Skip to content
THE HUNTER’S LEDGER
ATT&CK Technique · Command and Control
T1071.001 Web Protocols
Mapped by 28 reports, 86 detection rules and 18 tracked actors on The Hunters Ledger. Technique page on attack.mitre.org.

← All techniques and the coverage heatmap

Reports

Each report maps this technique in its own ATT&CK table, at the confidence the report states. The link opens that table.

Report Sep 2026 · under Command and Control · HIGH
Gotenberg CVE-2026-42589 Mass Exploitation and Cryptomining
Report Sep 2026 · under Command and Control · HIGH
Sliver C2 Windows Post-Exploitation Staging, 193.233.202.17
Report Aug 2026 · under Command and Control · HIGH
Carrier Credential Harvesting Through a Customer's Router
Report Jul 2026 · under Command and Control · HIGH
GOCLOUD Multi-Service Cryptojacking
Report Jul 2026 · under Command and Control · DEFINITE
Enough to Be Dangerous: The Mechanics of an LLM-Assisted Intrusion Campaign
Report Jul 2026 · under Command and Control · HIGH
EvilSoul-Engine: A Brazilian Stealer-Builder Malware-as-a-Service
Report Jun 2026 · under Command and Control · HIGH
Flask C2 & MSSQL CLR Backdoor on a Windows Post-Exploitation Staging Host
Report May 2026 · under Command and Control · HIGH
CVE-2026-41940 cPanel Harvester Toolkit (216.126.227.49)
Report May 2026 · under Command and Control · HIGH
BellaMain Turkish PhaaS Panel (79.137.192.3)
Report May 2026 · under Command and Control · HIGH
Inkognito Russian VPN/Phishing Operator (INK VPN / INK Lens)
Report May 2026 · under Command and Control · HIGH
Rhadamanthys MaaS Customer Deep-Dive (79.137.192.3)
Report May 2026 · under Command and Control · HIGH
HijackLoader / Penguish / Rugmi to AsyncRAT Multi-Vector Phishing Campaign
Report Apr 2026 · under Command and Control · HIGH
AdaptixC2 Open Directory Exposure (45.130.148.125)
Report Apr 2026 · under Command and Control · HIGH
Chaos Ransomware (TorBrowserTor) Multi-Stage Loader (94.103.1.13)
Report Apr 2026 · under Command and Control · HIGH
ShinyHunters Data Leak Site (91.215.85.22)
Report Apr 2026 · under Command and Control · HIGH
OpenStrike Expanded Toolkit — 106 New Files (2026-04-08)
Report Apr 2026 · under Command and Control · DEFINITE
OpenStrike Beacon Toolkit (172.105.0.126)
Report Apr 2026 · under Command and Control · HIGH
Shadow RAT & XWorm Open Directory Campaign
Report Apr 2026 · under Command and Control · HIGH
Open Directory at 193.56.255.154 — XiebroC2 v3.1 & Covenant C2
Report Mar 2026 · under Command and Control · HIGH
Sliver C2 Toolchain with ScareCrow Loader (45.94.31.220)
Report Feb 2026 · under Command and Control · HIGH
Webserver Compromise Kit (91.236.230.250)
Report Feb 2026 · under Command and Control · HIGH
Remcos RAT OpenDirectory Campaign
Report Feb 2026 · under Command and Control · HIGH
NsMiner: Multi-Stage Cryptojacking Operation
Report Jan 2026 · under Command and Control · HIGH
Arsenal-237 New Files: Advanced Toolkit Analysis
Report Dec 2025 · under Command and Control · HIGH
Dual-RAT Analysis: Pulsar RAT vs. NjRAT/XWorm
Report Dec 2025 · under Command and Control · HIGH
PULSAR RAT (server.exe) — Technical Analysis & Business Risk Assessment
Report Nov 2025 · under Command and Control · HIGH
Hybrid Loader/Stealer Ecosystem Masquerading as Sogou
Report Oct 2025 · under Command and Control · HIGH
Quasar + XWorm + PowerShell

Detection rules

Rules whose ATT&CK coverage line names this technique, by detection page. The link opens the page's coverage table.

