MITRE ATT&CK Technique
T1102.001Dead Drop Resolver
- First Reported
- Sep 8, 2026
- Latest Reported
- Oct 1, 2026
Official Description
Adversaries may use an existing, legitimate external Web service to host information that points to additional command and control (C2) infrastructure. Adversaries may post content, known as a dead drop resolver, on Web services with embedded (and often obfuscated/encoded) domains or IP addresses. Once infected, victims will reach out to and be redirected by these resolvers.
Popular websites and social media acting as a mechanism for C2 may give a significant amount of cover due to the likelihood that hosts within a network are already communicating with them prior to a compromise. Using common services, such as those offered by Google or Twitter, makes it easier for adversaries to hide in expected noise. Web service providers commonly use SSL/TLS encryption, giving adversaries an added level of protection.
Use of a dead drop resolver may also protect back-end C2 infrastructure from discovery through malware binary analysis while also enabling operational resiliency (since this infrastructure may be dynamically changed).
Popular websites and social media acting as a mechanism for C2 may give a significant amount of cover due to the likelihood that hosts within a network are already communicating with them prior to a compromise. Using common services, such as those offered by Google or Twitter, makes it easier for adversaries to hide in expected noise. Web service providers commonly use SSL/TLS encryption, giving adversaries an added level of protection.
Use of a dead drop resolver may also protect back-end C2 infrastructure from discovery through malware binary analysis while also enabling operational resiliency (since this infrastructure may be dynamically changed).
- Tactics
- Command And Control
- Platforms
- ESXi, Linux, macOS, Windows
- Parent Technique
- T1102 · Web Service
- MITRE Version
- 1.1
- Last Modified
- May 12, 2026
Reported Context (3)
- When enabled, Remus queried an Ethereum smart contract through an RPC service to obtain a live C2 domain and port. CIS Links SLTT Remus C2 Traffic to Three Malware Delivery Chains
- TerminalFix obtains its final C2 list from a public forum profile. September 2026 Cyber Campaigns Target US and EU With Session Theft, Phishing and Payment Fraud
- Amatera resolved a C2 IP address from a Telegraph page, while ZigCryptoStealer obtained a C2 domain from a BNB Smart Chain contract. ClearFake WebDAV Chains Deliver Amatera, ZigCryptoStealer and Unauthorized NetSupport
Malware (10)
Threat Actors (4)
MITRE ATT&CK (26)
Vendors (4)
Products (20)
Tools (11)
Industries (6)
Countries (9)
Note: Related entities, including threat actors, malware, CVEs, MITRE ATT&CK techniques, vendors, products, tools, countries, and industries, are shown when they appear in the same reporting. Their presence does not necessarily mean they were targeted, compromised, vulnerable, responsible for the activity, or directly involved in the incident.