T1071.001 · command-and-control · 53 actors · 17 correlated reports

Web Protocols

Adversaries may communicate using application layer protocols associated with web traffic to avoid detection/network filtering by blending in with existing traffic. Commands to the remote system, and often the results of those commands, will be embedded within the protocol traffic between the client and server. Protocols such as HTTP/S and WebSocket that carry web traffic may be very common in environments. HTTP/S packets have many fields and headers in which data can be concealed. An adversary may abuse these protocols to communicate with systems under their control within a victim network while also mimicking normal, expected traffic.

Open detection, hunting, mitigation, and evidence workspace

Detection logic

Analyze network data for uncommon data flows (e.g., a client sending significantly more data than it receives from a server). Processes utilizing the network that do not normally have network communication or have never been seen before are suspicious. Analyze packet contents to detect application layer protocols that do not follow the expected protocol standards regarding syntax, structure, or any other variable adversaries could leverage to conceal data. Monitor for web traffic to/from known-bad or suspicious domains.

Observed actors

Correlated CTI and IR reports

Bad Karma No Justice: Void Manticore Destructive Activities in Israel
Check Point Research · direct source mapping
APT39 (Chafer / Remix Kitten)
Israel Threat Actors CTI · explicit report mention
APT41 Targeting Pharmaceutical Sector: Log4Shell to Domain Compromise
1200km CTI repository · explicit report mention
ATT&CK as a Working Tool: Theory and Hands-On Practical Usage
1200km CTI repository · explicit report mention
CTI Research: MuddyWater / Seedworm (Mango Sandstorm)
1200km CTI repository · explicit report mention
CTI Research: MuddyWater / Seedworm (Mango Sandstorm)
1200km CTI repository · explicit report mention
CTI Research: Sandworm / APT44
1200km CTI repository · explicit report mention
CTI Research: Sandworm / APT44
1200km CTI repository · explicit report mention
Executive Summary
Israel Threat Actors CTI · explicit report mention
From Threat Intelligence to Detection: A Practitioner's Guide
1200km CTI repository · explicit report mention
IOC Tables — MuddyWater / Seedworm (Mango Sandstorm)
1200km CTI repository · explicit report mention
Operation DragonRx — APT41 Full Attack Simulation
1200km CTI repository · explicit report mention
Operation DragonRx: Simulating an APT41 Attack End-to-End — From Log4Shell to DFIR and Malware Analysis
1200km CTI repository · explicit report mention
ATT CK as a Working Tool Theory and Hands On Practical Usage
1200km Medium · authored report mention
CTI Research MuddyWater Seedworm Mango Sandstorm
1200km Medium · authored report mention
CTI Research Sandworm APT44
1200km Medium · authored report mention
From Threat Intelligence to Detection A Practitioner s Guide
1200km Medium · authored report mention

Continue the investigation