Applied Cybernetics Group
T1041 — Exfiltration Over C2 Channel
- Technique
T1041- Tactics
- Exfiltration
- MISP citations
- 0
- KEV CVEs mapped
- 12
- Community rules
- 5
- thrunt rules
- 0
- Upstream
- https://attack.mitre.org/techniques/T1041
MITRE description
Adversaries may steal data by exfiltrating it over an existing command and control channel. Stolen data is encoded into the normal communications channel using the same protocol as command and control communications.
KEV CVEs mapped to this technique
Per MITRE CTID's hand-curated KEV→ATT&CK mappings — these are the actively-exploited vulnerabilities behind this technique's KEV signal.
CVE-2025-33053CVE-2025-32756CVE-2024-55550CVE-2024-4577CVE-2024-27443CVE-2023-5631CVE-2023-38831CVE-2023-2868CVE-2023-1389CVE-2019-18935CVE-2019-0604CVE-2018-4878
Detection coverage
SigmaHQ community rules
- Equation Group C2 Communication (emerging-threats)
- Shai-Hulud NPM Package Malicious Exfiltration via Curl (emerging-threats)
- Tunneling Tool Execution (threat-hunting)
- OpenCanary - TFTP Request (core)
- Network Communication Initiated To Portmap.IO Domain (core)