Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Command and Control/ T1071.001

T1071.001Web Protocols

T1071.001 — Web Protocols is a MITRE ATT&CK technique in the Command and Control tactic. Clankerusecase tracks 250 detection use cases covering it and 244 threat-intel articles citing it.

Command and Control
View on the matrix → Filter Detection Library MITRE official spec ↗
250Use cases
244Articles
0Sub-techniques
1Tactic

Use cases covering this technique (250)

Beaconing — periodic outbound to small set of destinations Internal c2 · alerting DSP [WEEKLY] Brand-Impersonation Domain Fetch Followed by User-Context Loader Within 10 Minutes Internal delivery · alerting DSPDD [WEEKLY] Developer/AI tooling runtime spawns shell or egress LOLBin (unauth RCE post-expl) Internal exploit · alerting DSPDDCS [WEEKLY] Developer package install spawning script-host with non-registry C2 within 5 minutes Internal install · alerting DSPDD [WEEKLY] Install-Time npm/Bun Lifecycle Execution Beaconing Out Within Minutes Internal install · alerting DSΣPDDCS [WEEKLY] Internet-facing server process spawns interpreter then beacons to first-seen external host within 5 minutes Internal install · alerting DSPDD [WEEKLY] Internet-facing service process spawns shell/LOLBin within minutes of public inbound connection — post-RCE command execution Internal exploit · alerting DSΣPDD [WEEKLY] Non-Browser Process Reads Browser Credential / Cookie SQLite Then Egresses to Public Destination Within 10 Minutes Internal actions · alerting DSPDD [WEEKLY] npm Install-Time Lifecycle Hook Triggers Outbound Egress to Newly-Seen Domain (Shai-Hulud/Miasma/IronWorm pattern) Internal install · alerting DSPDD [WEEKLY] npm/node-gyp Install-Hook Spawn Chained to Outbound Egress Internal install · alerting DSΣPDDCS [WEEKLY] Package Manager / Dev-Tool Auto-Execution Triggers Non-Registry Egress or Credential-Store Access Internal install · alerting DSPDD [WEEKLY] Package-manager install hook spawns interpreter that beacons to non-registry host within 120s Internal install · alerting DSPDD [WEEKLY] Package Manager Install Hook Spawns Scripting Interpreter Then Touches Credential Files or Egresses Off-Registry Internal install · alerting DSPDD [WEEKLY] Package Manager Install Spawning Outbound Egress to Non-Registry Infrastructure Within 5 Minutes Internal install · alerting DSPDD [WEEKLY] Package manager lifecycle hook spawns network-fetching shell or runtime Internal install · alerting DSΣPDD [WEEKLY] Package manager lifecycle hook spawns runtime with outbound egress to non-registry host within 5 minutes Internal install · alerting DSPDD [WEEKLY] Package manager spawns network-fetching child to public code-hosting within minutes of install Internal install · alerting DSPDD [WEEKLY] Script Interpreter or Package-Install Hook Egress to Free-Tier Edge SaaS Within 5 Minutes of Process Start Internal c2 · alerting DSΣPDD [WEEKLY] Self-hosted application service spawns shell or SSH within seconds of inbound unauthenticated API write Internal exploit · alerting DSPDD [WEEKLY] Server / AI-agent process spawns shell or LOLBIN with public egress — post-RCE behavioural chain Internal exploit · alerting DSΣPDD [WEEKLY] Supply-chain repo credential theft → outbound exfil to attacker infra Internal actions · alerting DSPDD Windows ConvertTo-AADIntBackdoor Execution Via PowerShell Script ESCU actions · alerting P Windows Non-System Process Querying Definition Update ESCU actions · hunting P Cisco Secure Firewall - Blacklisted SSL Certificate Fingerprint ESCU