{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/c2-traffic/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":[],"_cs_severities":["medium"],"_cs_tags":["command-and-control","ai-security","endpoint-detection","c2-traffic"],"_cs_type":"advisory","_cs_vendors":[],"content_html":"\u003cp\u003eAdversaries are increasingly leveraging the capabilities of Large Language Models (LLMs) to dynamically perform malicious actions on compromised systems. This threat involves malware or post-exploitation scripts that utilize legitimate LLM APIs as a proxy for command and control (C2) or to execute logic within the affected system. This behavior is characterized by network connections to a broad range of AI and ML infrastructure providers, including OpenAI, Anthropic, Mistral, and various specialized inference services, initiated by unsigned binaries or common Windows/macOS scripting utilities such as PowerShell, curl, or WScript. Because these connections mimic legitimate traffic to AI services, detection must focus on the process context, specifically identifying unauthorized or unsigned code initiating the requests.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eInitial access is established through standard means, such as spearphishing or exploiting a public-facing service.\u003c/li\u003e\n\u003cli\u003eThe attacker drops an unsigned or obfuscated payload (e.g., PowerShell script or malicious executable) into a non-standard directory like /tmp/ or \\Users\\Public.\u003c/li\u003e\n\u003cli\u003eThe malicious process executes and gathers system information or target data.\u003c/li\u003e\n\u003cli\u003eThe process initiates an HTTPS connection to an LLM provider's API endpoint (e.g., api.openai.com).\u003c/li\u003e\n\u003cli\u003eThe attacker sends instructions or prompts to the LLM API to generate code or malicious commands tailored to the system state.\u003c/li\u003e\n\u003cli\u003eThe response from the LLM is parsed and executed locally by the malicious process.\u003c/li\u003e\n\u003cli\u003eThe process performs further actions, such as exfiltrating data or establishing persistent access, based on the AI-generated logic.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows attackers to bypass traditional static signature-based defenses by using dynamically generated, AI-assisted malicious logic. This increases the complexity of incident response and attribution, as the malicious commands originate from a legitimate, trusted API service. Affected organizations risk unauthorized data exfiltration, automated system exploitation, and stealthy persistence, as the C2 channel is obscured by traffic destined for reputable AI infrastructure.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eDeploy the provided EQL-based detection rules across all endpoints to monitor for suspicious processes communicating with known LLM API domains.\u003c/li\u003e\n\u003cli\u003eImplement strict network segmentation and egress filtering to prevent unauthorized processes from accessing cloud-based AI service APIs.\u003c/li\u003e\n\u003cli\u003ePerform a historical search on network proxy and DNS logs for connections to the listed LLM endpoints originating from high-risk or non-standard process paths.\u003c/li\u003e\n\u003cli\u003eReview and harden systems to prevent the execution of unsigned binaries or unauthorized scripting tools in sensitive environments.\u003c/li\u003e\n\u003cli\u003eIf an alert triggers, investigate the process tree and parent process to confirm whether the connection originates from a legitimate user-installed application or a malicious actor.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-18T19:04:04Z","date_published":"2026-09-18T19:04:04Z","id":"https://feed.craftedsignal.io/briefs/2026-09-llm-c2-detection/","summary":"Detection logic identifying unsigned binaries or scripting utilities establishing network connections to various Large Language Model API endpoints for potential command and control.","title":"Detection of Malicious Use of LLM Endpoints for Command and Control","url":"https://feed.craftedsignal.io/briefs/2026-09-llm-c2-detection/"}],"language":"en","title":"CraftedSignal Threat Feed - C2-Traffic","version":"https://jsonfeed.org/version/1.1"}