QUIC/HTTP3 C2 Transport
Overview
Malware using QUIC (RFC 9000) or HTTP/3 as its primary command-and-control transport. QUIC runs over UDP and provides built-in encryption (TLS 1.3) and stream multiplexing, making it harder to inspect with traditional TLS-intercepting proxies. HTTP/3 maps HTTP semantics onto QUIC streams.
Why It Matters
- Most corporate firewalls allow outbound UDP/443 (HTTP/3 fallback).
- Wireshark/tshark QUIC dissection requires key log files; passive decryption is infeasible without session keys.
- 0-RTT resumption allows fast reconnect after process restart or network change.
- Connection migration (CID switching) lets C2 survive IP changes.
Observed In
- afk-stealer — Go-based infostealer using
quic-gov0.x with X25519+MLKEM768 key exchange, 0-RTT, andhttp3ALPN negotiation. ^[/intel/analyses/0b6c65cde50cae62eb3e15a9857193abd2ed130f8d73de6afc3e58ac2397c49a.html]
Detection
- Watch for UDP/443 flows to non-well-known endpoints.
quic-gofingerprints: long initial packets with QUIC version negotiation, specific transport parameter encoding.- TLS ClientHello with
quicSNI extension orh3ALPN token.
ATT&CK Mapping
- T1071 — Application Layer Protocol
- T1572 — Protocol Tunneling
Related
- dns-over-https-fallback — complementary fallback transport