actions · alerting P Cisco Secure Firewall - Connection to File Sharing Domain ESCU actions · hunting P Cisco Secure Firewall - High EVE Threat Confidence ESCU actions · hunting P Cisco Secure Firewall - Wget or Curl Download ESCU actions · hunting P HTTP C2 Framework User Agent ESCU actions · alerting P HTTP Malware User Agent ESCU actions · alerting P HTTP PUA User Agent ESCU actions · hunting P HTTP RMM User Agent ESCU actions · hunting P HTTP Duplicated Header ESCU actions · hunting P HTTP Possible Request Smuggling ESCU actions · alerting P HTTP Rapid POST with Mixed Status Codes ESCU actions · hunting P HTTP Request to Reserved Name on IIS Server ESCU actions · alerting P HTTP Scripting Tool User Agent ESCU actions · hunting P Detect web traffic to dynamic domain providers ESCU actions · alerting P HTTP Suspicious Tool User Agent ESCU actions · hunting P [LLM] Artifactory host egress to public internet (package-registry sandbox escape) Bespoke c2 · hunting DSΣPCS [LLM] Flying Eagle Android RAT C2 / panel infrastructure callback (confirmed IOCs) Bespoke c2 · alerting DSΣPDDCS [LLM] Flying Eagle / SQLRCE / Night Dragon control-panel exposed on monitored web server Bespoke c2 · hunting SΣP [LLM] RAT C2 egress to hardcoded joyfill IPs and /$/boot request paths Bespoke c2 · hunting DSΣPDDCS [LLM] Node.js resolving C2 via Tron + Binance Smart Chain dead-drop RPC Bespoke c2 · hunting DSPDDCS [LLM] JFrog Artifactory SSRF egress to non-registry destinations (internet escape) Bespoke c2 · hunting DSΣPCS [LLM] Anonymous access to Artifactory Terraform/Cargo/Ansible remote repositories Bespoke delivery · hunting SPDD [LLM] Tengu botnet C2 / IPFS beacon to 64.89.163.8 on TCP 9931 and 8080 Bespoke c2 · hunting DSΣPDDCS [LLM] Trojanized MeshAgent covert backdoor: SYSTEM service beaconing over WSS (Sinobi) Bespoke c2 · hunting DSΣPDDCS [LLM] Outbound C2 / reverse shell from TeamCity server process — CVE-2026-63077 Bespoke c2 · hunting DSPDDCS [LLM] NightLedger C2 beacon to realhealthshop[.]com / tjconsultingservices[.]com with hardcoded URIs Bespoke c2 · alerting DSΣPDDCS [LLM] BridgeHead WebSocket SOCKS5 tunnel to smartconnect.azurewebsites.net with hardcoded Edg/86 UA Bespoke c2 · alerting DSΣPDDCS [LLM] Mirage Kitten (UNC1549) infrastructure & payload IOC sweep Bespoke c2 · alerting DSPDDCS [LLM] Dysphoria botnet blockchain C2 resolution via ENS/SNS (.eth/.sol) domains Bespoke c2 · alerting DSΣPDDCS [LLM] Egress to Dysphoria distribution-node / relay IPs (194.87.198.x, 194.58.38.x) Bespoke c2 · hunting DSΣPDDCS [LLM] curl/wget/nc spawned by n8n/Node reaching external hosts (post-escape C2/exfil) Bespoke c2 · hunting DSPDDCS [LLM] Cruciferra C2 beacon to known IOC domains/IPs (incl. .gu.cc cluster) Bespoke c2 · hunting DSΣPDDCS [LLM] Telegram Bot API used for C2 by non-browser/non-messaging process Bespoke c2 · hunting DSΣPDDCS [LLM] TELESHIM/MIXEDKEY sideload host binary beacons to Telegram (C2 + exfil) Bespoke actions · alerting DSΣPDDCS [LLM] BINDCLOAK C2 beacon to cert.hypersnet.com / ssl.blsouqs.com Bespoke c2 · alerting DSΣPDDCS [LLM] Network connections to Cl0p CVE-2026-12569 C2 / staging infrastructure Bespoke c2 · hunting DSΣPDDCS [LLM] mrmustard stealer C2 exfil to metrics.femboy.energy Bespoke c2 · alerting DSΣPCS [LLM] Callback to Hermes operator staging/C2 infrastructure (VShell / ShadowPad / Hades) Bespoke c2 · hunting DSΣPDDCS [LLM] TAG-195 Golden Chickens C2 beacon to known staging/C2 infrastructure Bespoke c2 · hunting DSΣPDDCS [LLM] msaRAT: Headless Chrome/Edge launched with remote-debugging (CDP abuse) Bespoke c2 · hunting DSΣPDDCS [LLM] msaRAT: Headless browser initiating WebRTC STUN/TURN egress Bespoke c2 · hunting DSΣPDDCS [LLM] Network/DNS contact to Q2 2026 campaign infrastructure (pixeldrain payload + ClickUp dropper hosts) Bespoke c2 · alerting DSΣPDDCS [LLM] CL-STA-1114 (Void Blizzard) Zimbra espionage C2/exfil infrastructure contact Bespoke c2 · hunting DSΣPDDCS [LLM] Browser-initiated webmail data exfiltration to CL-STA-1114 C2 Bespoke actions · hunting DSΣPDDCS [LLM] msaRAT CDP abuse: headless Chrome/Edge with remote-debugging port spawned by non-browser parent Bespoke c2 · alerting DSΣPDDCS [LLM] msaRAT C2 network IOC: connection to 172.86.126.18 or is-01-ast.ols-img-12.workers.dev Bespoke c2 · hunting DSΣPDDCS [LLM] NodeBB server outbound ActivityPub/webfinger fetch to ephemeral tunnel or new domain Bespoke exploit · hunting DSΣPCS [LLM] Anomalous DLL-host process reaching Microsoft Graph/login.microsoftonline for calendar C2 Bespoke c2 · hunting DSΣPDDCS [LLM] SleeperGem: ruby process C2 contact to Forgejo host git.disroot.org Bespoke c2 · alerting DSΣPCS [LLM] ClickFix RunMRU entry launching rundll32 against WebDAV GUID share (ACR Stealer) Bespoke delivery · alerting DSΣPDDCS [LLM] rundll32 loading DLL from remote WebDAV @ssl GUID share with ordinal export (ACR Stealer) Bespoke install · alerting DSΣPDDCS [LLM] Endpoint traffic to ACR Stealer C2 / dead-drop domains Bespoke c2 · alerting DSΣPDDCS [LLM] Blockchain-anchored C2 fallback: non-browser process contacting polygon-rpc.com Bespoke c2 · alerting DSΣPDDCS [LLM] Connection to known UAT-11795 Starland RAT C2 / distribution domains Bespoke c2 · alerting DSΣPDDCS [LLM] HelloProxy C2-handler artifact: tesh4RPC.txt written to C:\Users\Public Bespoke c2 · alerting DSΣPDDCS [LLM] HelloNet C2 egress to 5.39.253.206 / 176.32.34.135 Bespoke c2 · hunting DSΣPDDCS [LLM] Starland RAT / WLDR C2 beaconing to UAT-11795 HWID-parameterized domains Bespoke c2 · alerting DSΣPDDCS [LLM] Starland RAT blockchain fallback C2 via Polygon eth_call (polygon-rpc.com) Bespoke c2 · hunting DSΣPDDCS [LLM] Outbound C2 to Miasma controller 85.137.53.71 on ports 8080/8081/8091 Bespoke c2 · hunting DSΣPDDCS [LLM] Build runner beacon/exfil to Velora backdoor C2 (89.36.224.5 / datahub.ink) Bespoke c2 · hunting DSΣPDDCS [LLM] CI runner egress to MiniRAT C2 89.36.224.5 (Velora SDK backdoor) Bespoke c2 · hunting DSΣPDDCS [LLM] C2 beacon to audit.checkmarx[.]cx /v1/telemetry (TeamPCP Shai-Hulud Third Coming) Bespoke c2 · alerting DSΣPDDCS [LLM] Miasma M-RED-TEAM HTTP C2 beacon to 85.137.53.71 Bespoke c2 · hunting DSΣPDDCS [LLM] axios RAT C2 beacon to sfrclak[.]com / 142.11.206.73:8000 Bespoke c2 · hunting DSΣPDDCS [LLM] IronWorm C2 beacon to hardcoded IPs and Tor endpoints from temp-dir process Bespoke c2 · hunting DSΣPDDCS [LLM] The Gentlemen SystemBC C2 beacon to known operator IPs Bespoke c2 · hunting DSΣPDDCS [LLM] Outbound network connection from a child process of SiYuan.exe (post-RCE C2/exfil) Bespoke c2 · alerting DSPCS [LLM] Exfil to lookalike Injective gRPC-web subdomain (@injectivelabs stealer C2) Bespoke c2 · alerting DSΣPDDCS [LLM] Outbound C2 to PlugX/ShadowPad/Cobalt Strike/Remcos infrastructure targeting Pakistani law enforcement Bespoke c2 · alerting DSΣPDDCS [LLM] Compromised web-application server beaconing to espionage C2 (portal-update implant) Bespoke c2 · hunting DSΣPDDCS [LLM] PromptSpy Android GenAI malware C2/distribution domain contact (mgardownload.com, m-mgarg.com) Bespoke c2 · alerting DSΣPDDCS [LLM] Outbound connection