Detection rules Sep 2026 · 2 rules
Gotenberg CVE-2026-42589 Mass Exploitation and Cryptomining
Out-of-Band Tagged Callback URI Shape (SURICATA, Hunting); Out-of-Band Deploy Verdict Body (MINER_OK) (SURICATA, Hunting)
Detection rules Sep 2026 · 5 rules
Sliver C2 Windows Post-Exploitation Staging, 193.233.202.17
Sliver Beacon Canonical Import Path In Process Memory (YARA, Detection); Sliver Operator Build Artifacts, 193.233.202.17 Campaign (YARA, Detection); EtherRAT-class Node.js Bot Configuration Constants (YARA, Detection); HTTP POST To A Minified-Static-Asset-Shaped Path With A Single-Letter Query Parameter (SURICATA, Detection); HTTP Client Claims A Non-Existent Chrome 108 Build (SURICATA, Detection)
Detection rules Aug 2026 · 2 rules
CloudSync: An Assembler's Intrusion Toolkit
SentinelStealer c3lestial.fun TLS SNI (SURICATA, Hunting); SentinelStealer c3lestial.fun DNS Query (SURICATA, Hunting)
Detection rules Jul 2026 · 4 rules
GOCLOUD Multi-Service Cryptojacking
GOCLOUD_Windows_Miner_WinJenkins (YARA, Detection); GOCLOUD_Linux_Miner_v7 (YARA, Detection); GOCLOUD XMRig Heartbeat, Fixed Parameter Order (SURICATA, Detection); GOCLOUD XMRig Worker-Label Heartbeat (SURICATA, Detection)
Detection rules Jul 2026 · 2 rules
EvilSoul-Engine: A Brazilian Stealer-Builder Malware-as-a-Service
EvilSoul-Engine 299a2e7f Socket.IO WebPanel Build (YARA, Detection); EvilSoul-Engine Webhook-Resolution Relay POST /tralalero (SURICATA, Detection)
Detection rules Jul 2026 · 1 rule
KAIDO: A Brazilian Quasar-Fork RAT with Hidden-Desktop Session Hijacking
KAIDO TeamKAIDO C2 TLS Certificate Issuer (SURICATA, Detection)
Detection rules Jun 2026 · 2 rules
Multi-Actor AI-Agent Framework Abuse (8 Operators)
Russian A2A C2 Python-stdlib BaseHTTPServer (YARA, Detection); A2A C2 X-Agent-Id Header + API Endpoint Pattern (SURICATA, Detection)
Detection rules Jun 2026 · 3 rules
Flask C2 & MSSQL CLR Backdoor on a Windows Post-Exploitation Staging Host
Flask C2 Health Endpoint: Distinctive JSON Field-Combo (SURICATA, Detection); Flask C2 Beacon Endpoint: POST to /api/report (SURICATA, Hunting); Flask C2 Beacon Endpoint: POST to /api/heartbeat (SURICATA, Hunting)
Detection rules May 2026 · 7 rules
Rovodev AI-Co-Authored Mirai Variant + Matrix C2 (87.106.143.220)
MAL_Python_Persistent_Bot_DualChannel_CNC (YARA, Detection); Pandora-Mirai Naku Binary Distribution URI Path (SURICATA, Detection); Pandora-Mirai Pandoras-Box Binary Distribution URI Path (SURICATA, Detection); Pandora-Mirai bot.sh Reseed Download URI Pattern (SURICATA, Hunting); Naku Binary Reference in HTTP URI (Bare Substring) (SURICATA, Hunting); Naku Binary Fetch URI Pattern: Historical Aruba Distribution Convention (SURICATA, Hunting); Naku Binary Fetch URI Pattern: Historical Aruba Backup Distribution Convention (SURICATA, Hunting)
Detection rules May 2026 · 6 rules
Russian Gemini CLI Credential Mill (213.165.51.115)
AI Operator Handoff Document Family (YARA, Detection); A2A C2 Server (Unauthenticated Python stdlib) (YARA, Detection); A2A C2 Client Console / Exec Tool (YARA, Detection); C2_INFRA_TRANSFER Explicit AI-to-AI Header (Narrow / Highest Fidelity) (YARA, Detection); Python HTTP Server on Non-Standard Port with UTF-16LE Encoding (A2A C2 Pattern) (SIGMA, Hunting); A2A C2 Beacon POST to Operator Endpoint with X-Agent-ID Header (SURICATA, Detection)
Detection rules May 2026 · 6 rules
Turkish ARPA AI-Augmented Observability Compromise (209.38.205.158)
Rule 1: PowerShell Instana Local Collector (YARA, Detection); Rule 2: ARPA Observability Harvester Platform (YARA, Detection); Sigma Rule 1: PowerShell Process Invoking Instana API with Stored JWT Bearer Token (SIGMA, Detection); Sigma Rule 2: Outbound HTTPS to the Victim Organization Instana Tenant (SIGMA, Hunting); HTTP POST to ARPA Instana Ingestion Endpoint (IP-Agnostic) (SURICATA, Detection); DNS Query Egress to the Victim Organization Instana Tenant (SURICATA, Hunting)
Detection rules May 2026 · 2 rules
CVE-2026-41940 cPanel Harvester Toolkit (216.126.227.49)
Operator Flask C2 Dashboard /login-2fa Redirect Path (SIGMA, Hunting); Operator Flask C2 Dashboard Banner Hunt: Werkzeug/3.1.8 + /login-2fa (SURICATA, Hunting)
Detection rules May 2026 · 2 rules
Inkognito Russian VPN/Phishing Operator (INK VPN / INK Lens)
Inkognito Custom X-Admin-Token Header in HTTP Request (SURICATA, Hunting); Inkognito X-Admin-Token in CORS Allow-Headers Response (SURICATA, Hunting)
