T1102.001: Dead Drop Resolver
Adversaries may use an existing, legitimate external Web service to host information that points to additional command and control (C2) infrastructure. Adversaries may post content, known as a dead drop resolver, on Web services with embedded (and often obfuscated/encoded) domains or IP addresses. Once infected, victims will reach out to and be redirected by these resolvers.
Popular websites and social media acting as a mechanism for C2 may give a significant amount of cover due to the likelihood that hosts within a network are already communicating with them prior to a compromise. Using common services, such as those offered by Google or Twitter, makes it easier for adversaries to hide in expected noise. Web service providers commonly use SSL/TLS encryption, giving adversaries an added level of protection.
Use of a dead drop resolver may also protect back-end C2 infrastructure from discovery through malware binary analysis while also enabling operational resiliency (since this infrastructure may be dynamically changed).
Security context for executives and security teams
Dead Drop Resolver is a command-and-control behavior where malware uses a legitimate external web service, such as a popular website or social media platform, to find the real C2 address. This matters because the first network contact may look like normal business web traffic, especially over SSL/TLS, while the actual back-end infrastructure can change dynamically. For leaders, the key issue is whether the organization can distinguish expected use of common web services from infected hosts retrieving hidden C2 pointers.
Executive priority
Prioritize this as a resilience and visibility problem, not just a malware indicator problem. Blocking one domain or IP may not be enough because the resolver can point to changing infrastructure and legitimate services may be difficult to block outright. Executives should ask whether web access governance, proxy controls, network intrusion prevention, and SOC playbooks can handle suspicious use of otherwise trusted services without disrupting business operations. This technique is also useful for audit and compliance discussions around outbound traffic control, encrypted web visibility, and incident response evidence retention.
Technical view
This is an enterprise command-and-control sub-technique under Web Service and applies to ESXi, Linux, macOS, and Windows environments. SOC and detection teams should validate coverage for hosts contacting legitimate external web services and then following embedded, encoded, obfuscated, or unusual domains/IPs. ATT&CK provides no official detection text for this object, but the relationship to DET0058 indicates a dedicated detection strategy exists for Web Service: Dead Drop Resolver. Relationships to multiple campaigns, groups, and malware families show the behavior is not limited to one toolset; use that as context for detection engineering, not as proof of local attribution.
Likely telemetry
- Web proxy and secure web gateway logs showing outbound requests to popular external web services
- DNS query and response logs for follow-on domains discovered after web-service access
- Network intrusion detection/prevention events at internet boundaries
- TLS/SSL connection metadata, including destination, timing, certificate, and SNI where available
- Endpoint process-to-network connection telemetry across Windows, Linux, macOS, and ESXi where collected
Detection direction
- Baseline normal organizational use of common web services so suspicious resolver-like access patterns are not lost in expected noise.
- Look for sequences where an endpoint accesses a legitimate web service and soon after connects to uncommon or newly observed external domains or IP addresses.
- Tune detections for encoded, obfuscated, or unusual content retrieval from pages, feeds, posts, or similar web-hosted content, while accounting for legitimate automation and user activity.
- Correlate web proxy, DNS, network, and endpoint process telemetry; any single source may be insufficient because SSL/TLS and common-service usage can obscure content.
- Validate whether DET0058-aligned logic is implemented locally, but do not assume coverage because the ATT&CK object itself does not provide official detection details.
Mitigation priorities
- Start with Restrict Web-Based Content: enforce policy-driven controls such as URL filtering, download restrictions, script blocking, and control of unauthorized browser behaviors where appropriate.
- Use Network Intrusion Prevention at network boundaries to block known malicious or policy-violating traffic when signatures or reliable indicators are available.
- Define acceptable-use and exception processes for popular web services so defenders can act on suspicious use without creating unmanaged business disruption.
- Retain outbound web, DNS, and network evidence long enough to support incident response reconstruction when a resolver points to changing back-end C2 infrastructure.
- Review controls across all supported enterprise platforms in scope: ESXi, Linux, macOS, and Windows.
Additional notes and limits
The relationship set includes campaigns, groups, and software such as C0017, the 3CX Supply Chain Attack, Patchwork, RTM, APT41, Rocke, PlugX, MiniDuke, BLACKCOFFEE, BADNEWS, Xbash, Astaroth, Metamorfo, PolyglotDuke, Javali, Grandoreiro, and CharmPower. These relationships support the conclusion that the technique appears across varied intrusion contexts, but they should not be used alone for attribution. The most important local validation is whether common web-service traffic is observable, baselined, and correlated with follow-on outbound connections.
The supplied ATT&CK object does not include official detection text, specific analytics, data components, or vendor implementation guidance. The mitigation descriptions are high level, and local feasibility depends on business use of external web services, encrypted traffic visibility, privacy requirements, and available telemetry. No claim of active exploitation or customer exposure is made from this object alone.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Dead Drop Resolver
Adversaries may use an existing, legitimate external Web service to host information that points to additional command and control (C2) infrastructure. Adversaries may post content, known as a dead drop resolver, on Web services with embedded (and often obfuscated/encoded) domains or IP addresses. Once infected, victims will reach out to and be redirected by these resolvers.
Popular websites and social media acting as a mechanism for C2 may give a significant amount of cover due to the likelihood that hosts within a network are already communicating with them prior to a compromise. Using common services, such as those offered by Google or Twitter, makes it easier for adversaries to hide in expected noise. Web service providers commonly use SSL/TLS encryption, giving adversaries an added level of protection.
Use of a dead drop resolver may also protect back-end C2 infrastructure from discovery through malware binary analysis while also enabling operational resiliency (since this infrastructure may be dynamically changed).
How security teams should use this page
Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.
All related ATT&CK context
No relationships are available in the current normalized data for this object.
Object version and sync metadata
The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.
Mirrored ATT&CK source object
The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.
Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.