to UAT-7810 (LapDogs ORB) SHORTLEASH/DOGLEASH C2 VPS Bespoke c2 · hunting DSΣPDDCS [LLM] Neo4j server outbound egress to public IP (LOAD CSV / apoc.load SSRF) Bespoke c2 · hunting DSPDDCS [LLM] Outbound egress from shell/downloader child of a Python (Langroid) process Bespoke c2 · hunting DSPCS [LLM] TeamPCP Trivy/KICS supply-chain credential exfil to scan.aquasecurtiy.org & 45.148.10.212 Bespoke c2 · hunting DSΣPCS [LLM] HTTP request to an executable PHP file under Mautic /media (web-shell interaction) Bespoke c2 · alerting SP [LLM] ARToken/EvilTokens PhaaS infrastructure contact (pamconj.com panel + Cloudflare Worker lure) Bespoke delivery · alerting DSΣPDDCS [LLM] Dormant crypto-miner on servers: sustained stratum egress to mining pools Bespoke actions · hunting DSPDDCS [LLM] easy-day-js second-stage C2 beacon to Mastra supply-chain infrastructure Bespoke c2 · hunting DSΣPDDCS [LLM] Jackson Maven typosquat C2 — beacon to fasterxml.org / 103.127.243.82 Bespoke c2 · alerting DSΣPDDCS [LLM] JetBrains IDE process beaconing to malicious plugin C2 39.107.60.51 Bespoke c2 · alerting DSΣPDDCS [LLM] JetBrains IDE JVM plaintext HTTP POST to AI-key stealer endpoint /api/software/ Bespoke actions · hunting DSPDDCS [LLM] AI coding-assistant egress to first-seen external domain (phantom squatting) Bespoke c2 · hunting DSPDDCS [LLM] Outbound connection to CL-STA-1062 / TinyRCT C2 and tool-staging infrastructure Bespoke c2 · hunting DSΣPDDCS [LLM] Gamaredon dead-drop C&C resolution via Telegra.ph and GoFile from script hosts Bespoke c2 · alerting DSΣPDDCS [LLM] easy-day-js stealer C2 beacon to Hostwinds 23.254.164.0/24 (ports 8000/443) Bespoke c2 · hunting DSΣPDDCS [LLM] Bun process reaching GitHub commit-search API — Miasma dead-drop C2 Bespoke c2 · hunting DSΣPDDCS [LLM] Network egress to ClawHavoc cluw / AMOS C2 infrastructure Bespoke c2 · hunting DSΣPCS [LLM] macOS.Gaslight Telegram Bot API C2 polling from non-browser process Bespoke c2 · hunting DSΣPCS [LLM] Salesforce API access bearing python-requests/aiohttp automation user-agent (Icarus OAuth abuse) Bespoke actions · alerting DSP [LLM] Developer-runtime exfiltration to webhook.site (Shai-Hulud token drop) Bespoke actions · alerting DSΣPDDCS [LLM] Atomic Arch C2/exfil: build-spawned egress to temp.sh and github.com/fardewoak/nodejs-argo Bespoke c2 · alerting DSΣPDDCS [LLM] Sapphire Sleet easy-day-js RAT C2 beacon to Hostwinds 23.254.164.92 / 23.254.164.123 Bespoke c2 · hunting DSΣPDDCS [LLM] Cross-platform stealer RAT C2 beacon to 23.254.164.123 Bespoke c2 · alerting DSPDDCS [LLM] JetBrains IDE plugin AI-key exfil: endpoint egress to C2 39.107.60.51 Bespoke actions · hunting DSΣPDDCS [LLM] JetBrains AI-key stealer HTTP exfil: cleartext POST to /api/software/ path Bespoke c2 · hunting DSΣP [LLM] axios npm RAT C2 beacon to UNC1069 infra (142.11.206.73 / sfrclak.com) Bespoke c2 · alerting DSΣPDDCS [LLM] OceanLotus SPECTRALVIPER C2 communication to FireAnt-campaign domains/IPs Bespoke c2 · hunting DSΣPDDCS [LLM] SPECTRALVIPER injected OneDrive.Sync.Service.exe beaconing (Cookie-header C2) Bespoke c2 · alerting DSPDDCS [LLM] GlassWorm Stage-2 C2 beacon to Vultr-hosted command-and-control IPs Bespoke c2 · hunting DSΣPDDCS [LLM] Exfiltration to attacker-controlled Sentry ingest endpoint (onering crate) Bespoke actions · alerting DSΣPDDCS [LLM] Rust build script making outbound network connection (build-time exfil) Bespoke c2 · hunting DSΣPDDCS [LLM] Outbound DNS / HTTP to Miasma C2 (git-service.com / m-kosche.com) Bespoke c2 · alerting DSΣPDDCS [LLM] Package