logo

Azure ServiceBus WebSockets as a C2 Channel

ID: b26cee5b-b029-5e0d-bc73-556a77bfa792

STIX ID: report--b26cee5b-b029-5e0d-bc73-556a77bfa792

Feed Name: LevelBlue SpiderLabs Blog

Threat Score
70/100

Date Published: 2026-03-24

Date Updated: 2026-04-28

Author: Stuart White

...
...

This report demonstrates how to modify Cobalt Strike's CobaltBus to use Azure Service Bus over WebSockets (AmqpWebSockets) so C2 traffic travels over HTTPS (port 443) instead of TCP/5671, allowing beacons to bypass firewall rules that block nonstandard outbound ports; it includes code snippets, a lab walkthrough, traffic captures, and defensive detection recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.