MITRE ATT&CK Technique
T1041Exfiltration Over C2 Channel
- First Reported
- Aug 3, 2026
- Latest Reported
- Oct 1, 2026
Official Description
Adversaries may steal data by exfiltrating it over an existing command and control channel. Stolen data is encoded into the normal communications channel using the same protocol as command and control communications.
- Tactics
- Exfiltration
- Platforms
- ESXi, Linux, macOS, Windows
- MITRE Version
- 2.3
- Last Modified
- May 12, 2026
Reported Context (5)
- Packet captures showed Remus exfiltrating through multipart POST requests to its C2 server. CIS Links SLTT Remus C2 Traffic to Three Malware Delivery Chains
- The components submitted collected findings, including recovered plaintext credentials, to their tasking and reporting hub through /v1/ingest or /api/crack/report. TIKTOUK Toolkit Collects WordPress, Email, and Cloud Credentials
- The article states that Remcos RAT transmits collected information and execution results through communication with its C2 server. Phishing Emails Use Fake Purchase Requests to Deliver Remcos RAT
- Remcos RAT transmits collected information and execution results through communication with its C2 server. Phishing Quote Requests Deliver Remcos RAT via Obfuscated PowerShell
- The stealer sent collected wallet tokens, account data, and surveillance output to its C2 server. Fake Roblox Xeno Cheats Deliver Java Stealer Through Discord and Forums
CVE (3)
Malware (5)
Threat Actors (3)
MITRE ATT&CK (32)
Vendors (1)
Products (20)
Tools (13)
Industries (2)
Countries (2)
Note: Related entities, including threat actors, malware, CVEs, MITRE ATT&CK techniques, vendors, products, tools, countries, and industries, are shown when they appear in the same reporting. Their presence does not necessarily mean they were targeted, compromised, vulnerable, responsible for the activity, or directly involved in the incident.