typetechniqueconfidencehighcreated2026-08-15updated2026-08-15c2quichttp3protocol-tunnelingexfiltration

QUIC/HTTP3 C2 Transport

Overview

Malware using QUIC (RFC 9000) or HTTP/3 as its primary command-and-control transport. QUIC runs over UDP and provides built-in encryption (TLS 1.3) and stream multiplexing, making it harder to inspect with traditional TLS-intercepting proxies. HTTP/3 maps HTTP semantics onto QUIC streams.

Why It Matters

  • Most corporate firewalls allow outbound UDP/443 (HTTP/3 fallback).
  • Wireshark/tshark QUIC dissection requires key log files; passive decryption is infeasible without session keys.
  • 0-RTT resumption allows fast reconnect after process restart or network change.
  • Connection migration (CID switching) lets C2 survive IP changes.

Observed In

  • afk-stealer — Go-based infostealer using quic-go v0.x with X25519+MLKEM768 key exchange, 0-RTT, and http3 ALPN negotiation. ^[/intel/analyses/0b6c65cde50cae62eb3e15a9857193abd2ed130f8d73de6afc3e58ac2397c49a.html]

Detection

  • Watch for UDP/443 flows to non-well-known endpoints.
  • quic-go fingerprints: long initial packets with QUIC version negotiation, specific transport parameter encoding.
  • TLS ClientHello with quic SNI extension or h3 ALPN token.

ATT&CK Mapping

  • T1071 — Application Layer Protocol
  • T1572 — Protocol Tunneling

Related