
Command and Control servers, more commonly referred to as C2 or C&C, are a cornerstone of cybercriminals' arsenal. These servers facilitate nearly invisible communication with compromised devices within a targeted network, playing a crucial role in the remote management of digital attacks. Their ability to discreetly transmit commands and orchestrate data theft positions C2 servers as sophisticated and dangerously effective attack vectors.
Nowadays, all malware that penetrates a network by various means (phishing, brute force credential attacks, or credential theft) makes callbacks to a C2 server to receive instructions, download additional components, or exfiltrate data.
In the MITRE ATT&CK framework, the involvement of C2 servers at different stages of the attack is one of the most common strategies.
What are the extended features of C2 servers:
Orchestration of complex attacks:
C2 servers are not limited to coordinating simple phishing attacks. They orchestrate large-scale malicious campaigns, exploiting systemic and human vulnerabilities to infiltrate and compromise networks. These attacks can be diverse, ranging from deploying ransomware to conducting industrial espionage, demonstrating their versatility and dangerousness. In the case of a DDoS (or Distributed Denial of Service) attack, C2 servers act as the conductor or mastermind for the machines that are part of the zombie network.
Transmission of targeted orders:
The sophistication of C2 servers allows them to transmit specific commands to infected devices, orchestrating actions that go far beyond simple information gathering. They can modify system configurations, deploy additional malicious software, or even take complete control of devices for malicious purposes.
Remote Updates and Maintenance: In addition to distributing malware, C2 servers can send updates to existing malware, increasing its effectiveness or further camouflaging it from antivirus software. This ability to maintain and update infections remotely makes C2 servers particularly formidable.
Advanced camouflage techniques:
C2 servers use sophisticated methods to remain undetectable, including the use of advanced encryption techniques and anonymous networks. This invisibility allows attackers to remain active in a targeted network for long periods of time, collecting data and executing commands without being detected. Finally, these servers can regularly change domains and IP addresses, making them difficult to detect.
Some examples:
The CustomerLoader malware uses C2 servers to download advanced compromise payloads.
The StealC infostealer generates the URLs of its C2 servers in a completely random and continuous manner, making them very difficult to track.
Statistics and trends:
At this time, we cannot confirm the number of active servers, however the website https://urlhaus.abuse.ch/browse/page/2/ lists nearly 3 million malicious URLs. The constant evolution of C2 servers and their ability to frequently change domains highlight an alarming reality: cybercrime is constantly changing, making the task of defense all the more complex. The available statistics, although representing only a fraction of the actual scale of the problem, clearly indicate that there are millions of malicious URLs, with each C2 server having the potential to infect and control hundreds, if not thousands, of devices.
According to Akamai, between 10 and 15% of companies in 2022 had web traffic linked to communication with C2 servers.

Nevertheless, this number of infected machines allows us to gauge the scale of a threat, so it should not be overlooked in the event of attacks.
To detect early signs of an attack involving calls to C2 servers, it is important to monitor network traffic, as the volume and destination of network traffic generated by infected machines and directed to the Command & Control server can be significant. This unusual traffic can be used to identify and detect malicious activity.
Most serious malware today is executed via Command & Control servers. However, there are various frameworks that enable organizations to understand attackers' methods in order to be as responsive as possible.
Proactive defense against C2 servers:
Faced with this insidious threat, network traffic monitoring proves to be an essential first line of defense. Identifying abnormal communications with C2 servers enables early detection of infections. The MITRE ATT&CK framework and other strategic tools provide organizations with the means to understand adversaries' tactics and develop appropriate responses to protect their critical infrastructure.
If our peers have been able to define knowledge bases that enable us to increase our defenses against attacks using Command & Control servers, it is because the number of such attacks is indeed significant.
Olfeo: A response to the C2 threat:
In this context, Olfeo stands out for its proactive approach to cybersecurity. By blocking access to unknown and potentially malicious domains, Olfeo creates a secure digital environment, preventing malicious communications from the moment they are first attempted.
Olfeo's Zero Trust Internet Access technology, combined with a database that is continuously enriched by artificial intelligence and a dedicated team, ensures safe browsing while facilitating access to the legitimate resources necessary for daily business operations. This approach notably resolves the issue of detecting C2 servers whose domains may change regularly.
Conclusion:
The ubiquity and growing sophistication of Command and Control servers pose a major challenge to global digital security. However, the adoption of advanced defense strategies, combined with innovative cybersecurity solutions such as those offered by Olfeo, provides an effective solution. By interrupting malicious communication chains and preventing the exploitation of vulnerabilities, we can not only detect but also neutralize the threats posed by C2 servers, thereby protecting critical infrastructure and sensitive data from malicious actors.


