reverse shell — host beacons to gs.thc.org Global Socket relay Bespoke c2 · alerting DSΣPDDCS [LLM] AUR build process egress to temp.sh or github.com/fardewoak/nodejs-argo Bespoke c2 · alerting DSΣPDDCS [LLM] Atomic Arch: outbound HTTP upload to temp.sh from developer/build host Bespoke actions · alerting DSΣPDDCS [LLM] Atomic Arch: non-Tor-aware process connecting to local SOCKS proxy on 9050/9150 Bespoke c2 · hunting DSΣPDDCS [LLM] Atomic Arch — DNS resolution and HTTP POST to temp.sh from non-browser developer workstation process Bespoke c2 · alerting DSΣPDDCS [LLM] Atomic Arch — Tor client spawn or .onion endpoint contact from AUR-installing developer host Bespoke c2 · alerting DSΣPDDCS [LLM] Agentjacking C2/exfiltration to advisory-tracker.com (Tenet Sentry-MCP attack) Bespoke actions · alerting DSΣPDDCS [LLM] Outbound public network from LangGraph runtime to non-allowlisted destination Bespoke c2 · hunting DSΣPDDCS [LLM] Sniper Dz seized phishing infrastructure callback (post-takedown beacons) Bespoke c2 · alerting DSΣPDDCS [LLM] Shell or recon binary spawned by Tomcat/Java on Ivanti Sentry (CVE-2026-10520 post-exploitation) Bespoke exploit · alerting DSΣPDDCS [LLM] DNS/network contact with AudiA6 money-mule registration domains Bespoke c2 · alerting DSΣPDDCS [LLM] MeshCentral agent disguised as Microsoft Azure binary calling azurenetfiles.net Bespoke c2 · alerting DSΣPDDCS [LLM] Outbound connection or DNS resolution to imperva_artifactory.com (OpenClaw PoC C2) Bespoke c2 · alerting DSΣPDDCS [LLM] npm/node install-time process beaconing to webhook.site, sfrclak.com or 142.11.206.73 Bespoke c2 · alerting DSΣPDDCS [LLM] Miasma worm GitHub commit-search C2 magic strings on command line or script Bespoke c2 · alerting DSΣPDDCS [LLM] Outbound JSON-RPC or LLM-API egress from network appliance / edge device Bespoke c2 · alerting DSΣPDD [LLM] SPECTRALVIPER C2 callout to OceanLotus FireAnt infrastructure Bespoke c2 · hunting DSΣPDDCS [LLM] Network egress to OceanLotus SPECTRALVIPER C2 IPs (2024-2026 campaigns) Bespoke c2 · hunting DSΣPDDCS [LLM] Sustained low-volume beaconing to OceanLotus SPECTRALVIPER C2 (long-tail persistence) Bespoke c2 · hunting DSPDDCS [LLM] build.rs invoking curl POST to Sentry envelope endpoint with code diff payload Bespoke actions · alerting DSΣPDDCS [LLM] Network egress to onering Sentry exfil ingest domain or project envelope path Bespoke c2 · alerting DSΣPDDCS [LLM] Connection to RoguePlanet PoC C2 Domain projectnightcrawler.dev Bespoke c2 · alerting DSΣPDDCS [LLM] Unauthenticated WebSocket / HTTP 101 upgrade to phoenix_storybook playground routes Bespoke delivery · hunting DSΣPDDCS [LLM] BEAM process outbound to new public destination or non-standard port (post-RCE C2) Bespoke c2 · hunting DSPDDCS [LLM] Outbound DNS / HTTP to Miasma C2 (git-service.com / m-kosche.com) Bespoke c2 · alerting DSΣPDDCS [LLM] Miasma C2 / IOC domain resolution: check.git-service.com, t.m-kosche.com, git-service.com Bespoke c2 · alerting