T1102.001Dead Drop Resolver
T1102.001 — Dead Drop Resolver is a MITRE ATT&CK technique in the Command and Control tactic. Clankerusecase tracks 14 detection use cases covering it and 12 threat-intel articles citing it.
Command and Control
14Use cases
12Articles
0Sub-techniques
1Tactic
↑ Parent technique: T1102 · Web Service
Use cases covering this technique (14)
[LLM] GitHub dead-drop C2 — commit-search for RevokeAndItGoesKaboom / TheBeautifulSandsOfTime [LLM] Gamaredon dead-drop C&C resolution via Telegra.ph and GoFile from script hosts [LLM] Bun process reaching GitHub commit-search API — Miasma dead-drop C2 [LLM] VS Code/Cursor extension host fetches dropper from nrwl/nx orphan commit on GitHub [LLM] macOS Python backdoor persistence via kitty-monitor LaunchAgent and cat.py drop [LLM] FIRESCALE GitHub dead-drop fallback C2 lookup (api.github.com commit search) [LLM] Outbound fetch of attacker-controlled autoimport VSIX from ColossusQuailPray GitHub release [LLM] node.exe contacting Solana JSON-RPC endpoints (suspected blockchain dead-drop C2) [LLM] ForceMemo: Python process queries Solana mainnet RPC endpoint (blockchain dead-drop C2) [LLM] DRILLAPP C2 staging: msedge.exe contacting pastefy.app [LLM] Inbound email with HTML attachment linking to unpkg.com Beamglea package [LLM] Beamglea mad-* dead-drop fetch from raw.githubusercontent.com/Abassdos2992 [LLM] Ruby/Rails process fetching remote code from pastebin.com raw (rest-client 1.6.13 backdoor) [LLM] strong_password 0.0.7 backdoor: Ruby app server fetches second-stage payload from pastebin.com/raw/xa456PFtArticles citing this technique (12)
high Microsoft's durabletask package on PyPi Compromised. Mini Shai Hulud attacks again... again! art-469
crit ForceMemo: Hundreds of GitHub Python Repos Compromised via Account Takeover and Force-Push art-597