logo

LDAPFragger: Command and Control over LDAP attributes

ID: 3668c5f8-a281-5638-b21d-06cef882bd61

STIX ID: report--3668c5f8-a281-5638-b21d-06cef882bd61

Feed Name: Fox-IT blog

Threat Score
70/100

Date Published: 2020-03-19

Date Updated: 2026-04-27

...
...

This blogpost documents LDAPFrag, an open-source method and tool that routes Cobalt Strike C2 traffic over Active Directory by abusing writable personal-information attributes as a covert data store. It covers attribute enumeration and selection, hashing to share attribute and domain-controller choices, fragmentation and CRC checks for reliable transfer, autodiscovery to bootstrap C2 parameters, and mitigation guidance to detect or limit such LDAP-based channels.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.