DSΣPDDCS [LLM] GIFTEDCROOK / Gamaredon C2 callback to article IOCs (IPs + workers.dev / trycloudflare / .ru domains) Bespoke c2 · hunting DSΣPDDCS [LLM] Hades C2: GitHub commit search for campaign markers TheBeautifulSnadsOfTime / firedalazer Bespoke c2 · alerting DSΣPDDCS [LLM] Internal host outbound to CVE-2026-50751 Qilin actor IPs (post-bypass C2 / staging) Bespoke c2 · alerting DSΣPDDCSCW [LLM] Connection to AI-brand phishing / installer C2 infrastructure (MSTI June 2026 IOCs) Bespoke c2 · alerting DSΣPDDCS [LLM] Outbound endpoint connections to BRICKSTORM C2 IP 149.248.11.71 Bespoke c2 · hunting DSΣPDDCSCW [LLM] Outbound connection to UNC3753 (Luna Moth) infrastructure IPs Bespoke c2 · hunting DSΣPDDCSCW [LLM] Bright Data SDK control-plane beacon to proxyjs/clientsdk endpoints Bespoke c2 · alerting DSΣPDDCS [LLM] ait-bsc outbound TCP to public/non-baseline destination (attacker-supplied loc port) Bespoke c2 · alerting DSPDDCS [LLM] GitHub Actions runner: node from Claude Code Action egresses to non-Anthropic/non-GitHub endpoint Bespoke c2 · hunting DSPDDCS [LLM] Mini Shai-Hulud npm worm exfiltration to t.m-kosche.com OpenTelemetry endpoint Bespoke actions · alerting DSΣPDDCS [LLM] KongTuke TDS C2 callout to 144.31.221.82:6060 with /capcha URL path Bespoke c2 · alerting DSΣPDDCS [LLM] Same host calling KongTuke C2 from both powershell.exe and curl.exe within short window Bespoke c2 · alerting DSPDDCS [LLM] Argamal Stage2 BITSAdmin Pull of zaesdl.dat from GitHub Bespoke c2 · alerting DSΣPDDCS [LLM] Argamal RAT C2 Beacon — 186.158.223.35 / freeddns / kozow / ignorelist / UDP-57441 / TCP-3747 Bespoke c2 · alerting DSΣPDDCS [LLM] Package manager runtime connecting to durabletask/axios supply-chain C2 IOCs Bespoke c2 · alerting DSΣPDDCS [LLM] C2 beacon to audit.checkmarx[.]cx /v1/telemetry (TeamPCP Shai-Hulud Third Coming) Bespoke c2 · alerting DSΣPDDCS [LLM] Egress to typosquatted C2 flipboxstudio.info (Laravel-Lang Composer SC) Bespoke c2 · alerting DSΣPDDCS [LLM] FlutterShell macOS C2 contact (atsheisdomestic / etoftheappyrince / healightejustb) Bespoke c2 · alerting DSΣPCS [LLM] FlutterShell adware redirector contact (ads-parkpro / sinterfumesco / softwe.art) Bespoke actions · alerting DSΣPCS [LLM] TeamPCP Checkmarx KICS supply-chain stealer C2 callback (audit.checkmarx.cx / 94.154.172.43) Bespoke c2 · hunting DSΣPDDCS [LLM] C2 callback to moika.tech payload distribution infrastructure Bespoke c2 · alerting DSΣPDDCS [LLM] Container egress to cryptominer pool / Kinsing C2 Bespoke c2 · alerting DSΣPDDCS [LLM] Outbound HTTP beacon to vpmdhaj C2 (aab.sportsontheweb.net) Bespoke c2 · alerting DSΣPDDCS [LLM] Cyberhaven trojanized Chrome extension C2 callback to cyberhavenext.pro Bespoke c2 · alerting DSΣPDDCS [LLM] NoName057(16) DDoSia client check-in (/client/login, /client/get_targets) Bespoke c2 · alerting DSΣPCS [LLM] axios RAT C2 callout to sfrclak.com / 142.11.206.73:8000 Bespoke c2 · alerting DSΣPDDCS [LLM] Yamcs Java process