Possible Discord Webhook C2 or Data Exfiltration

PremiumReviewedSigma · Medium · v1
Category
proxy
Author
HuntRule
Published
2026-10-05
Updated
2026-10-05

ATT&CK techniques

C2 → Exfiltration
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Discovery

  10. Lateral Movement

  11. Collection

  12. Impact

What it detects

This rule detects outbound requests to Discord webhook endpoints which threat actors repurpose as command and control channels and as a destination for exfiltrated data. Because webhooks blend into normal Discord traffic they provide a low cost covert channel for stealing information and receiving operator instructions.

Related detections9 linkedT1102 — drag to rearrange
Windows Suspicious Non-Browser Network Traffic to api.telegram.org
Linux network connections to ngrok tunneling endpoints
Windows Executable Initiating Connections to ngrok Tunnel Domains
Windows Process Initiated Connections to Ngrok Domains
Possible Gamaredon C2 via Ephemeral Tunneling and Worker Services
Possible Gamaredon Dead-Drop C2 via Telegraph and GoFile Web Services
Suspicious Environment Variable Dump Piped to Base64 for CI Credential Exfil
Suspicious APT29 Zulip C2 Communication via curl User-Agent (via proxy)
Malicious Destructive Recursive Delete of Home Directory
Possible Discord Webhook C2 or Data Exfiltration
Pivot detection · T1102 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.