Detection rules May 2026 · 3 rules
Rhadamanthys MaaS Customer Deep-Dive (79.137.192.3)
BellaMain PhaaS Panel PHP Source (YARA, Detection); BellaMain PhaaS Panel HTTP Request Patterns (SIGMA, Detection); Rhadamanthys Customer Panel-ID URL Pattern (SURICATA, Detection)
Detection rules May 2026 · 1 rule
HijackLoader / Penguish / Rugmi to AsyncRAT Multi-Vector Phishing Campaign
AsyncRAT SSL JA3 Fingerprint 07af4aa9e4d215a5ee63f9a0a277fbe3 (SURICATA, Detection)
Detection rules Apr 2026 · 8 rules
AdaptixC2 Open Directory Exposure (45.130.148.125)
AdaptixC2 Windows Beacon: Stock Framework Fingerprint (YARA, Detection); AdaptixC2 Default Listener: Anomalous Firefox 20 User-Agent with X-Beacon-Id Header (SIGMA, Hunting); AdaptixC2 Beacon: High-Frequency Deterministic HTTP POST Cadence to Stock URIs (SIGMA, Hunting); AdaptixC2 Default Listener X-Beacon-Id Heartbeat Header (Broad, Any IP) (SURICATA, Detection); AdaptixC2 Beacon Empty-Body POST Carrying the X-Beacon-Id Header (SURICATA, Detection); AdaptixC2 Stock Listener URI /api/v1/status with Firefox 20 UA (SURICATA, Hunting); AdaptixC2 Operator-Added jQuery URI with Firefox 20 UA (SURICATA, Hunting); AdaptixC2 Stock Listener Response Envelope (Server-Side) (SURICATA, Hunting)
Detection rules Apr 2026 · 3 rules
Chaos Ransomware (TorBrowserTor) Multi-Stage Loader (94.103.1.13)
Orcus RAT v7 Wardow Crack (YARA, Detection); Loopback C2 Connection on Port 20268 (SIGMA, Hunting); XOR-Encoded Payload Staging Download (.xor URI Suffix) (SURICATA, Hunting)
Detection rules Apr 2026 · 9 rules
OpenStrike Expanded Toolkit — 106 New Files (2026-04-08)
OpenStrike Gen-4 Beacon (YARA, Detection); OpenStrike Gen-1 and Gen-2 Prototype Beacons (YARA, Detection); Cobalt Strike Malleable C2 BOIE9 IE9 User-Agent in Proxy Traffic (SIGMA, Hunting); OpenStrike Gen-4 Beacon Task Polling HTTP GET to /updates with Hex Beacon ID (SIGMA, Hunting); OpenStrike Gen-4 Beacon Output Submission HTTP POST to /submit with Hex Beacon ID (SIGMA, Hunting); OpenStrike Gen-4 Beacon Network Task Poll (GET /updates) (SURICATA, Hunting); OpenStrike Gen-4 Beacon Output Submission (POST /submit) (SURICATA, Hunting); Cobalt Strike Malleable C2 BOIE9 IE9 User-Agent Detected (SURICATA, Hunting); CovertVPN HTTP Data Channel GET /receive Endpoint (SURICATA, Hunting)
Detection rules Apr 2026 · 5 rules
OpenStrike Beacon Toolkit (172.105.0.126)
OpenStrike C Beacon Debug Strings + AES/HMAC Crypto Constants (YARA, Detection); OpenStrike Python Universal Beacon Self-Identification Banner (YARA, Detection); Cobalt Strike 3.x Tripwired ReflectiveLoader + MALC Malleable Profile (YARA, Detection); Cobalt Strike Malleable C2 Profile MALC User-Agent in Proxy Traffic (SIGMA, Detection); Cobalt Strike Malleable C2 MALC User-Agent Detected (SURICATA, Detection)
Detection rules Apr 2026 · 4 rules
Open Directory at 193.56.255.154 — XiebroC2 v3.1 & Covenant C2
Covenant C2 GruntStager Combined Build Detection (YARA, Detection); Covenant C2 GruntStager HTTP Beacon: Campaign Session Token Detected (SIGMA, Detection); Covenant GruntStager C2 Beacon: Campaign Session Token in HTTP POST (SURICATA, Detection); Covenant GruntStager Masquerade: Chrome 41 Windows 7 UA on Port 443 (SURICATA, Detection)
Detection rules Mar 2026 · 1 rule
ZeroTrace Multi-Family MaaS Operation (74.0.42.25)
PureRAT v4.1.9 Protocol Preamble Before TLS (SURICATA, Detection)
Detection rules Mar 2026 · 1 rule
Sliver C2 Toolchain with ScareCrow Loader (45.94.31.220)
sihost.exe Initiating Anomalous Outbound Network Connection (SIGMA, Detection)
Detection rules Feb 2026 · 1 rule
Webserver Compromise Kit (91.236.230.250)
Anachronistic IE11/Win7 User-Agent (Possible revsocks) (SURICATA, Hunting)
Detection rules Dec 2025 · 3 rules
Dual-RAT Analysis: Pulsar RAT vs. NjRAT/XWorm
Quasar RAT C2 Connection on TCP 4782 (SIGMA, Detection); NjRAT/XWorm Pastebin Dead-Drop C2 Resolution (SIGMA, Detection); NjRAT/XWorm Spoofed Mobile Safari User-Agent (SURICATA, Hunting)
Detection rules Nov 2025 · 2 rules
Hybrid Loader/Stealer Ecosystem Masquerading as Sogou
SogouStealer C2 Scheduler and Signature-Database Components (YARA, Detection); SogouStealer CGI1 C2 URI Pattern (SURICATA, Hunting)
Detection rules Nov 2025 · 1 rule
Houselet.exe — The Go-Based Loader Masquerading as PlayStation Remote Play
HTTP POST to PHP Endpoint With Missing User-Agent (SIGMA, Hunting)

