Command & Control
Command and control communication involves establishing a persistent channel between the attacker and the compromised system for sending commands and receiving results. The attacker uses this channel to manage malware, launch new attack phases, and retrieve data.
Term
description · examples · notesCommand and control communication involves establishing a persistent channel between the attacker and the compromised system for sending commands and receiving results. The attacker uses this channel to manage malware, launch new attack phases, and retrieve data.
Description
Communication is often disguised to resemble normal network traffic, using standard protocols, encryption, and legitimate services as intermediaries.
Examples
- Malware periodically contacting a command server via encrypted HTTP requests
- Using DNS queries to transfer commands and data in small segments
- Communication through a legitimate messaging platform or cloud service
- Decentralized communication via a peer-to-peer network
Notes
- Analysis of unusual DNS patterns and encrypted connections to unknown destinations can reveal command and control communication.
Mentioned in the news
- 18. APR 2026. Hunt.io mapirao više od 1.250 C2 servera kod ruskih hosting provajdera →
- 24. APR 2026. GopherWhisper cilja mongolske državne sisteme Go backdoor alatima →
- 22. APR 2026. SystemBC otkrio više od 1.570 žrtava povezanih sa Gentlemen ransomware grupom →
- 13. MAR 2026. APT36 koristi AI za masovnu proizvodnju malvera (Vibeware) →
Threats
used by 12Threats that use it. Select one to open its page.
Defenses
countered by 12How it is countered. Select one to open its page.