C2 Infrastructure
Command-and-control (C2) infrastructure is the server, domain, or cloud resource malware uses to receive instructions and exfiltrate data. Blocking C2 IPs and domains at the firewall and DNS layer disrupts active infections before lateral movement.
C2 infrastructure is everything an operator stands up so that infected machines can be told what to do: the domains they resolve, the addresses they connect to, the certificates on those endpoints, the redirectors in front of them and the panel behind. A single campaign may rotate through dozens of domains while keeping one back-end server.
That layering is deliberate. Redirectors absorb takedowns and blocklisting; the real server is never exposed to the victim. So the observable indicators (first-hop domains and addresses) churn quickly, while the things that identify the campaign (server fingerprints, certificate reuse, hosting choices) change slowly.
Trackers exploit the slow layer. A C2 framework answers in a recognisable way, uses a default certificate or a default port, and a scan of the address space finds new servers before any victim reports them. Those scans are what C2 feeds are made of.
Example
A feed lists a new address as a Cobalt Strike team server, found by its default TLS certificate. Reverse IP shows five fresh domains on the address; DNS history shows two of them previously pointed at another listed server. One scan hit, six indicators.
In isMalicious
The C2 feed at /data/c2-feeds aggregates tracker output into addresses and domains with the framework or family named, and an IP or domain report shows a C2 listing with its source and last-seen date so the freshness of the indicator is part of the verdict.
Frequently Asked Questions
What is C2 Infrastructure?
Command-and-control (C2) infrastructure is the server, domain, or cloud resource malware uses to receive instructions and exfiltrate data. Blocking C2 IPs and domains at the firewall and DNS layer disrupts active infections before lateral movement.
How is C2 Infrastructure related to C2 (Command and Control)?
C2 Infrastructure and C2 (Command and Control) are both key concepts in threat intelligence. A Command and Control server is infrastructure used by attackers to remotely control compromised hosts (a botnet) and deliver instructions, exfiltrate data, or push malware updates. Blocking C2 communications is one of the most effective ways to disrupt an active attack.
Related Terms
C2 (Command and Control)
A Command and Control server is infrastructure used by attackers to remotely control compromised hosts (a botnet) and deliver instructions, exfiltrate data, or push malware updates. Blocking C2 communications is one of the most effective ways to disrupt an active attack.
Botnet
A botnet is a network of compromised devices ("bots") controlled by an attacker via a C2 server. Botnets are used for DDoS attacks, spam campaigns, credential stuffing, and ransomware delivery. Individual bots are often unaware they are compromised.
Fast Flux
Fast flux is a DNS technique used by attackers to rapidly change the IP addresses associated with a domain — sometimes cycling through hundreds of IPs within minutes. It is used to make C2 servers and phishing sites resistant to IP-based blocking and takedowns.
Put this intelligence to work
Query indexed indicators — IPs, domains, URLs, and hashes — in seconds.