typeconceptconfidencehighcreated2026-08-04updated2026-08-04c2c2-protocolmitre-attck

Raw TCP C2 Socket

Malware that uses the Berkeley sockets API directly (WSOCK32.dll or ws2_32.dll) for command-and-control communication without an application-layer framing protocol such as HTTP, HTTPS, or DNS. This reduces network telemetry visibility because the traffic is opaque to standard HTTP inspection proxies and does not carry easily parseable headers.

Fingerprint

  • Imports: socket, connect, send, recv, WSAStartup, gethostbyname, inet_addr.
  • Absence of WinHttpOpen, InternetOpenA, or URLDownloadToFileA.
  • Hardcoded IP addresses or hostname strings (often encrypted) inside the payload.

Countermeasures

  • Monitor for processes with no obvious network purpose (e.g., masqueraded system utilities) making outbound TCP connections on non-standard ports.
  • Use Zeek/Suricata anomaly detection for long-lived TCP sessions with low data volume.

Pages Where Observed

  • wraith — Full WSOCK32 import surface with no hardcoded C2 strings recovered statically. ^[sample 0ab9a570/pefile.txt]
  • raw-tcp-c2-socket — Also documented in darkcomet and remcos families.