manager runtime connecting to durabletask/axios supply-chain C2 IOCs Bespoke c2 · alerting DSΣPDDCS [LLM] Egress to typosquatted C2 flipboxstudio.info (Laravel-Lang Composer SC) Bespoke c2 · alerting DSΣPDDCS [LLM] node child of npm install initiating outbound network to non-registry destination Bespoke c2 · hunting DSPDDCS [LLM] Cyberhaven trojanized Chrome extension C2 callback to cyberhavenext.pro Bespoke c2 · alerting DSΣPDDCS [LLM] axios RAT C2 callout to sfrclak.com / 142.11.206.73:8000 Bespoke c2 · alerting DSΣPDDCS [LLM] DNS/HTTPS exfil to sentry.anyclaw.store (Codex token C2 masquerading as Sentry) Bespoke c2 · alerting DSΣPDDCS [LLM] HTTPS POST to /startlog with codexui User-Agent (Codex exfil over the wire) Bespoke actions · alerting DSΣPDDCS [LLM] Mini Shai-Hulud npm worm C2/exfil egress (masscan.cloud, git-tanstack.com, getsession.org) Bespoke actions · alerting DSΣPDDCS [LLM] BTMOB C2/phishing domain contact — arbsniper.com Bespoke c2 · alerting DSΣPDDCS [LLM] Egress to BTMOB hosted C2 cluster (LATAM/Hetzner IPs, Google CDN excluded) Bespoke c2 · hunting DSPDDCS [LLM] Laravel-Lang supply chain C2/exfil to flipboxstudio.info Bespoke c2 · alerting DSΣPDDCS [LLM] C2 egress to flipboxstudio.info from Laravel-Lang composer dropper Bespoke c2 · alerting DSΣPDDCS [LLM] Megalodon CI/CD exfil: outbound HTTPS to C2 216.126.225.129:8443 Bespoke c2 · hunting DSΣPDDCS [LLM] Endpoint DNS or web traffic to fake FIFA World Cup 2026 typosquat domain Bespoke delivery · alerting DSΣPDDCS [LLM] Nx Console / Shai-Hulud C2 connection (t.m-kosche.com, check.git-service.com, filev2.getsession.org, api.masscan.cloud, 83.142.209.194) Bespoke c2 · alerting DSΣPDDCS [LLM] DNS / Network egress to TeamPCP Nx Console C2 domain check.git-service.com Bespoke c2 · alerting DSΣPDDCS [LLM] EchoCreep Discord API beacon from non-browser process (Webworm 2025) Bespoke c2 · hunting DSΣPDDCS [LLM] GraphWorm OneDrive /createUploadSession C2 from non-Office process Bespoke c2 · hunting DSΣPDDCS [LLM] WormFrp / Webworm Amazon S3 staging bucket access (wamanharipethe / whpjewellers) Bespoke actions · alerting DSΣPDDCS [LLM] Webworm 2025 IOC match — known C2 IPs (Vultr/IT7) and file hashes Bespoke c2 · hunting DSΣPDDCS [LLM] TeamPCP rope.pyz Dropper Fetch from check.git-service.com C2 Bespoke c2 · hunting DSΣPDDCS [LLM] C2 / payload-host resolution to check.git-service.com (durabletask worm) Bespoke c2 · alerting DSΣPCS [LLM] FIRESCALE GitHub dead-drop fallback C2 lookup (api.github.com commit search) Bespoke c2 · alerting DSΣP [LLM] Mini Shai-Hulud C2 exfil to t.m-kosche.com disguised as OpenTelemetry collector Bespoke c2 · alerting DSΣPDDCS [LLM] Outbound C2 to t.m-kosche.com from CI/CD runner or any endpoint Bespoke c2 · alerting DSΣPDDCS [LLM] node-ipc C2 callback to sh.azurestaticprovider.net (May 2026 npm supply-chain) Bespoke c2 · alerting DSΣPDDCS [LLM] Mini Shai-Hulud C2 backchannel: python polling GitHub commit search for 'firedalazer' Bespoke c2 · alerting DSPDDCS [LLM] Outbound egress to node-ipc stealer infrastructure (azurestaticprovider[.]net / 37.16.75.69) Bespoke actions · alerting DSΣPDDCS [LLM] FrostyNeighbor C2 callout to needbinding/nebao/algsat/sardk/alexavegas/lavanille Bespoke c2 · alerting DSΣPDDCS [LLM] Mini Shai-Hulud npm Worm C2 callback to Session Protocol CDN and masscan.cloud Bespoke c2 · alerting DSΣPDDCS [LLM] Mini Shai-Hulud dead-drop git commit authored as claude@users.noreply.github.com Bespoke actions · alerting DSΣPDDCS [LLM] ScarCruft sqgame supply-chain delivery domain contact (BirdCall/RokRAT) Bespoke