ATT&CK Technique · Exfiltration
T1041 Exfiltration Over C2 ChannelMapped by 17 reports, 12 detection rules and 13 tracked actors on The Hunters Ledger. Technique page on attack.mitre.org.
← All techniques and the coverage heatmap
Reports
Each report maps this technique in its own ATT&CK table, at the confidence the report states. The link opens that table.
Report
AdvancedRouterScanner
Detection rules
Rules whose ATT&CK coverage line names this technique, by detection page. The link opens the page's coverage table.
Detection rules
FACEIT ClickFix Pages Point CS2 Players to a Script URL That VirusTotal Ties to a Steam-Focused ExecutableNewdouble_ClickFix_SteamCDP_Loader_Strings (YARA, Hunting); Panel Import POST With X-Vac-Secret Header (SURICATA, Hunting)
Detection rules
Gotenberg CVE-2026-42589 Mass Exploitation and CryptominingOut-of-Band Command Output Body Markers (START/END Brackets) (SURICATA, Hunting)
Detection rules
Carrier Credential Harvesting Through a Customer's RouterNetwork-Device Self-Exfiltration via Outbound PUT with User-Agent cisco-IOS (SURICATA, Detection)
Detection rules
EvilSoul-Engine: A Brazilian Stealer-Builder Malware-as-a-ServiceEvilSoul-Engine Webhook-Resolution Relay POST /tralalero (SURICATA, Detection)
Detection rules
Multi-Actor AI-Agent Framework Abuse (8 Operators)ARPA Observability Harvester Systemd Service Pattern (YARA, Detection)
Detection rules
Russian Gemini CLI Credential Mill (213.165.51.115)A2A C2 Beacon POST to Operator Endpoint with X-Agent-ID Header (SURICATA, Detection)
Detection rules
Turkish ARPA AI-Augmented Observability Compromise (209.38.205.158)HTTP POST to ARPA Instana Ingestion Endpoint (IP-Agnostic) (SURICATA, Detection)
Detection rules
BellaMain Turkish PhaaS Panel (79.137.192.3)BellaMain USOM Poll, Telegram Bot Outbound, and Correlations (SIGMA, Hunting)
Detection rules
OpenStrike Expanded Toolkit — 106 New Files (2026-04-08)OpenStrike Gen-4 Beacon (YARA, Detection); OpenStrike Gen-4 Beacon Output Submission HTTP POST to /submit with Hex Beacon ID (SIGMA, Hunting); OpenStrike Gen-4 Beacon Output Submission (POST /submit) (SURICATA, Hunting)
Tracked actors
Designations whose reports map this technique.
- UTA-2026-002: XiebroC2 and Covenant operator working from a Chinese-language build environment
- UTA-2026-004: Developer of the OpenStrike multi-implant C2 toolkit, with a cracked Cobalt Strike arsenal
- UTA-2026-008: Developer and operator of the BellaMain Turkish phishing-as-a-service panel
- UTA-2026-009: Multi-product fraud operator pairing a real VPN service with a brand-impersonation phishing library
- UTA-2026-010: Rhadamanthys MaaS customer with a self-built loader (customer side only, never the vendor)
- UTA-2026-011: Financially motivated operator weaponising a cPanel authentication bypass with a custom harvesting toolkit
- UTA-2026-012: AI-augmented credential-mill operator using an LLM for per-target password mutation
- UTA-2026-013: Espionage-flavoured operator harvesting a state-affiliated insurer's observability stack through an AI agent platform
- UTA-2026-018: Hands-on-keyboard operator exploiting four Southeast Asian governments with a bespoke edge-device toolkit
- UTA-2026-020: Self-branded commodity cryptojacking operator mass-exploiting exposed Chinese enterprise software
- UTA-2026-021: Assembler-model intrusion operator staging other actors' tooling against one German victim forest
- UTA-2026-023: Telecom-focused operator reaching a carrier's credential plane through a customer's managed router
- UTA-2026-024: Windows post-exploitation intrusion set with Sliver and a blockchain-resolved implant
ATT&CK v19.2. MITRE ATT&CK® is a registered trademark of The MITRE Corporation; technique names are MITRE's and link to MITRE's own pages. The mapping on each linked page is this publication's reading of its own evidence.