T1102.003 One-Way Communication

Adversaries may use an existing, legitimate external Web service as a means for sending commands to a compromised system without receiving return output over the Web service channel. Compromised systems may leverage popular websites and social media to host command and control (C2) instructions. Those infected systems may opt to send the output from those commands back over a different C2 channel, including to another distinct Web service. Alternatively, compromised systems may return no output at all in cases where adversaries want to send instructions to systems and do not want a response.

Popular websites and social media acting as a mechanism for C2 may give a significant amount of cover due to the likelihood that hosts within a network are already communicating with them prior to a compromise. Using common services, such as those offered by Google or Twitter, makes it easier for adversaries to hide in expected noise. Web service providers commonly use SSL/TLS encryption, giving adversaries an added level of protection.

View in MITRE ATT&CK®

CIS Controls Mappings

Capability ID Capability Description Mapping Type ATT&CK ID ATT&CK Name Notes
CIS-13.10 Perform Application Layer Filtering mitigates T1102.003 One-Way Communication
Comments
Application-layer filtering can block unauthorized web services used for one-way command-and-control communications.
References
CIS-13.8 Deploy a Network Intrusion Prevention Solution mitigates T1102.003 One-Way Communication
Comments
Network intrusion prevention solutions can use signatures for known adversary malware to block identifiable one-way command-and-control traffic using web services.
References
CIS-4.5 Implement and Manage a Firewall on End-User Devices mitigates T1102.003 One-Way Communication
Comments
Endpoint firewall policy can prevent malware from sending data or retrieving instructions through unauthorized web services. One-way traffic to an approved and commonly used service may be difficult to distinguish from legitimate activity through basic port filtering.
References
    CIS-9.3 Maintain and Enforce Network-Based URL Filters mitigates T1102.003 One-Way Communication
    Comments
    Popular websites and social media acting as a mechanism for C2 may give a significant amount of cover due to the likelihood that hosts within a network are already communicating with them prior to a compromise. Using common services, such as those offered by Google or Twitter, makes it easier for adversaries to hide in expected noise. 9.3 helps prevent link-based and web-based initial access by stopping users from reaching malicious or unapproved content. If 9.3 implementation includes outbound web-services used broadly enough to block unauthorized services and restrict access to unsafe websites, then this technique is defensible.
    References