← All terms

Command and Control (C2)

Command and control (C2) is the covert channel malware uses to receive an attacker's instructions and send stolen data out — the remote hand on the compromised device.

Command and control (C2) is the communication channel between compromised systems and the attacker's infrastructure. Malware on a victim's machine is only the hands; C2 is the nervous system that tells those hands what to do — run this command, grab those files, download the next payload, wait. The same channel carries results back out, which makes C2 both the attacker's steering wheel and, frequently, their exfiltration route. A remote access trojan checking in for instructions and a botnet of thousands of machines awaiting orders are both, at bottom, C2 architectures at different scales.

How it works

After the initial compromise — typically a phishing click, a malicious download, or a paste-and-run lure — the implant "beacons" out to attacker-controlled infrastructure: a server, a rented cloud instance, a hijacked website, sometimes even a legitimate service such as a messaging platform or file-sharing API abused as a relay. Outbound connections are used precisely because firewalls scrutinize inbound traffic far more than outbound, and the beacons are disguised as ordinary web traffic — HTTPS requests at randomized intervals, DNS queries carrying encoded data. Through this channel the attacker escalates from one infected machine to an interactive operation: issuing commands, deploying additional tools, and directing lateral movement toward the real objective. Cutting the C2 link effectively blinds the intrusion, which is why takedowns of major malware operations — such as the seizure of some 2,300 domains in the 2025 Lumma Stealer action — focus on the infrastructure rather than the individual infections.

How to defend against it

Prevent the beacon, then hunt it. Egress filtering and DNS security block or log connections to newly registered and known-bad domains; TLS inspection or network analytics catch the telltale rhythm of beaconing that hides inside encrypted traffic; endpoint detection flags the processes making the calls. Because the implant almost always arrives through a human action, the earliest defense is the person: an employee who recognizes the lure and reports it immediately can end the intrusion before the first beacon fires — and awareness of paste-and-run tricks like ClickFix, which hand the attacker their first C2 connection with the victim's own keystrokes, closes off one of the fastest-growing delivery paths.

Related terms

Remote Access Trojan (RAT)A remote access trojan is malware that gives an attacker covert, ongoing control of a victim's device — keyboard, files, camera and credentials included.BotnetA botnet is a network of malware-infected devices an attacker controls remotely, rented out to send spam, spread phishing, and disguise credential attacks.Dwell TimeDwell time is how long an attacker operates inside a network before being detected — the window in which a foothold becomes a full breach.Data ExfiltrationData exfiltration is the unauthorized transfer of data out of an organization — by external attackers, malicious insiders, or careless employees.
See your Human Risk Score

NOUSEC simulates attacks across 8 channels and turns the results into one number your board can read.

Book a demo