MITRE ATT&CK Technique
T1008Fallback Channels
- First Reported
- Apr 29, 2026
- Latest Reported
- Sep 24, 2026
Official Description
Adversaries may use fallback or alternate communication channels if the primary channel is compromised or inaccessible in order to maintain reliable command and control and to avoid data transfer thresholds.
- Tactics
- Command And Control
- Platforms
- ESXi, Linux, macOS, Windows
- MITRE Version
- 1.1
- Last Modified
- May 12, 2026
Reported Context (2)
- If its hardcoded C2 server was unavailable, SectopRAT queried backup URLs for an alternative C2 IP address. Fortinet Details SectopRAT Hidden in Legitimate Windows Software
- Failure of outbound C2 causes the bot to expose an inbound SOCKS5-like listener with the same command dispatcher. Operator’s Debug Build Exposes xlabs_v1 DDoS-for-Hire Botnet
Malware (6)
People (1)
Threat Actors (1)
MITRE ATT&CK (28)
Vendors (7)
Products (11)
Tools (7)
Countries (2)
Note: Related entities, including threat actors, malware, CVEs, MITRE ATT&CK techniques, vendors, products, tools, countries, and industries, are shown when they appear in the same reporting. Their presence does not necessarily mean they were targeted, compromised, vulnerable, responsible for the activity, or directly involved in the incident.