Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Command and Control/ T1102

T1102Web Service

T1102 — Web Service is a MITRE ATT&CK technique in the Command and Control tactic. Clankerusecase tracks 17 detection use cases covering it and 15 threat-intel articles citing it.

Command and Control
View on the matrix → Filter Detection Library MITRE official spec ↗
17Use cases
15Articles
3Sub-techniques
1Tactic

Sub-techniques (3)

Use cases covering this technique (17)

Linux Ngrok Reverse Proxy Usage ESCU actions · hunting P Windows Ngrok Reverse Proxy Usage ESCU actions · hunting P Ngrok Reverse Proxy on Network ESCU actions · hunting P Windows Abused Web Services ESCU actions · hunting P [LLM] Tengu botnet C2 / IPFS beacon to 64.89.163.8 on TCP 9931 and 8080 Bespoke c2 · hunting DSΣPDDCS [LLM] InsureOTP kit exfiltration: browser connecting to api.telegram.org Bot API Bespoke actions · alerting DSΣPDDCS [LLM] TAG-195 Golden Chickens C2 beacon to known staging/C2 infrastructure Bespoke c2 · hunting DSΣPDDCS [LLM] msaRAT C2 network IOC: connection to 172.86.126.18 or is-01-ast.ols-img-12.workers.dev Bespoke c2 · hunting DSΣPDDCS [LLM] NodeBB server outbound ActivityPub/webfinger fetch to ephemeral tunnel or new domain Bespoke exploit · hunting DSΣPCS [LLM] Node.js retrieving Miasma second stage from IPFS gateway (specific CIDs) Bespoke delivery · alerting DSΣPDDCS [LLM] Malicious 'SHA1HULUD' self-hosted GitHub Actions runner installation / persistence Bespoke install · alerting DSΣPDDCS [LLM] ARToken/EvilTokens PhaaS infrastructure contact (pamconj.com panel + Cloudflare Worker lure) Bespoke delivery · alerting DSΣPDDCS [LLM] Cloudflare-tunnel curl-piped Python stager (kamikaze.sh / kube.py) Bespoke delivery · alerting DSΣPDDCS [LLM] Outbound exfiltration to webhook.site from npm / node / bun process tree Bespoke c2 · alerting DSΣPDDCS [LLM] Browser load of Beamglea redirect-* or mad-* package script from unpkg.com Bespoke exploit · alerting DSΣPDDCS [LLM] Discord webhook / CDN exfiltration from non-browser process (Empyrean stealer C2) Bespoke actions · hunting DSPDDCS [LLM] strong_password 0.0.7 backdoor: beacon to home server smiley.zzz.com.ua Bespoke c2 · alerting DSΣPDDCS

Articles citing this technique (15)