LDAPFragger: Command and Control over LDAP attributes
ID: 3668c5f8-a281-5638-b21d-06cef882bd61
STIX ID: report--3668c5f8-a281-5638-b21d-06cef882bd61
Feed Name: Fox-IT blog
Threat Score
This blogpost documents LDAPFrag, an open-source method and tool that routes Cobalt Strike C2 traffic over Active Directory by abusing writable personal-information attributes as a covert data store. It covers attribute enumeration and selection, hashing to share attribute and domain-controller choices, fragmentation and CRC checks for reliable transfer, autodiscovery to bootstrap C2 parameters, and mitigation guidance to detect or limit such LDAP-based channels.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
