T1646: Exfiltration Over C2 Channel
Essential information
- MITRE technique ID
T1646- Confidence
- 100/100
- Revoked
- No
- Published
- 01/04/2022 17:43
- Modified
- 27/03/2026 01:41
- Author / Source
- The MITRE Corporation
Platforms
android iOS
Description
Adversaries may steal data by exfiltrating it over an existing command and control channel. Stolen data is encoded into the normal communications channel using the same protocol as command and control communications.
Kill chain phases
| Kill chain | Phase |
|---|---|
| mitre-mobile-attack | exfiltration |
Marking (TLP)
Copyright 2015-2025, The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation.