typetechniqueconfidencehighcreated2026-08-18updated2026-08-18c2-protocolc2exfiltrationmitre-attckgo

WebSocket C2 Transport

Malware using WebSocket (RFC 6455) as its primary command-and-control channel, typically over TLS (wss://). Observed in Go-based malware via github.com/gorilla/websocket.

Detection / Fingerprint

  • PE imports or strings referencing github.com/gorilla/websocket
  • Go type strings like *websocket.Conn, *websocket.Dialer, websocket.CloseError
  • wss:// or ws:// URLs in decoded strings
  • JSON-over-WebSocket message framing (application/json + steal finished!)

Implementation Patterns

The AFK Stealer sibling bd6dead7 uses a wsSess type to manage the WebSocket session with methods for:

  • recvWss — inbound command loop
  • sendTrace — telemetry / screenshot streaming
  • sepDesktop — hidden desktop session
  • execCommand / shellCommand — remote execution
  • ffdesktop / ffwmic / ffwcam — screen / WMI / webcam capture

Defensive Detection

  • Network: monitor for outbound WebSocket handshakes (Upgrade: websocket, Connection: Upgrade) to non-standard ports or ephemeral domains
  • Process: Go binaries with gorilla/websocket in module strings spawning shells or accessing browser credential stores

Cross-References