delivery · alerting DSΣPDDCS [LLM] Outbound to elementary-data exfil C2 igotnofriendsonlineorirl-imgonnakmslmao.sky Bespoke c2 · alerting DSΣPDDCS [LLM] TeamPCP @bitwarden/cli stealer exfil to audit.checkmarx.cx (94.154.172.43) Bespoke c2 · hunting DSΣPDDCS [LLM] Mini Shai-Hulud 'OhNoWhatsGoingOnWithGitHub' dead-drop keyword in outbound URL Bespoke c2 · alerting DSΣPDD [LLM] Exfil to skyhanni.cloud C2 with X-Rise-To-The-Trinny header Bespoke c2 · alerting DSΣPDDCS [LLM] Qinglong cryptominer payload download from file.551911.xyz Bespoke delivery · alerting DSΣPDDCS [LLM] Cyberhaven compromised extension C2 beacon to cyberhavenext[.]pro Bespoke c2 · hunting DSΣPDDCS [LLM] Non-browser process posting to Slack Web API (LaxGopher C2) Bespoke c2 · hunting DSPDDCS [LLM] Non-browser process posting to Discord API (RatGopher C2) Bespoke c2 · hunting DSPDDCS [LLM] Beaconing to GopherWhisper C2 IP 43.231.113.50 (incl. SSLORDoor raw TLS/443) Bespoke c2 · alerting DSΣPDDCS [LLM] Suspicious draft email manipulation against barrantaya.1010@outlook.com (BoxOfFriends Graph API C2) Bespoke c2 · hunting DSPDDCS [LLM] GPT-Proxy backdoor C2 / Stage-2 download (sync.geeker.indevs.in, gibunxi4201/kube-node-diag) Bespoke c2 · alerting DSΣPDD [LLM] Trust Wallet Shai-Hulud C2 callback to metrics-trustwallet.com / 138.124.70.40 Bespoke c2 · alerting DSΣPDDCS [LLM] Outbound connection to Velora DEX npm supply-chain C2 89.36.224.5 Bespoke c2 · alerting DSΣPDDCS [LLM] TeamPCP Trivy/KICS C2 callback to scan.aquasecurtiy.org / 45.148.10.212 Bespoke c2 · hunting DSΣPDD [LLM] axios Supply Chain RAT C2 Callback to sfrclak.com (Port 8000) Bespoke c2 · alerting DSΣPDDCS [LLM] hackerbot-claw payload host: DNS/HTTP egress to hackmoltrepeat.com (C2 + exfil) Bespoke c2 · alerting DSΣPDDCS [LLM] hackerbot-claw token exfiltration: curl POST with GITHUB_TOKEN to recv.hackmoltrepeat.com Bespoke actions · alerting DSΣPDDCS [LLM] OpenClaw Gateway WebSocket listener / loopback connection on TCP 18789 Bespoke c2 · hunting DSΣPDDCS [LLM] IoliteLabs IOC sweep: rraghh.com / oortt.com hostnames + campaign file hashes Bespoke c2 · hunting DSΣPDD [LLM] Outbound connection to TeamPCP C2 83.142.209.203 / ringtone.wav stego payload fetch Bespoke c2 · alerting DSΣPDDCS [LLM] WAV-disguised stager pull from TeamPCP loader 83.142.209.203:8080 Bespoke delivery · hunting DSΣPDDCS [LLM] TeamPCP C2 / exfil egress to models.litellm.cloud, checkmarx.zone and AS205759 nodes Bespoke c2 · hunting DSΣPDDCS [LLM] Outbound C2 to sfrclak.com / 142.11.206.73:8000 (Axios npm RAT beacon) Bespoke c2 · alerting DSΣPDDCS [LLM] axios npm RAT C2 beacon to sfrclak.com / 142.11.206.73:8000 Bespoke c2 · hunting DSΣPDD [LLM] Outbound DNS/HTTPS to TeamPCP exfil domain models.litellm.cloud (litellm PyPI compromise) Bespoke c2 · alerting DSΣPDDCS [LLM] TeamPCP C2 egress to 83.142.209.203:8080 (telnyx WAV-stego dropper) Bespoke c2 · hunting DSΣPDDCS [LLM] TeamPCP supply-chain C2 — outbound to checkmarx[.]zone / 83.142.209.11 Bespoke c2 · hunting DSΣPDD [LLM] Trivy supply-chain C2 beacon to typosquat domain scan.aquasecurtiy.org Bespoke c2 · alerting DSΣPDD [LLM] bittensor-wallet 4.0.2 backdoor C2 domain contact (opentensor-* lookalikes) Bespoke c2 · alerting DSΣPDD [LLM] node.exe contacting Solana JSON-RPC endpoints (suspected blockchain dead-drop C2) Bespoke c2 · hunting DSPDDCS [LLM] C2 beaconing to Vercel-hosted Cloudflare-impersonating domains (cloudflareguard / cloudflareinsights) Bespoke c2 · alerting DSΣPDD [LLM] ForceMemo: Python process queries Solana mainnet RPC