Tracked actors

Designations whose reports map this technique.

  • UTA-2026-001: Sliver C2 operator with an automated ScareCrow, Donut and SysWhispers3 build pipeline
  • UTA-2026-002: XiebroC2 and Covenant operator working from a Chinese-language build environment
  • UTA-2026-003: Commodity MaaS consumer running Shadow RAT and XWorm from one Windows VPS
  • UTA-2026-004: Developer of the OpenStrike multi-implant C2 toolkit, with a cracked Cobalt Strike arsenal
  • UTA-2026-005: Chaos ransomware builder user with a private five-stage crypter
  • UTA-2026-006: Stock AdaptixC2 operator with an operator-written PowerShell and .NET injection chain
  • UTA-2026-007: HijackLoader customer running a 15-month multi-vector phishing campaign into an AsyncRAT-class RAT
  • UTA-2026-008: Developer and operator of the BellaMain Turkish phishing-as-a-service panel
  • UTA-2026-009: Multi-product fraud operator pairing a real VPN service with a brand-impersonation phishing library
  • UTA-2026-010: Rhadamanthys MaaS customer with a self-built loader (customer side only, never the vendor)
  • UTA-2026-011: Financially motivated operator weaponising a cPanel authentication bypass with a custom harvesting toolkit
  • UTA-2026-012: AI-augmented credential-mill operator using an LLM for per-target password mutation
  • UTA-2026-013: Espionage-flavoured operator harvesting a state-affiliated insurer's observability stack through an AI agent platform
  • UTA-2026-014: DDoS-for-hire operator running an AI co-authored C2 framework over a Pandora-Mirai botnet
  • UTA-2026-019: Grey-market personal-data harvester running scores of LLM-assisted attack scripts against Chinese consumer platforms
  • UTA-2026-020: Self-branded commodity cryptojacking operator mass-exploiting exposed Chinese enterprise software
  • UTA-2026-023: Telecom-focused operator reaching a carrier's credential plane through a customer's managed router
  • UTA-2026-024: Windows post-exploitation intrusion set with Sliver and a blockchain-resolved implant

ATT&CK v19.2. MITRE ATT&CK® is a registered trademark of The MITRE Corporation; technique names are MITRE's and link to MITRE's own pages. The mapping on each linked page is this publication's reading of its own evidence.