T1102Web Service
T1102 — Web Service is a MITRE ATT&CK technique in the Command and Control tactic. Clankerusecase tracks 17 detection use cases covering it and 15 threat-intel articles citing it.
Command and Control
17Use cases
15Articles
3Sub-techniques
1Tactic
Sub-techniques (3)
Use cases covering this technique (17)
Linux Ngrok Reverse Proxy Usage Windows Ngrok Reverse Proxy Usage Ngrok Reverse Proxy on Network Windows Abused Web Services [LLM] Tengu botnet C2 / IPFS beacon to 64.89.163.8 on TCP 9931 and 8080 [LLM] InsureOTP kit exfiltration: browser connecting to api.telegram.org Bot API [LLM] TAG-195 Golden Chickens C2 beacon to known staging/C2 infrastructure [LLM] msaRAT C2 network IOC: connection to 172.86.126.18 or is-01-ast.ols-img-12.workers.dev [LLM] NodeBB server outbound ActivityPub/webfinger fetch to ephemeral tunnel or new domain [LLM] Node.js retrieving Miasma second stage from IPFS gateway (specific CIDs) [LLM] Malicious 'SHA1HULUD' self-hosted GitHub Actions runner installation / persistence [LLM] ARToken/EvilTokens PhaaS infrastructure contact (pamconj.com panel + Cloudflare Worker lure) [LLM] Cloudflare-tunnel curl-piped Python stager (kamikaze.sh / kube.py) [LLM] Outbound exfiltration to webhook.site from npm / node / bun process tree [LLM] Browser load of Beamglea redirect-* or mad-* package script from unpkg.com [LLM] Discord webhook / CDN exfiltration from non-browser process (Empyrean stealer C2) [LLM] strong_password 0.0.7 backdoor: beacon to home server smiley.zzz.com.uaArticles citing this technique (15)
crit CTM360 Research Reveals How Insurance Phishing Has Evolved Into Real-Time Account Hijacking art-74
high Catan and Mouse art-261