logo

Instant Messaging-Based Adversarial C2 Techniques and How to Detect Them

ID: 6d05d339-11ba-56ca-a0cd-60d90fc5f3ef

STIX ID: report--6d05d339-11ba-56ca-a0cd-60d90fc5f3ef

Feed Name: Dragos Blog

Threat Score
60/100

Date Published: 2023-03-02

Date Updated: 2026-04-27

...
...

This report explains how threat actors use Telegram and Discord APIs as covert C2 channels, the detection challenges they present, common indicators such as API endpoint connections, external IP lookup calls, unusual HTTP User-Agents, and suspicious process behaviors, and recommends behavioral-based detection and process monitoring to identify such abuse.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.