Malware

Command and control

Also called C2, C&C.

Command and control is the channel an infected machine uses to receive instructions and send back stolen data. Attackers write it as C2 or C&C.

How it is measured

You see C2 as outbound traffic to a server that gives orders: HTTPS posts, DNS queries with odd subdomains, WebSocket connections, or requests to a cloud storage bucket. Defenders map it by IP, domain, URL path, certificate, and timing, then publish the findings as indicators.

On a hacked website, the signal is code that fetches instructions and acts on them: `fetch(url).then(r => r.text()).then(eval)` is the minimal case. The response changes over time, so capture it more than once.

Worked example

An e-commerce server runs a PHP backdoor that, every ten minutes, requests `https://api.cloud-sync.example/t.php?k=ab12` and runs whatever text comes back. On a quiet Tuesday the reply is `OK`. On Wednesday it is a base64 block that installs a card skimmer into the checkout template.

The owner blocks the domain at the firewall, finds the PHP file by its outbound call, and removes it. Blocking the domain alone would have left the file in place, ready to ask again on the next domain.

How it differs

C2 is the control path. A botnet is the set of machines that obey it. Beaconing is the periodic check-in that travels over C2. A payload is the work C2 delivers. You can swap the C2 server without losing the botnet, and you can lose the C2 server and leave the infected hosts sitting dormant.

Common errors

Treating a blocked domain as a cure. Searching only for IP addresses, which attackers rotate. Assuming a C2 channel looks like malware traffic when it often looks like normal HTTPS. Ignoring DNS. Forgetting to find and remove the local process that talks to it.

In practice

Log outbound connections from your servers, since servers rarely need to talk to random new domains. Alert on any first-seen destination from a production host. When you find one, trace it to the process, remove the process and its persistence, and then block the destination.

See also

Botnet, Beaconing, Payload

Sources

Count this on a real site.

Watch my website