Skip to content
SecAIQ

Command and Control (C2)

The infrastructure attackers use to remotely send instructions to and receive data from malware installed on compromised devices.

·1 min read

Command and control (C2) refers to the servers and infrastructure attackers use to remotely communicate with malware already installed on compromised devices, sending instructions, downloading additional malicious tools, or exfiltrating stolen data. A network of devices under a single C2 infrastructure is often called a botnet.

Security teams work hard to identify and block C2 communication, since cutting off that channel neutralizes malware even if it can't be immediately removed from every infected device. Attackers counter this by disguising C2 traffic to look like normal web traffic or by routing it through legitimate cloud services.

Was this helpful?

Share on