T1071 - Command And Control - MITRE ATT&CK

Threat entity extracted from intelligence sources

Frequency
7
occurrences
First Seen
November 6, 2025
Last Seen
December 24, 2025

T1071 - Command And Control is a mitre_attack tracked across 13 threat clusters and 7 intelligence report mentions on ThreatCluster. First observed November 6, 2025; most recent activity December 24, 2025.

Related Threat Clusters

  • Critical Auth Bypass Vulnerability in Asus DSL Routers

    Asus has identified a critical authentication bypass vulnerability (CVE-2025-59367) affecting its DSL-AC51, DSL-AC750, and DSL-N16 router models. This flaw allows remote, unauthenticated attackers to gain full control…

    14 articles · Updated November 16, 2025
  • WebRAT Malware Distributed via GitHub Exploits

    WebRAT malware, a backdoor with info-stealing capabilities, is being distributed through GitHub repositories claiming to host proof-of-concept exploits for recently disclosed vulnerabilities. Initially targeting gamers…

    4 articles · Updated December 23, 2025
  • APT24 Uses BadAudio Malware in Ongoing Espionage Campaign

    APT24, a China-linked hacking group, has been utilizing a previously undocumented malware named BadAudio in a three-year espionage campaign. This malware has been delivered through various methods, including…

    6 articles · Updated November 20, 2025
  • Russia and North Korea Collaborate in Cyber Operations

    Research indicates that Russian APT group Gamaredon and North Korean Lazarus Group are collaborating by sharing operational infrastructure. This partnership marks a significant development in state-sponsored cyber…

    4 articles · Updated November 26, 2025
  • Five Plead Guilty in North Korean IT Worker Fraud Scheme

    Five individuals have pleaded guilty to facilitating North Korean operatives in obtaining remote IT jobs at U.S. companies by using false and stolen identities. The U.S. Department of Justice has also seized $15 million…

    39 articles · Updated November 17, 2025
  • North Korea and Russia Collaborate in Cyber Operations

    North Korea's Lazarus Group and Russia's Gamaredon have reportedly begun collaborating in cyber operations, marking the first known instance of such cooperation. Researchers from Gen Digital indicate that the two groups…

    4 articles · Updated November 24, 2025
  • SonicWall Investigates State-Backed Breach of Cloud Backup Service

    SonicWall reported a security incident involving unauthorized access to backup firewall configuration files stored in a cloud environment. The company attributed the breach to a state-backed threat actor and engaged…

    8 articles · Updated November 21, 2025
  • SonicWall Investigates State-Backed Breach of Cloud Backup Service

    SonicWall reported unauthorized access to backup firewall configuration files in September 2025, attributed to a state-backed threat actor. The company engaged Mandiant for an investigation and communicated with…

    11 articles · Updated November 26, 2025
  • Lazarus Group Linked to $30M Upbit Hack in South Korea

    South Korean authorities suspect that North Korea's Lazarus Group was behind a hack of Upbit, resulting in losses of approximately $30.4 million. The breach involved unusual activity in Solana tokens and led Upbit to…

    100 articles · Updated November 28, 2025
  • Matrix Push C2 Framework Used for Browser Notification Attacks

    Cybercriminals are utilizing the Matrix Push C2 framework to exploit browser notifications for distributing malicious links. This method involves social engineering tactics to trick users into allowing notifications,…

    8 articles · Updated November 21, 2025

Recent Intelligence Reports

  • Webrat turns GitHub PoCs into a malware trap — Csoonline · December 24, 2025
  • Russia and North Korea Expand Cybersecurity Cooperation in 2025 — Mezha · November 22, 2025
  • Asus Routers Hit by 'WrtHug' Malware Campaign — Varindia · November 21, 2025
  • Hackers Deploy New Matrix Push C2 to Launch Malware and Phishing Attacks Through ... — Cyberpress · November 21, 2025
  • Google exposes BadAudio malware used in APT24 espionage campaigns — Bleepingcomputer · November 20, 2025
  • Android Devices Targeted By KONNI APT in Find Hub Exploitation — Infosecurity-Magazine · November 11, 2025
  • SonicWall Firewall Backups Stolen by Nation — Darkreading · November 6, 2025

CVSS v3.1 Breakdown