Gold Open Source
ExplorePackagesVulnerabilitiesCWEsMCP ServersScan
Login
Gold Open Source

The authoritative source for production-ready open-source components. Every package, container image, AI model, and MCP server undergoes rigorous verification for security, malware, and license compliance.

Explore Gold

  • Explore Everything
  • Packages
  • Gold Certified Packages
  • Container Images
  • AI Models
  • MCP Servers
  • Agent Skills
  • Chip Manufacturers

Security Data & Tools

  • Scan Your Dependencies
  • Trending Threats
  • Threat RSS Feeds
  • CVE Database
  • Actively Exploited (KEV)
  • SGZ Zero-Days
  • CWE Index
  • MITRE ATT&CK
  • Malicious Packages
  • Security Glossary
  • Supply-Chain Report
  • Developers (API & Badge)
  • Chrome Extension
  • Credits & Data Sources

Products

  • The Platform
  • ESSCM
  • Portal
  • TPRM
  • OSM
  • Cowork
  • Code / Runner
  • Guard

Use Cases

  • Know Your Software
  • Auto-Fix Vulnerabilities
  • Asset Discovery
  • AI Governance
  • MCP Server Security
  • Supply Chain Compliance
  • Zero-Day Discovery
  • All Use Cases

Company

  • About
  • Pricing
  • Blog
  • Documentation
  • Safeguard Academy
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 Gold Open Source. All rights reserved.

Built with care bySafeguard
Home/ATT&CK/T1041
MITRE ATT&CK Technique

T1041: Exfiltration Over C2 Channel

ShareXLinkedInRedditHN

Adversaries may steal data by exfiltrating it over an existing command and control channel. Stolen data is encoded into the normal communications channel using the same protocol as command and control communications.

Tactics
Exfiltration
Platforms
ESXi, Linux, macOS, Windows

▪Mitigations (2)

M1031Network Intrusion Prevention

Use intrusion detection signatures to block traffic at network boundaries.

M1057Data Loss Prevention

Data Loss Prevention (DLP) involves implementing strategies and technologies to identify, categorize, monitor, and control the movement of sensitive data within an organization. This includes protecting data formats indicative of Personally Identifiable Information (PII), intellectual property, or financial data from unauthorized access, transmission, or exfiltration. DLP solutions integrate with network, endpoint, and cloud platforms to enforce security policies and prevent accidental or malicious data leaks. (Citation: PurpleSec Data Loss Prevention) This mitigation can be implemented through the following measures: Sensitive Data Categorization: - Use Case: Identify and classify data based on sensitivity (e.g., PII, financial data, trade secrets). - Implementation: Use DLP solutions to scan and tag files containing sensitive information using predefined patterns, such as Social Security Numbers or credit card details. Exfiltration Restrictions: - Use Case: Prevent unauthorized transmission of sensitive data. - Implementation: Enforce policies to block unapproved email attachments, unauthorized USB usage, or unencrypted data uploads to cloud storage. Data-in-Transit Monitoring: - Use Case: Detect and prevent the transmission of sensitive data over unapproved channels. - Implementation: Deploy network-based DLP tools to inspect outbound traffic for sensitive content (e.g., financial records or PII) and block unapproved transmissions. Endpoint Data Protection: - Use Case: Monitor and control sensitive data usage on endpoints. - Implementation: Use endpoint-based DLP agents to block copy-paste actions of sensitive data and unauthorized printing or file sharing. Cloud Data Security: - Use Case: Protect data stored in cloud platforms. - Implementation: Integrate DLP with cloud storage platforms like Google Drive, OneDrive, or AWS to monitor and restrict sensitive data sharing or downloads.

▪Used by groups (27)

G0004Ke3changG0022APT3G0032Lazarus GroupG0034Sandworm TeamG0038Stealth FalconG0047Gamaredon GroupG0050APT32G0065LeviathanG0069MuddyWaterG0087APT39G0090WIRTEG0093GALLIUMG0094KimsukyG0102Wizard SpiderG0114ChimeraG0126HigaisaG0128ZIRCONIUMG0129Mustang PandaG0142ConfuciusG1012CURIUMG1014LuminousMothG1015Scattered SpiderG1030AgriusG1035Winter VivernG1043BlackByteG1052Contagious InterviewG1055VOID MANTICORE

▪Software using this technique (164)

