Instant Messaging-Based Adversarial C2 Techniques and How to Detect Them
ID: 6d05d339-11ba-56ca-a0cd-60d90fc5f3ef
STIX ID: report--6d05d339-11ba-56ca-a0cd-60d90fc5f3ef
Feed Name: Dragos Blog
Threat Score
This report explains how threat actors use Telegram and Discord APIs as covert C2 channels, the detection challenges they present, common indicators such as API endpoint connections, external IP lookup calls, unusual HTTP User-Agents, and suspicious process behaviors, and recommends behavioral-based detection and process monitoring to identify such abuse.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
