WebSocket C2 Transport
Malware using WebSocket (RFC 6455) as its primary command-and-control channel, typically over TLS (wss://). Observed in Go-based malware via github.com/gorilla/websocket.
Detection / Fingerprint
- PE imports or strings referencing
github.com/gorilla/websocket - Go type strings like
*websocket.Conn,*websocket.Dialer,websocket.CloseError wss://orws://URLs in decoded strings- JSON-over-WebSocket message framing (
application/json+steal finished!)
Implementation Patterns
The AFK Stealer sibling bd6dead7 uses a wsSess type to manage the WebSocket session with methods for:
recvWss— inbound command loopsendTrace— telemetry / screenshot streamingsepDesktop— hidden desktop sessionexecCommand/shellCommand— remote executionffdesktop/ffwmic/ffwcam— screen / WMI / webcam capture
Defensive Detection
- Network: monitor for outbound WebSocket handshakes (
Upgrade: websocket,Connection: Upgrade) to non-standard ports or ephemeral domains - Process: Go binaries with
gorilla/websocketin module strings spawning shells or accessing browser credential stores
Cross-References
- Observed in: afk-stealer
bd6dead7f5a0ec51 - Related: quic-http3-c2-transport — fallback transport in same family
- Related: rat — concept page for remote-access tool capabilities