beacons to webhook / interact / tunneling service (CVE-2026-46621 C2) Bespoke c2 · alerting DSΣPDDCS [LLM] Reverse-shell /dev/tcp file descriptor from Yamcs java process tree Bespoke c2 · alerting DSΣPDDCS [LLM] DNS/HTTPS exfil to sentry.anyclaw.store (Codex token C2 masquerading as Sentry) Bespoke c2 · alerting DSΣPDDCS [LLM] HTTPS POST to /startlog with codexui User-Agent (Codex exfil over the wire) Bespoke actions · alerting DSΣPDDCS [LLM] Outbound recon callback from Yamcs host (curl/shell child of JVM to public IP) Bespoke c2 · alerting DSPCS [LLM] Mini Shai-Hulud npm worm C2/exfil egress (masscan.cloud, git-tanstack.com, getsession.org) Bespoke actions · alerting DSΣPDDCS [LLM] BTMOB C2/phishing domain contact — arbsniper.com Bespoke c2 · alerting DSΣPDDCS [LLM] Egress to BTMOB hosted C2 cluster (LATAM/Hetzner IPs, Google CDN excluded) Bespoke c2 · hunting DSPDDCS [LLM] Laravel-Lang supply chain C2/exfil to flipboxstudio.info Bespoke c2 · alerting DSΣPDDCS [LLM] C2 egress to flipboxstudio.info from Laravel-Lang composer dropper Bespoke c2 · alerting DSΣPDDCS [LLM] nezha-agent outbound network connection to cloud instance-metadata service Bespoke actions · alerting DSΣPDDCS [LLM] Megalodon CI/CD exfil: outbound HTTPS to C2 216.126.225.129:8443 Bespoke c2 · hunting DSΣPDDCS [LLM] Screening Serpens C2 — DNS/network to UNC1549 infrastructure (Feb-Apr 2026) Bespoke c2 · alerting DSΣPDDCS [LLM] Endpoint DNS or web traffic to fake FIFA World Cup 2026 typosquat domain Bespoke delivery · alerting DSΣPDDCS [LLM] Nx Console / Shai-Hulud C2 connection (t.m-kosche.com, check.git-service.com, filev2.getsession.org, api.masscan.cloud, 83.142.209.194) Bespoke c2 · alerting DSΣPDDCS [LLM] Mini Shai-Hulud C2 callback to zero.masscan.cloud / 94.154.172.43 Bespoke c2 · alerting DSΣPDDCS [LLM] TamperedChef C2 / distribution callback to appsuites.ai and sibling domains Bespoke c2 · alerting DSΣPDDCS [LLM] DNS / Network egress to TeamPCP Nx Console C2 domain check.git-service.com Bespoke c2 · alerting DSΣPDDCS [LLM] EchoCreep Discord API beacon from non-browser process (Webworm 2025) Bespoke c2 · hunting DSΣPDDCS [LLM] GraphWorm OneDrive /createUploadSession C2 from non-Office process Bespoke c2 · hunting DSΣPDDCS [LLM] WormFrp / Webworm Amazon S3 staging bucket access (wamanharipethe / whpjewellers) Bespoke actions · alerting DSΣPDDCS [LLM] Webworm 2025 IOC match — known C2 IPs (Vultr/IT7) and file hashes Bespoke c2 · hunting DSΣPDDCS [LLM] TeamPCP rope.pyz Dropper Fetch from check.git-service.com C2 Bespoke c2 · hunting DSΣPDDCS [LLM] Reverse shell from 9router-spawned shell — outbound TCP from node-child bash Bespoke c2 · hunting DSPDDCS [LLM] DNS lookup for git-tanstack.com TeamPCP C2 staging domain Bespoke c2 · alerting DSΣPDDCS [LLM] Outbound connection to TeamPCP C2 IP 83.142.209.194 Bespoke c2 · hunting DSΣPDDCS [LLM] GlassFish java process outbound HTTP fetch to external host (gadget XML callback) Bespoke exploit · hunting DSPDDCS [LLM] Mini