TACTIC: COMMAND AND CONTROL
Web Protocols (T1071.001): real cases
MITRE Definition ↗ Adversaries communicate using standard HTTP and HTTPS web protocols to blend with regular traffic.
Key Facts
Technique ID
T1071.001
Command and Control
Mapped Cases
1
Primary sources
Related Laws
4
Criminal statutes
- ATT&CK Technique Identifier: T1071.001.
- Tactical Phase: Command and Control.
- Substantiated in 1 primary court prosecution cases.
- Every associated case includes verbatim evidentiary excerpts from indictments or sworn affidavits.
Verified Evidentiary Case Records
SolarWinds Orion Supply Chain Intrusion (APT29 / SVR)
alleged 2020-12-13
Primary Source Evidence Excerpt: CISA Advisory AA20-352A ¶ 14
"The backdoor communicated with adversary command and control servers via HTTP requests designed to mimic legitimate SolarWinds Orion communication protocols."
U.S. District Court for the Southern District of New York
View full case dossier →
Commonly Charged Criminal Statutes
18 U.S.C. § 1030(a)(2)
Unauthorized Access to Obtain Protected Information
Prohibits intentionally accessing a computer without authorization or exceeding authorized access to obtain financial, government, or protected computer records.
18 U.S.C. § 1030(a)(5)(A)
Intentional Damage to a Protected Computer
Prohibits knowingly causing the transmission of a program, information, code, or command that intentionally causes damage without authorization to a protected computer.
18 U.S.C. § 1030(a)(7)
Extortion in Connection with Computers
Prohibits transmitting in interstate or foreign commerce threats to cause damage to a protected computer or obtain confidential information with intent to extort money or value.
18 U.S.C. § 1030(b)
Conspiracy to Commit Computer Fraud
Punishes any person who conspires to commit or attempts to commit any computer fraud offense under section 1030.