MITRE ATT&CK Technique
T1102Web Service
- First Reported
- Sep 6, 2026
- Latest Reported
- Sep 6, 2026
Official Description
Adversaries may use an existing, legitimate external Web service as a means for relaying data to/from a compromised system. Popular websites, cloud services, and social media acting as a mechanism for C2 may give a significant amount of cover due to the likelihood that hosts within a network are already communicating with them prior to a compromise. Using common services, such as those offered by Google, Microsoft, or Twitter, makes it easier for adversaries to hide in expected noise.(Citation: Broadcom BirdyClient Microsoft Graph API 2024) Web service providers commonly use SSL/TLS encryption, giving adversaries an added level of protection.
Use of Web services may also protect back-end C2 infrastructure from discovery through malware binary analysis while also enabling operational resiliency (since this infrastructure may be dynamically changed).
Use of Web services may also protect back-end C2 infrastructure from discovery through malware binary analysis while also enabling operational resiliency (since this infrastructure may be dynamically changed).
- Tactics
- Command And Control
- Platforms
- ESXi, Linux, macOS, Windows
- MITRE Version
- 1.3
- Last Modified
- May 12, 2026
Sub-techniques (3)
Reported Context (1)
- The attack retrieves commands or payloads through GitHub Raw Content and, in one variant, Pastebin. Kimsuky-Linked Campaign Uses Malicious LNKs, GitHub PATs and AI-Generated Decoys
Threat Actors (1)
MITRE ATT&CK (11)
Vendors (3)
Products (4)
Tools (1)
Industries (2)
Countries (1)
Note: Related entities, including threat actors, malware, CVEs, MITRE ATT&CK techniques, vendors, products, tools, countries, and industries, are shown when they appear in the same reporting. Their presence does not necessarily mean they were targeted, compromised, vulnerable, responsible for the activity, or directly involved in the incident.