ATT&CK Technique · Command and Control
T1071.001 Web ProtocolsMapped by 28 reports, 86 detection rules and 18 tracked actors on The Hunters Ledger. Technique page on attack.mitre.org.
← All techniques and the coverage heatmap
Reports
Each report maps this technique in its own ATT&CK table, at the confidence the report states. The link opens that table.
Report
Quasar + XWorm + PowerShell
Detection rules
Rules whose ATT&CK coverage line names this technique, by detection page. The link opens the page's coverage table.
Detection rules
Gotenberg CVE-2026-42589 Mass Exploitation and CryptominingOut-of-Band Tagged Callback URI Shape (SURICATA, Hunting); Out-of-Band Deploy Verdict Body (MINER_OK) (SURICATA, Hunting)
Detection rules
Sliver C2 Windows Post-Exploitation Staging, 193.233.202.17Sliver Beacon Canonical Import Path In Process Memory (YARA, Detection); Sliver Operator Build Artifacts, 193.233.202.17 Campaign (YARA, Detection); EtherRAT-class Node.js Bot Configuration Constants (YARA, Detection); HTTP POST To A Minified-Static-Asset-Shaped Path With A Single-Letter Query Parameter (SURICATA, Detection); HTTP Client Claims A Non-Existent Chrome 108 Build (SURICATA, Detection)
Detection rules
CloudSync: An Assembler's Intrusion ToolkitSentinelStealer c3lestial.fun TLS SNI (SURICATA, Hunting); SentinelStealer c3lestial.fun DNS Query (SURICATA, Hunting)
Detection rules
GOCLOUD Multi-Service CryptojackingGOCLOUD_Windows_Miner_WinJenkins (YARA, Detection); GOCLOUD_Linux_Miner_v7 (YARA, Detection); GOCLOUD XMRig Heartbeat, Fixed Parameter Order (SURICATA, Detection); GOCLOUD XMRig Worker-Label Heartbeat (SURICATA, Detection)
Detection rules
EvilSoul-Engine: A Brazilian Stealer-Builder Malware-as-a-ServiceEvilSoul-Engine 299a2e7f Socket.IO WebPanel Build (YARA, Detection); EvilSoul-Engine Webhook-Resolution Relay POST /tralalero (SURICATA, Detection)
Detection rules
KAIDO: A Brazilian Quasar-Fork RAT with Hidden-Desktop Session HijackingKAIDO TeamKAIDO C2 TLS Certificate Issuer (SURICATA, Detection)
Detection rules
Multi-Actor AI-Agent Framework Abuse (8 Operators)Russian A2A C2 Python-stdlib BaseHTTPServer (YARA, Detection); A2A C2 X-Agent-Id Header + API Endpoint Pattern (SURICATA, Detection)
Detection rules
Flask C2 & MSSQL CLR Backdoor on a Windows Post-Exploitation Staging HostFlask C2 Health Endpoint: Distinctive JSON Field-Combo (SURICATA, Detection); Flask C2 Beacon Endpoint: POST to /api/report (SURICATA, Hunting); Flask C2 Beacon Endpoint: POST to /api/heartbeat (SURICATA, Hunting)
Detection rules
Rovodev AI-Co-Authored Mirai Variant + Matrix C2 (87.106.143.220)MAL_Python_Persistent_Bot_DualChannel_CNC (YARA, Detection); Pandora-Mirai Naku Binary Distribution URI Path (SURICATA, Detection); Pandora-Mirai Pandoras-Box Binary Distribution URI Path (SURICATA, Detection); Pandora-Mirai bot.sh Reseed Download URI Pattern (SURICATA, Hunting); Naku Binary Reference in HTTP URI (Bare Substring) (SURICATA, Hunting); Naku Binary Fetch URI Pattern: Historical Aruba Distribution Convention (SURICATA, Hunting); Naku Binary Fetch URI Pattern: Historical Aruba Backup Distribution Convention (SURICATA, Hunting)
Detection rules
Russian Gemini CLI Credential Mill (213.165.51.115)AI Operator Handoff Document Family (YARA, Detection); A2A C2 Server (Unauthenticated Python stdlib) (YARA, Detection); A2A C2 Client Console / Exec Tool (YARA, Detection); C2_INFRA_TRANSFER Explicit AI-to-AI Header (Narrow / Highest Fidelity) (YARA, Detection); Python HTTP Server on Non-Standard Port with UTF-16LE Encoding (A2A C2 Pattern) (SIGMA, Hunting); A2A C2 Beacon POST to Operator Endpoint with X-Agent-ID Header (SURICATA, Detection)
