Command and Control (C2)
Definition
The channel through which an attacker sends instructions to malware on a compromised host and receives data back. C2 channels range from direct TCP connections to domain-generation algorithm (DGA) traffic, DNS tunnelling, and traffic over legitimate platforms. Network logs recording C2 traffic are primary evidence in most malware investigations.
- Abbreviation
- C2, also written C&C
- Common channels
- Direct TCP/HTTPS, DNS tunnelling, DGA domains, legitimate platforms
- Evidence type
- Network logs, proxy logs, DNS query logs, firewall records
- Investigative use
- Identifies attacker infrastructure and timeline of compromise
Common questions
Why do attackers use domain-generation algorithms for C2?+
A DGA produces a large, changing set of candidate domains on a schedule known only to the attacker and the malware, so defenders cannot block C2 by blacklisting a single fixed domain, and takedown of any one registered domain has little effect.
How can investigators detect C2 traffic hidden in legitimate platforms?+
Analysts look for anomalies such as unusual API call patterns, beaconing intervals, or data volumes that do not match normal user behaviour on the platform, and correlate the timing with endpoint telemetry showing the malware process making the connection.
What happens once a C2 channel is identified during an investigation?+
The channel's indicators, such as destination IPs, domains, or JA3 fingerprints, are used to search historical logs for the full extent of communication and to identify other compromised hosts contacting the same infrastructure.
Related terms
- Credential Stuffing
- An automated attack that replays username-password pairs from previous data breaches against new target services, exploiting the widespread reuse of passwords across...
- Double Extortion
- A ransomware tactic in which the attacker exfiltrates data before encrypting it, then demands payment both for the decryption key and for...
- Dropper
- A malware component whose sole function is to deliver and install a secondary payload. The dropper itself may be a trojan, a...
- FAFT Virtual Asset Guidance
- Guidance from the Financial Action Task Force requiring member states to regulate virtual asset service providers (cryptocurrency exchanges) as financial institutions, applying...
- Image-Based Sexual Abuse (IBSA)
- The non-consensual creation, capture, or distribution of intimate sexual images. The term encompasses non-consensual intimate image sharing (formerly called revenge porn), upskirt...
- Payload
- The action the malware performs once active: data encryption (ransomware), credential theft (banking trojan), resource hijacking (cryptominer), or system destruction (wiper). The...
- Persistence Mechanism
- The technique malware uses to survive a reboot or user logout. Common methods include registry run keys, scheduled tasks, Windows services, cron...
- Propagation Mechanism
- The method by which malware copies itself to new hosts. Viruses attach to host files; worms exploit network services autonomously; trojans rely...
- Rootkit
- Malware designed to hide its own presence by subverting the operating system's reporting functions. User-mode rootkits hook API calls; kernel-mode rootkits modify...
- Synthetic Identity Fraud
- The creation of a fictitious identity by combining real and fabricated personal data elements, such as a genuine national ID number paired...
Explained in these topics
- Malware Taxonomy: Viruses, Trojans, Ransomware and More
- Ransomware, Identity Theft and Online ExploitationInfrastructure used by threat actors to issue instructions to compromised systems and receive exfiltrated data. In ransomware operations, C2 channels are typic...