Shai-Hulud / TeamPCP C2 beacon to api.masscan.cloud / git-tanstack.com / *.getsession.org Bespoke c2 · alerting DSPDDCS [LLM] BadIIS C2 IP / domain beacon (lee.6686ty.vip, iis.01nmwe.xyz) Bespoke c2 · hunting DSΣPDDCS [LLM] IIS worker (w3wp.exe) initiating outbound connection to public IP Bespoke c2 · hunting DSPDDCS [LLM] Mini Shai-Hulud C2 exfil to t.m-kosche.com disguised as OpenTelemetry collector Bespoke c2 · alerting DSΣPDDCS [LLM] Outbound C2 to t.m-kosche.com from CI/CD runner or any endpoint Bespoke c2 · alerting DSΣPDDCS [LLM] node-ipc C2 callback to sh.azurestaticprovider.net (May 2026 npm supply-chain) Bespoke c2 · alerting DSΣPDDCS [LLM] Mini Shai-Hulud C2 backchannel: python polling GitHub commit search for 'firedalazer' Bespoke c2 · alerting DSPDDCS [LLM] Outbound network connection to mistralai 2.4.6 dropper C2 (83.142.209.194) Bespoke c2 · alerting DSΣPDDCS [LLM] Arcane backend host outbound Git/HTTPS to non-allowlisted host on port 22/443 (CVE-2026-45625 credential sink) Bespoke c2 · hunting DSPDDCS [LLM] Cisco Secure FMC anomalous outbound HTTP PUT (Interlock CVE-2026-20131 callback) Bespoke c2 · hunting SP [LLM] Outbound connection to Gremlin Stealer exfiltration host 194.87.92.109 Bespoke actions · hunting DSΣPDDCS [LLM] Outbound egress to node-ipc stealer infrastructure (azurestaticprovider[.]net / 37.16.75.69) Bespoke actions · alerting DSΣPDDCS [LLM] AdaptixC2 'shadowcore' / Mythic C2 traffic to UAT-8616 infrastructure 194.163.175.135 Bespoke c2 · hunting DSΣPDDCS [LLM] AdaptixC2 'systemd-resolved' or Sliver 'CWan' implant on Linux / SD-WAN host Bespoke install · hunting DSΣPDDCS [LLM] FrostyNeighbor C2 callout to needbinding/nebao/algsat/sardk/alexavegas/lavanille Bespoke c2 · alerting DSΣPDDCS [LLM] Mini Shai-Hulud npm Worm C2 callback to Session Protocol CDN and masscan.cloud Bespoke c2 · alerting DSΣPDDCS [LLM] Mini Shai-Hulud dead-drop git commit authored as claude@users.noreply.github.com Bespoke actions · alerting DSΣPDDCS [LLM] Malformed CL-STA-1132 attacker User-Agent (Mozilla/5.5 + Safari/532.31) Bespoke exploit · alerting DSΣPDD [LLM] ScarCruft sqgame supply-chain delivery domain contact (BirdCall/RokRAT) Bespoke delivery · alerting DSΣPDDCS [LLM] Outbound to elementary-data exfil C2 igotnofriendsonlineorirl-imgonnakmslmao.sky Bespoke c2 · alerting DSΣPDDCS [LLM] TeamPCP @bitwarden/cli stealer exfil to audit.checkmarx.cx (94.154.172.43) Bespoke c2 · hunting DSΣPDDCS [LLM] Mini Shai-Hulud 'OhNoWhatsGoingOnWithGitHub' dead-drop keyword in outbound URL Bespoke c2 · alerting DSΣPDD [LLM] Exfil to skyhanni.cloud C2 with X-Rise-To-The-Trinny header Bespoke c2 · alerting DSΣPDDCS [LLM] Qinglong cryptominer payload download from file.551911.xyz Bespoke delivery · alerting DSΣPDDCS [LLM] Cyberhaven compromised Chrome extension C2 callback (cyberhavenext.pro) Bespoke c2 · hunting DSΣPDDCS [LLM] Non-browser process posting to Slack Web API (LaxGopher C2) Bespoke c2 · hunting DSPDDCS [LLM] Non-browser process posting