Detection rules
Turkish ARPA AI-Augmented Observability Compromise (209.38.205.158)Rule 1: PowerShell Instana Local Collector (YARA, Detection); Rule 2: ARPA Observability Harvester Platform (YARA, Detection); Sigma Rule 1: PowerShell Process Invoking Instana API with Stored JWT Bearer Token (SIGMA, Detection); Sigma Rule 2: Outbound HTTPS to the Victim Organization Instana Tenant (SIGMA, Hunting); HTTP POST to ARPA Instana Ingestion Endpoint (IP-Agnostic) (SURICATA, Detection); DNS Query Egress to the Victim Organization Instana Tenant (SURICATA, Hunting)
Detection rules
CVE-2026-41940 cPanel Harvester Toolkit (216.126.227.49)Operator Flask C2 Dashboard /login-2fa Redirect Path (SIGMA, Hunting); Operator Flask C2 Dashboard Banner Hunt: Werkzeug/3.1.8 + /login-2fa (SURICATA, Hunting)
Detection rules
Inkognito Russian VPN/Phishing Operator (INK VPN / INK Lens)Inkognito Custom X-Admin-Token Header in HTTP Request (SURICATA, Hunting); Inkognito X-Admin-Token in CORS Allow-Headers Response (SURICATA, Hunting)
Detection rules
Rhadamanthys MaaS Customer Deep-Dive (79.137.192.3)BellaMain PhaaS Panel PHP Source (YARA, Detection); BellaMain PhaaS Panel HTTP Request Patterns (SIGMA, Detection); Rhadamanthys Customer Panel-ID URL Pattern (SURICATA, Detection)
Detection rules
HijackLoader / Penguish / Rugmi to AsyncRAT Multi-Vector Phishing CampaignAsyncRAT SSL JA3 Fingerprint 07af4aa9e4d215a5ee63f9a0a277fbe3 (SURICATA, Detection)
Detection rules
AdaptixC2 Open Directory Exposure (45.130.148.125)AdaptixC2 Windows Beacon: Stock Framework Fingerprint (YARA, Detection); AdaptixC2 Default Listener: Anomalous Firefox 20 User-Agent with X-Beacon-Id Header (SIGMA, Hunting); AdaptixC2 Beacon: High-Frequency Deterministic HTTP POST Cadence to Stock URIs (SIGMA, Hunting); AdaptixC2 Default Listener X-Beacon-Id Heartbeat Header (Broad, Any IP) (SURICATA, Detection); AdaptixC2 Beacon Empty-Body POST Carrying the X-Beacon-Id Header (SURICATA, Detection); AdaptixC2 Stock Listener URI /api/v1/status with Firefox 20 UA (SURICATA, Hunting); AdaptixC2 Operator-Added jQuery URI with Firefox 20 UA (SURICATA, Hunting); AdaptixC2 Stock Listener Response Envelope (Server-Side) (SURICATA, Hunting)
Detection rules
Chaos Ransomware (TorBrowserTor) Multi-Stage Loader (94.103.1.13)Orcus RAT v7 Wardow Crack (YARA, Detection); Loopback C2 Connection on Port 20268 (SIGMA, Hunting); XOR-Encoded Payload Staging Download (.xor URI Suffix) (SURICATA, Hunting)
Detection rules
OpenStrike Expanded Toolkit — 106 New Files (2026-04-08)OpenStrike Gen-4 Beacon (YARA, Detection); OpenStrike Gen-1 and Gen-2 Prototype Beacons (YARA, Detection); Cobalt Strike Malleable C2 BOIE9 IE9 User-Agent in Proxy Traffic (SIGMA, Hunting); OpenStrike Gen-4 Beacon Task Polling HTTP GET to /updates with Hex Beacon ID (SIGMA, Hunting); OpenStrike Gen-4 Beacon Output Submission HTTP POST to /submit with Hex Beacon ID (SIGMA, Hunting); OpenStrike Gen-4 Beacon Network Task Poll (GET /updates) (SURICATA, Hunting); OpenStrike Gen-4 Beacon Output Submission (POST /submit) (SURICATA, Hunting); Cobalt Strike Malleable C2 BOIE9 IE9 User-Agent Detected (SURICATA, Hunting); CovertVPN HTTP Data Channel GET /receive Endpoint (SURICATA, Hunting)
Detection rules
OpenStrike Beacon Toolkit (172.105.0.126)OpenStrike C Beacon Debug Strings + AES/HMAC Crypto Constants (YARA, Detection); OpenStrike Python Universal Beacon Self-Identification Banner (YARA, Detection); Cobalt Strike 3.x Tripwired ReflectiveLoader + MALC Malleable Profile (YARA, Detection); Cobalt Strike Malleable C2 Profile MALC User-Agent in Proxy Traffic (SIGMA, Detection); Cobalt Strike Malleable C2 MALC User-Agent Detected (SURICATA, Detection)
