216.73.216.226

T1646: Exfiltration Over C2 Channel

View on MITRE ATT&CK The MITRE Corporation · Published 01/04/2022 17:43 · Modified 27/03/2026 01:41

Essential information

MITRE technique ID
T1646
Confidence
100/100
Revoked
No
Published
01/04/2022 17:43
Modified
27/03/2026 01:41
Author / Source
The MITRE Corporation

Platforms

android iOS

Description

Adversaries may steal data by exfiltrating it over an existing command and control channel. Stolen data is encoded into the normal communications channel using the same protocol as command and control communications.

Kill chain phases

Kill chainPhase
mitre-mobile-attack exfiltration

Marking (TLP)

Copyright 2015-2025, The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation.

External references