216.73.217.22

T1001.003: T1001.003

View on MITRE ATT&CK The MITRE Corporation · Published 16/12/2025 19:38 · Modified 05/05/2026 18:07

Essential information

MITRE technique ID
T1001.003
Confidence
100/100
Revoked
No
Published
16/12/2025 19:38
Modified
05/05/2026 18:07
Author / Source
The MITRE Corporation

Aliases

Protocol or Service Impersonation

Platforms

windows macos linux ESXi

Description

Adversaries may impersonate legitimate protocols or web service traffic to disguise command and control activity and thwart analysis efforts. By impersonating legitimate protocols or web services, adversaries can make their command and control traffic blend in with legitimate network traffic. Adversaries may impersonate a fake SSL/TLS handshake to make it look like subsequent traffic is SSL/TLS encrypted, potentially interfering with some security tooling, or to make the traffic look like it is related with a trusted entity. Adversaries may also leverage legitimate protocols to impersonate expected web traffic or trusted services. For example, adversaries may manipulate HTTP headers, URI endpoints, SSL certificates, and transmitted data to disguise C2 communications or mimic legitimate services such as Gmail, Google Drive, and Yahoo Messenger.(Citation: ESET Okrum July 2019)(Citation: Malleable-C2-U42)

Kill chain phases

Kill chainPhase
mitre-attack command-and-control

Marking (TLP)

TLP:CLEAR Copyright 2015-2025, The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation.

External references