MITRE ATT&CK Technique
T1001.003Protocol or Service Impersonation
- First Reported
- May 5, 2026
- Latest Reported
- May 5, 2026
Official Description
Adversaries may impersonate legitimate protocols or web service traffic to disguise command and control activity and thwart analysis efforts. By impersonating legitimate protocols or web services, adversaries can make their command and control traffic blend in with legitimate network traffic.
Adversaries may impersonate a fake SSL/TLS handshake to make it look like subsequent traffic is SSL/TLS encrypted, potentially interfering with some security tooling, or to make the traffic look like it is related with a trusted entity.
Adversaries may also leverage legitimate protocols to impersonate expected web traffic or trusted services. For example, adversaries may manipulate HTTP headers, URI endpoints, SSL certificates, and transmitted data to disguise C2 communications or mimic legitimate services such as Gmail, Google Drive, and Yahoo Messenger.(Citation: ESET Okrum July 2019)(Citation: Malleable-C2-U42)
Adversaries may impersonate a fake SSL/TLS handshake to make it look like subsequent traffic is SSL/TLS encrypted, potentially interfering with some security tooling, or to make the traffic look like it is related with a trusted entity.
Adversaries may also leverage legitimate protocols to impersonate expected web traffic or trusted services. For example, adversaries may manipulate HTTP headers, URI endpoints, SSL certificates, and transmitted data to disguise C2 communications or mimic legitimate services such as Gmail, Google Drive, and Yahoo Messenger.(Citation: ESET Okrum July 2019)(Citation: Malleable-C2-U42)
- Tactics
- Command And Control
- Platforms
- ESXi, Linux, macOS, Windows
- Parent Technique
- T1001 · Data Obfuscation
- MITRE Version
- 2.1
- Last Modified
- May 12, 2026
Reported Context (1)
- Beacon exfiltration traffic spoofs a Chrome User-Agent, although polling retains a native PowerShell WebClient identifier. Investigation Details Intrusion Targeting 12 Omani Government Entities, With 26,000 Records Extracted
CVE (4)
Threat Actors (3)
MITRE ATT&CK (21)
Vendors (4)
Products (10)
Tools (4)
Industries (1)
Countries (4)
Note: Related entities, including threat actors, malware, CVEs, MITRE ATT&CK techniques, vendors, products, tools, countries, and industries, are shown when they appear in the same reporting. Their presence does not necessarily mean they were targeted, compromised, vulnerable, responsible for the activity, or directly involved in the incident.