MITRE ATT&CK Technique
T1071.001Web Protocols
- First Reported
- Apr 8, 2026
- Latest Reported
- Oct 1, 2026
Official Description
Adversaries may communicate using application layer protocols associated with web traffic to avoid detection/network filtering by blending in with existing traffic. Commands to the remote system, and often the results of those commands, will be embedded within the protocol traffic between the client and server.
Protocols such as HTTP/S(Citation: CrowdStrike Putter Panda) and WebSocket(Citation: Brazking-Websockets) that carry web traffic may be very common in environments. HTTP/S packets have many fields and headers in which data can be concealed. An adversary may abuse these protocols to communicate with systems under their control within a victim network while also mimicking normal, expected traffic.
Protocols such as HTTP/S(Citation: CrowdStrike Putter Panda) and WebSocket(Citation: Brazking-Websockets) that carry web traffic may be very common in environments. HTTP/S packets have many fields and headers in which data can be concealed. An adversary may abuse these protocols to communicate with systems under their control within a victim network while also mimicking normal, expected traffic.
- Tactics
- Command And Control
- Platforms
- ESXi, Linux, macOS, Network Devices, Windows
- Parent Technique
- T1071 · Application Layer Protocol
- MITRE Version
- 1.5
- Last Modified
- May 12, 2026
Reported Context (15)
- Remus registered with C2 over HTTP on non-standard ports and used HTTP POST requests in its C2 communications. CIS Links SLTT Remus C2 Traffic to Three Malware Delivery Chains
- Infected machines poll web-based /api/machine/* gate paths for commands and injection configuration. Underground Malware Operation Drains About $100,000 in Cryptocurrency
- 2CLoader sends registration and execution-status messages to its C2 server in HTTP POST requests. 2CLoader Malware Loader Uses Evasion and Injection to Deliver Vidar and Remus
- The AdaptixC2 implant used HTTP for command-and-control check-ins and encrypted communications. PaperCut Zero-Days Used to Deploy AdaptixC2 and Compromise an Education Customer’s Domain
- The installed web shell received .NET payloads through HTTP requests and returned execution results in HTTP responses. Attackers Exploit Telerik CVE-2019-18935 to Install Web Shells and Scan for Exposed WordPress Pages
CVE (3)
Malware (29)
Threat Actors (16)
MITRE ATT&CK (69)
Vendors (18)
Products (56)
Tools (36)
Industries (16)
Countries (25)
Note: Related entities, including threat actors, malware, CVEs, MITRE ATT&CK techniques, vendors, products, tools, countries, and industries, are shown when they appear in the same reporting. Their presence does not necessarily mean they were targeted, compromised, vulnerable, responsible for the activity, or directly involved in the incident.