Detection rules
Open Directory at 193.56.255.154 — XiebroC2 v3.1 & Covenant C2Covenant C2 GruntStager Combined Build Detection (YARA, Detection); Covenant C2 GruntStager HTTP Beacon: Campaign Session Token Detected (SIGMA, Detection); Covenant GruntStager C2 Beacon: Campaign Session Token in HTTP POST (SURICATA, Detection); Covenant GruntStager Masquerade: Chrome 41 Windows 7 UA on Port 443 (SURICATA, Detection)
Detection rules
ZeroTrace Multi-Family MaaS Operation (74.0.42.25)PureRAT v4.1.9 Protocol Preamble Before TLS (SURICATA, Detection)
Detection rules
Sliver C2 Toolchain with ScareCrow Loader (45.94.31.220)sihost.exe Initiating Anomalous Outbound Network Connection (SIGMA, Detection)
Detection rules
Webserver Compromise Kit (91.236.230.250)Anachronistic IE11/Win7 User-Agent (Possible revsocks) (SURICATA, Hunting)
Detection rules
Dual-RAT Analysis: Pulsar RAT vs. NjRAT/XWormQuasar RAT C2 Connection on TCP 4782 (SIGMA, Detection); NjRAT/XWorm Pastebin Dead-Drop C2 Resolution (SIGMA, Detection); NjRAT/XWorm Spoofed Mobile Safari User-Agent (SURICATA, Hunting)
Detection rules
Hybrid Loader/Stealer Ecosystem Masquerading as SogouSogouStealer C2 Scheduler and Signature-Database Components (YARA, Detection); SogouStealer CGI1 C2 URI Pattern (SURICATA, Hunting)
Detection rules
Houselet.exe — The Go-Based Loader Masquerading as PlayStation Remote PlayHTTP POST to PHP Endpoint With Missing User-Agent (SIGMA, Hunting)
Tracked actors
Designations whose reports map this technique.
- UTA-2026-001: Sliver C2 operator with an automated ScareCrow, Donut and SysWhispers3 build pipeline
- UTA-2026-002: XiebroC2 and Covenant operator working from a Chinese-language build environment
- UTA-2026-003: Commodity MaaS consumer running Shadow RAT and XWorm from one Windows VPS
- UTA-2026-004: Developer of the OpenStrike multi-implant C2 toolkit, with a cracked Cobalt Strike arsenal
- UTA-2026-005: Chaos ransomware builder user with a private five-stage crypter
- UTA-2026-006: Stock AdaptixC2 operator with an operator-written PowerShell and .NET injection chain
- UTA-2026-007: HijackLoader customer running a 15-month multi-vector phishing campaign into an AsyncRAT-class RAT
- UTA-2026-008: Developer and operator of the BellaMain Turkish phishing-as-a-service panel
- UTA-2026-009: Multi-product fraud operator pairing a real VPN service with a brand-impersonation phishing library
- UTA-2026-010: Rhadamanthys MaaS customer with a self-built loader (customer side only, never the vendor)
- UTA-2026-011: Financially motivated operator weaponising a cPanel authentication bypass with a custom harvesting toolkit
- UTA-2026-012: AI-augmented credential-mill operator using an LLM for per-target password mutation
- UTA-2026-013: Espionage-flavoured operator harvesting a state-affiliated insurer's observability stack through an AI agent platform
- UTA-2026-014: DDoS-for-hire operator running an AI co-authored C2 framework over a Pandora-Mirai botnet
- UTA-2026-019: Grey-market personal-data harvester running scores of LLM-assisted attack scripts against Chinese consumer platforms
- UTA-2026-020: Self-branded commodity cryptojacking operator mass-exploiting exposed Chinese enterprise software
- UTA-2026-023: Telecom-focused operator reaching a carrier's credential plane through a customer's managed router
- UTA-2026-024: Windows post-exploitation intrusion set with Sliver and a blockchain-resolved implant
ATT&CK v19.2. MITRE ATT&CK® is a registered trademark of The MITRE Corporation; technique names are MITRE's and link to MITRE's own pages. The mapping on each linked page is this publication's reading of its own evidence.