endpoint (blockchain dead-drop C2) Bespoke c2 · alerting DSΣPDD [LLM] Outbound C2 callback to xygeni-action backdoor IP 91.214.78.178 from CI runner Bespoke c2 · hunting DSΣPDDCS [LLM] Bash-spawned curl to xygeni-action C2 nip.io endpoint with /b/in /b/q /b/r path on CI runner Bespoke c2 · alerting DSΣPDDCS [LLM] DNS / HTTPS egress to TeamPCP exfil infra (models.litellm.cloud, checkmarx.zone) Bespoke c2 · hunting DSΣPDDCS [LLM] DNS/HTTP egress to CanisterWorm ICP canister C2 (tdtqy-oyaaa-aaaae-af2dq-cai) Bespoke c2 · alerting DSΣPDDCS [LLM] GlassWorm hardcoded C2 IP egress (45.32.150.251 / 217.69.3.152) for Stage-2 fetch and exfil Bespoke c2 · hunting DSΣPDDCS [LLM] GlassWorm Solana blockchain dead-drop C2 lookup via public RPC endpoints from Node Bespoke c2 · hunting DSΣPDDCS [LLM] Outbound TCP beacon to BlokTrooper Socket.IO C2 195.201.104.53:6931/6936/6939 Bespoke c2 · alerting DSΣPDDCS [LLM] Glassworm stage-2/stage-3 C2 callback to 45.32.150.251 or 217.69.3.152 Bespoke c2 · hunting DSΣPDD [LLM] DRILLAPP C2 staging: msedge.exe contacting pastefy.app Bespoke c2 · alerting DSΣPDDCS [LLM] DRILLAPP C2: msedge.exe egress to known DRILLAPP IPs or WebSocket to localhost:8000 Bespoke c2 · hunting DSΣPDDCS [LLM] BeardShell C2: outbound to Icedrive cloud-storage API as non-browser process Bespoke c2 · alerting DSΣPDDCS [LLM] Covenant C2: outbound to Filen cloud-storage API as non-browser process Bespoke c2 · alerting DSΣPDDCS [LLM] PlugX C2 egress — connections to decoraat.net / decoorat.net / gesecole.net Bespoke c2 · alerting DSΣPDDCS [LLM] Outbound traffic to *.oastify.com (BurpSuite Collaborator) from corporate endpoint Bespoke exfiltration · alerting DSΣPDDCS [LLM] Egress to Qix npm phishing/exfil infrastructure (npmjs.help, publicvm.com, BunnyCDN buckets) Bespoke c2 · hunting DSΣPDDCS [LLM] Ultralytics coinminer C2 — Stratum to connect.consrensys.com:8080 mining pool Bespoke c2 · alerting DSΣPCS [LLM] Scavenger npm malware C2 beacon to firebase.su / dieorsuffer.com / smartscreen-api.com Bespoke c2 · alerting DSΣPDD [LLM] Endpoint contact with attacker C2 setup-service.com (OpenClaw skill stager) Bespoke c2 · alerting DSΣPDDCS [LLM] AI agent skill leaks Stripe key or card PAN/CVC verbatim in curl command line Bespoke actions · alerting DSΣPDDCS [LLM] Dev endpoint contacts ClawHub / skills.sh agent-skill marketplace Bespoke delivery · hunting DSΣPDDCS [LLM] Sandworm SOCKS5 C2 egress to 31.172.71[.]5 (Fornex) or progamevl.ru Bespoke c2 · hunting DSΣPDDCS [LLM] GhostChat C2/staging infrastructure contact (hitpak.org, buildthenations.info, fkclb.com) Bespoke c2 · alerting DSΣPDDCS [LLM] GhostChat C2 beacon URL pattern: hitpak.org/page.php?tynor=<host>sss<user> Bespoke exfil · alerting DSΣPDDCS [LLM] MuddyViper C2 fingerprint: 'A WinHTTP Example Program/1.0' UA + distinctive URI paths Bespoke c2 · alerting DSΣPDDCS [LLM] Outbound exfiltration to webhook.site from npm / node / bun process tree Bespoke c2 · alerting DSΣPDDCS [LLM] PlushDaemon EdgeStepper hijacking infrastructure (wcsset.com / 47.242.198.250 / 8.212.132.120) contact Bespoke c2 · hunting DSΣP [LLM] LittleDaemon / DaemonicLogistics update-hijack URL pattern (popup_4.2.0.2246.dll, /update/updateInfo.bzp, /update/file6.bdat, /update/file2. Bespoke delivery · alerting DSΣP [LLM] TEA Protocol (tea.xyz) DNS resolution from developer or build endpoint Bespoke c2 · hunting DSΣPDDCS [LLM] Connection to Beamglea phishing credential-harvesting domains Bespoke actions · alerting DSΣPDDCS [LLM] DNS or HTTP egress to giftshop.club exfil domain Bespoke c2 · alerting DSΣPDDCS [LLM] Shai-Hulud worm C2 exfiltration to webhook.site UUID bb8ca5f6 Bespoke c2 · alerting DSΣPDDCS [LLM] Egress to websocket-api2.publicvm.com (Qix campaign credential exfil C2) Bespoke c2 · alerting DSΣPDDCS [LLM] Node process creating GitHub repo via api.github.com (s1ngularity exfil channel) Bespoke actions · hunting DSPDDCS [LLM] Scavenger Stealer C2 beacon to corroborated infrastructure (datahog.su / datalytica.su / smartscreen-api.com) Bespoke c2 · alerting DSΣPDDCS [LLM] Egress to Solidity Language Cursor extension C2 infrastructure (angelic.su / lmfao.su / staketree.net / ab498.pythonanywhere.com / 144.172.1 Bespoke c2 · hunting DSΣPDDCS [LLM] BoltDB Go backdoor C2 callback to 49.12.198.231:20022 Bespoke c2 · hunting DSΣPDDCS [LLM] Outbound fetch of file.sh via attacker-controlled commit d8daa0b... on raw.githubusercontent.com Bespoke c2 · alerting DSΣPDDCS [LLM] Polyfill malware C2: contact with googie-anaiytics homograph or kuurza redirect Bespoke c2 · alerting DSΣPDDCS [LLM] PHP web-server process initiating outbound TCP (fsockopen reverse shell to attacker) Bespoke c2 · alerting DSΣPCS [LLM] Moq SponsorLink email exfil egress to cdn.devlooped.com / SponsorLink blob Bespoke c2 · hunting DSΣPDDCS [LLM] npm/PyPI install-script beacon to hardcoded C2 3.72.6.53 (django-yauth supply chain) Bespoke c2 · alerting DSΣPDDCSCW [LLM] CircleCI breach C2 egress to potrax[.]com and 8 hardcoded attacker IPs Bespoke c2 · hunting DSΣPCSCW [LLM] Python child-of-python making download-and-exec egress to non-PyPI host Bespoke c2 · hunting DSΣPDDCS [LLM] Java process fetching first-seen external URL/DNS — Commons Config url/dns lookup (CVE-2022-33980) Bespoke c2 · hunting DSPDDCS [LLM] gxm-reference second-stage backdoor C2 to 82.196.7.23 / 82.196.15.238 (/callbackupload) Bespoke c2 · hunting DSΣPDDCS [LLM] node-ipc/peacenotwar geolocation beacon to api.ipgeolocation.io from Node runtime Bespoke c2 · alerting DSΣPDDCS [LLM] Outbound or inbound connection to TrojanOrders C2/source IP 45.134.20.11 Bespoke c2 · hunting DSΣPDDCS [LLM] Network activity involving CVE-2022-24086 attacker IP 45.134.20.11 Bespoke c2 · hunting DSΣPDDCSCW [LLM] CodeCov uploader egress to non-CodeCov host (surfaces exfil server IP) Bespoke c2 · hunting DSPCS [LLM] Outbound connection/DNS to npm exfil endpoint entfet95itcxpuu.m.pipedream.net Bespoke c2 · alerting DSΣPCS [LLM] npm/node install lifecycle spawning interactive or reverse shell Bespoke install · hunting DSΣPDDCS [LLM] ImageMagick convert lineage egress to public IP (url() delegate / netcat reverse shell) Bespoke c2 · hunting DSΣPCS [LLM] Mintegral SourMint SDK config/analytics beacon to rayjump.com Bespoke c2 · hunting DSΣPCS [LLM] Inbound web request to Node app with ?cmd= command-injection backdoor parameter Bespoke c2 · hunting SP [LLM] Exfiltration callback to mironanoru.zzz.com.ua (rest-client backdoor C2) Bespoke actions · alerting DSΣPDDCS [LLM] strong_password 0.0.7 backdoor: beacon to home server smiley.zzz.com.ua Bespoke c2 · alerting DSΣPDDCS [LLM] Agama wallet C2/exfil callback to updatecheck.herokuapp.com (electron-native-notify) Bespoke c2 · alerting DSΣPDDCS [LLM] CRLF / HTTP-header injection in URL query string (urllib3 CVE-2019-11236 PoC shape) Bespoke exploit · hunting SΣP [LLM] bootstrap-sass RCE trigger: base64 Ruby payload smuggled in ___cfduid cookie Bespoke exploit · hunting SP [LLM] ImageMagick binary making outbound network connection (ImageTragick URL/HTTPS coder SSRF) Bespoke c2 · hunting DSPCS

Articles citing this technique (244)