to Discord API (RatGopher C2) Bespoke c2 · hunting DSPDDCS [LLM] Beaconing to GopherWhisper C2 IP 43.231.113.50 (incl. SSLORDoor raw TLS/443) Bespoke c2 · alerting DSΣPDDCS [LLM] Suspicious draft email manipulation against barrantaya.1010@outlook.com (BoxOfFriends Graph API C2) Bespoke c2 · hunting DSPDDCS [LLM] GPT-Proxy backdoor C2 / Stage-2 download (sync.geeker.indevs.in, gibunxi4201/kube-node-diag) Bespoke c2 · alerting DSΣPDD [LLM] Trust Wallet Shai-Hulud C2 callback to metrics-trustwallet.com / 138.124.70.40 Bespoke c2 · alerting DSΣPDDCS [LLM] Outbound connection to Velora DEX npm supply-chain C2 89.36.224.5 Bespoke c2 · alerting DSΣPDDCS [LLM] TeamPCP Trivy/KICS C2 callback to scan.aquasecurtiy.org / 45.148.10.212 Bespoke c2 · hunting DSΣPDD [LLM] axios Supply Chain RAT C2 Callback to sfrclak.com (Port 8000) Bespoke c2 · alerting DSΣPDDCS [LLM] hackerbot-claw payload host: DNS/HTTP egress to hackmoltrepeat.com (C2 + exfil) Bespoke c2 · alerting DSΣPDDCS [LLM] hackerbot-claw token exfiltration: curl POST with GITHUB_TOKEN to recv.hackmoltrepeat.com Bespoke actions · alerting DSΣPDDCS [LLM] OpenClaw Gateway WebSocket listener / loopback connection on TCP 18789 Bespoke c2 · hunting DSΣPDDCS [LLM] IoliteLabs IOC sweep: rraghh.com / oortt.com hostnames + campaign file hashes Bespoke c2 · hunting DSΣPDD [LLM] Outbound connection to TeamPCP C2 83.142.209.203 / ringtone.wav stego payload fetch Bespoke c2 · alerting DSΣPDDCS [LLM] WAV-disguised stager pull from TeamPCP loader 83.142.209.203:8080 Bespoke delivery · hunting DSΣPDDCS [LLM] TeamPCP C2 / exfil egress to models.litellm.cloud, checkmarx.zone and AS205759 nodes Bespoke c2 · hunting DSΣPDDCS [LLM] Outbound C2 to sfrclak.com / 142.11.206.73:8000 (Axios npm RAT beacon) Bespoke c2 · alerting DSΣPDDCS [LLM] axios npm RAT C2 beacon to sfrclak.com / 142.11.206.73:8000 Bespoke c2 · hunting DSΣPDD [LLM] Outbound DNS/HTTPS to TeamPCP exfil domain models.litellm.cloud (litellm PyPI compromise) Bespoke c2 · alerting DSΣPDDCS [LLM] TeamPCP C2 egress to 83.142.209.203:8080 (telnyx WAV-stego dropper) Bespoke c2 · hunting DSΣPDDCS [LLM] TeamPCP supply-chain C2 — outbound to checkmarx[.]zone / 83.142.209.11 Bespoke c2 · hunting DSΣPDD [LLM] Trivy supply-chain C2 beacon to typosquat domain scan.aquasecurtiy.org Bespoke c2 · alerting DSΣPDD [LLM] bittensor-wallet 4.0.2 backdoor C2 domain contact (opentensor-* lookalikes) Bespoke c2 · alerting DSΣPDD [LLM] node.exe contacting Solana JSON-RPC endpoints (suspected blockchain dead-drop C2) Bespoke c2 · hunting DSPDDCS [LLM] C2 beaconing to Vercel-hosted Cloudflare-impersonating domains (cloudflareguard / cloudflareinsights) Bespoke c2 · alerting DSΣPDD [LLM] ForceMemo: Python process queries Solana mainnet RPC endpoint (blockchain dead-drop C2) Bespoke c2 · alerting DSΣPDD [LLM] Outbound C2 callback to xygeni-action backdoor IP 91.214.78.178 from CI runner Bespoke c2 · hunting DSΣPDDCS [LLM] Bash-spawned curl to xygeni-action C2 nip.io endpoint with /b/in /b/q /b/r path on CI runner Bespoke c2 · alerting DSΣPDDCS [LLM] DNS / HTTPS egress to TeamPCP exfil infra (models.litellm.cloud, checkmarx.zone) Bespoke c2 · hunting DSΣPDDCS [LLM] DNS/HTTP egress to CanisterWorm ICP canister C2 (tdtqy-oyaaa-aaaae-af2dq-cai) Bespoke c2 · alerting DSΣPDDCS [LLM] GlassWorm hardcoded C2 IP egress (45.32.150.251 / 217.69.3.152) for Stage-2 fetch and exfil Bespoke c2 · hunting DSΣPDDCS [LLM] GlassWorm Solana blockchain dead-drop C2 lookup via public RPC endpoints from Node Bespoke c2 · hunting DSΣPDDCS [LLM] Outbound TCP beacon to BlokTrooper Socket.IO C2 195.201.104.53:6931/6936/6939 Bespoke c2 · alerting DSΣPDDCS [LLM] Glassworm stage-2/stage-3 C2 callback to 45.32.150.251 or 217.69.3.152 Bespoke c2 · hunting DSΣPDD [LLM] DRILLAPP C2 staging: msedge.exe contacting pastefy.app Bespoke c2 · alerting DSΣPDDCS [LLM] DRILLAPP C2: msedge.exe egress to known DRILLAPP IPs or WebSocket to localhost:8000 Bespoke c2 · hunting DSΣPDDCS [LLM] BeardShell C2: outbound to Icedrive cloud-storage API as non-browser process Bespoke c2 · alerting DSΣPDDCS [LLM] Covenant C2: outbound to Filen cloud-storage API as non-browser process Bespoke c2 · alerting DSΣPDDCS [LLM] PlugX C2 egress — connections to decoraat.net / decoorat.net / gesecole.net Bespoke c2 · alerting DSΣPDDCS [LLM] Astro SSRF (CVE-2026-25545) — Node.js egress fetch for /404.html or /500.html with UA 'node' Bespoke exploit · alerting DSΣPDD [LLM] PromptSpy VNC C2 egress to 54.67.2.84 Bespoke c2 · hunting DSΣPDDCS [LLM] Outbound traffic to *.oastify.com (BurpSuite Collaborator) from corporate endpoint Bespoke exfiltration · alerting DSΣPDDCS [LLM] Egress to sidoraress json-bigint-extend gambling backdoor C2 infrastructure Bespoke c2 · alerting DSΣPDD [LLM] Inbound HTTP request bearing sidoraress backdoor x-operation operator tokens Bespoke c2 · alerting SΣPDD [LLM] CI runner anomalous outbound to raw.githubusercontent.com / gist.githubusercontent.com Bespoke c2 · alerting DSPDDCS [LLM] Egress to Qix npm phishing/exfil infrastructure (npmjs.help, publicvm.com, BunnyCDN buckets) Bespoke c2 · hunting DSΣPDDCS [LLM] Scavenger npm malware C2 beacon to firebase.su / dieorsuffer.com / smartscreen-api.com Bespoke c2 · alerting DSΣPDD [LLM] Endpoint contact with attacker C2 setup-service.com (OpenClaw skill stager) Bespoke c2 · alerting DSΣPDDCS [LLM] AI agent skill leaks Stripe key or card PAN/CVC verbatim in curl command line Bespoke actions · alerting DSΣPDDCS [LLM] Outbound connection to clawhub.ai or skills.sh from CLI agent (skill marketplace fetch) Bespoke delivery · hunting DSΣPDDCS [LLM] Sandworm SOCKS5 C2 egress to 31.172.71[.]5 (Fornex) or progamevl.ru Bespoke c2 · hunting DSΣPDDCS [LLM] GhostChat C2/staging infrastructure contact (hitpak.org, buildthenations.info, fkclb.com) Bespoke c2 · alerting DSΣPDDCS [LLM] GhostChat C2 beacon URL pattern: hitpak.org/page.php?tynor=<host>sss<user> Bespoke exfil · alerting DSΣPDDCS [LLM] ScreenConnect client beaconing