S0013PlugXmalwareS0024DyremalwareS0031BACKSPACEmalwareS0034NETEAGLEmalwareS0045ADVSTORESHELLmalwareS0062DustySkymalwareS0077CallMemalwareS0078PsylomalwareS0079MobileOrdermalwareS0083MisdatmalwareS0084Mis-TypemalwareS0085S-TypemalwareS0086ZLibmalwareS0115CrimsonmalwareS0147PteranodonmalwareS0192PupytoolS0234BandookmalwareS0238ProxysvcmalwareS0239BankshotmalwareS0240ROKRATmalwareS0251ZebrocymalwareS0264OopsIEmalwareS0266TrickBotmalwareS0268BisonalmalwareS0340OctopusmalwareS0351CannonmalwareS0356KONNImalwareS0363EmpiretoolS0367EmotetmalwareS0373AstarothmalwareS0375RemeximalwareS0376HOPLIGHTmalwareS0377EburymalwareS0381FlawedAmmyymalwareS0385njRATmalwareS0386UrsnifmalwareS0391HAWKBALLmalwareS0395LightNeuronmalwareS0409MachetemalwareS0428PoetRATmalwareS0431HotCroissantmalwareS0434Imminent MonitortoolS0438AttormalwareS0439OkrummalwareS0441PowerShowermalwareS0445ShimRatReportertoolS0447LokibotmalwareS0448Rising SunmalwareS0455MetamorfomalwareS0459MechaFloundermalwareS0461SDBbotmalwareS0467TajMahalmalwareS0476ValakmalwareS0477GoopymalwareS0484CarberpmalwareS0487KesselmalwareS0491StrongPitymalwareS0493GoldenSpymalwareS0495RDATmalwareS0496REvilmalwareS0502DrovorubmalwareS0520BLINDINGCANmalwareS0526KGH_SPYmalwareS0531GrandoreiromalwareS0533SLOTHFULMEDIAmalwareS0538CrutchmalwareS0543SparkmalwareS0568EVILNUMmalwareS0572Caterpillar WebShellmalwareS0584AppleJeusmalwareS0587PenquinmalwareS0588GoldMaxmalwareS0595ThiefQuestmalwareS0600DokimalwareS0603StuxnetmalwareS0604IndustroyermalwareS0610SideTwistmalwareS0615SombRATmalwareS0622AppleSeedmalwareS0632GrimAgentmalwareS0633SlivertoolS0649SMOKEDHAMmalwareS0650QakBotmalwareS0651BoxCaonmalwareS0652MarkiRATmalwareS0657BLUELIGHTmalwareS0658XCSSETmalwareS0661FoggyWebmalwareS0663SysUpdatemalwareS0667ChrommmemalwareS0670WarzoneRATmalwareS0671TomirismalwareS0674CharmPowermalwareS0678TorismamalwareS0680LitePowermalwareS0687Cyclops BlinkmalwareS0692SILENTTRINITYtoolS0696FlagpromalwareS1016MacMamalwareS1017OutSteelmalwareS1019SharkmalwareS1020KevinmalwareS1021DnsSystemmalwareS1022IceApplemalwareS1024CreepySnailmalwareS1025AmadeymalwareS1026MongallmalwareS1029AuTo StealermalwareS1030SquirrelwafflemalwareS1031PingPullmalwareS1034StrifeWatermalwareS1037STARWHALEmalwareS1039BumblebeemalwareS1042SUGARDUMPmalwareS1044FunnyDreammalwareS1050PcSharetoolS1059metaMainmalwareS1060MafaldamalwareS1064SVCReadymalwareS1065Woody RATmalwareS1075KOPILUWAKmalwareS1078RotaJakiromalwareS1081BADHATCHmalwareS1089SharpDiscomalwareS1090NightClubmalwareS1111DarkGatemalwareS1122MispadumalwareS1132IPsec HelpermalwareS1142LunarMailmalwareS1145PikabotmalwareS1148Raccoon StealermalwareS1149CHIMNEYSWEEPmalwareS1153Cuckoo StealermalwareS1156ManjusakamalwareS1159DUSTTRAPmalwareS1160LatrodectusmalwareS1166SolarmalwareS1169MangomalwareS1170ODAgentmalwareS1172OilBoostermalwareS1173PowerExchangemalwareS1178ShrinkLockermalwareS1182MagicRATmalwareS1183StrelaStealermalwareS1185LightSpymalwareS1186Line DancermalwareS1188Line RunnermalwareS1196Troll StealermalwareS1201TRANSLATEXTmalwareS1210SagerunexmalwareS1213Lumma StealermalwareS1240RedLine StealermalwareS1245InvisibleFerretmalwareS1246BeaverTailmalwareS1248XORIndex LoadermalwareS1249HexEval LoadermalwareS9007HTTPTroymalwareS9008Shai-HuludmalwareS9014PHASEJAMmalwareS9015BRICKSTORMmalwareS9020LODEINFOmalwareS9031AshTagmalwareS9032MuddyVipermalwareS9035LAMEHUGmalware

▪Reference

T1041on MITRE ATT&CK

MITRE ATT&CK® is a registered trademark of The MITRE Corporation. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.