to ClawdBot attacker relay (meeting.bulletmailer.net:8041) Bespoke c2 · hunting DSΣPDDCS [LLM] G_Wagon C2 beacon: node.exe or python.exe egress to Appwrite storage buckets Bespoke c2 · alerting DSΣPDDCS [LLM] Aikido npm phishing: direct outbound connection to RackGenius C2 (163.123.236.118) Bespoke c2 · hunting DSΣPDDCS [LLM] C2 beacon or stage-2 fetch to updatenet[.]work / 172.86.73.139 / dothebest[.]store Bespoke c2 · hunting DSΣPDDCS [LLM] Bun/Node bursty PUT to api.github.com /contents from infected host (Sha1-Hulud exfil) Bespoke actions · alerting DSPDDCS [LLM] MuddyViper C2 fingerprint: 'A WinHTTP Example Program/1.0' UA + distinctive URI paths Bespoke c2 · alerting DSΣPDDCS [LLM] Outbound exfiltration to webhook.site from npm / node / bun process tree Bespoke c2 · alerting DSΣPDDCS [LLM] Outbound exfiltration to Shai-Hulud webhook.site/bb8ca5f6 C2 endpoint Bespoke c2 · alerting DSΣPDD [LLM] PlushDaemon EdgeStepper hijacking infrastructure (wcsset.com / 47.242.198.250 / 8.212.132.120) contact Bespoke c2 · hunting DSΣP [LLM] LittleDaemon / DaemonicLogistics update-hijack URL pattern (popup_4.2.0.2246.dll, /update/updateInfo.bzp, /update/file6.bdat, /update/file2. Bespoke delivery · alerting DSΣP [LLM] TEA Protocol (tea.xyz) DNS resolution from developer or build endpoint Bespoke c2 · hunting DSΣPDDCS [LLM] ScoringMathTea C2 beacon to compromised WordPress hosts (Lazarus DreamJob IOCs) Bespoke c2 · hunting DSΣPDDCS [LLM] Connection to Beamglea phishing credential-harvesting domains Bespoke actions · alerting DSΣPDDCS [LLM] DNS or HTTP egress to giftshop.club exfil domain Bespoke c2 · alerting DSΣPDDCS [LLM] GhostAction C2 egress to Plesk-hosted exfiltration infrastructure Bespoke c2 · hunting DSΣPDDCS [LLM] Shai-Hulud worm C2 exfiltration to webhook.site UUID bb8ca5f6 Bespoke c2 · alerting DSΣPDDCS [LLM] Egress to websocket-api2.publicvm.com (Qix campaign credential exfil C2) Bespoke c2 · alerting DSΣPDDCS [LLM] Node process creating GitHub repo via api.github.com (s1ngularity exfil channel) Bespoke actions · hunting DSPDDCS [LLM] Scavenger C2 callback: ifyouseethisyouareultragay[.]com / pokerainteasy[.]su Bespoke c2 · alerting DSΣPDD [LLM] Scavenger Stealer C2 beacon to corroborated infrastructure (datahog.su / datalytica.su / smartscreen-api.com) Bespoke c2 · alerting DSΣPDDCS [LLM] Egress to Solidity Language Cursor extension C2 infrastructure (angelic.su / lmfao.su / staketree.net / ab498.pythonanywhere.com / 144.172.1 Bespoke c2 · hunting DSΣPDDCS [LLM] BoltDB Go backdoor C2 callback to 49.12.198.231:20022 Bespoke c2 · hunting DSΣPDDCS [LLM] Outbound fetch of file.sh via attacker-controlled commit d8daa0b... on raw.githubusercontent.com Bespoke c2 · alerting DSΣPDDCS [LLM] Polyfill malware C2: contact with googie-anaiytics homograph or kuurza redirect Bespoke c2 · alerting DSΣPDDCS [LLM] Moq SponsorLink email exfil egress to cdn.devlooped.com / SponsorLink blob Bespoke c2 · hunting DSΣPDDCS

Articles citing this technique (197)