IronSights

Threats & attacks

Command and controlC2

Infrastructure used by attackers to communicate with and control malware or compromised systems within a target network, issuing commands and receiving exfiltrated data.

Also known asC2C&Ccommand and control infrastructureC2 server

In plain English

Once malware infects a device, it 'phones home' to a C2 server controlled by the attacker. This allows the attacker to issue commands, download additional tools, receive stolen data, or trigger actions like ransomware detonation — all while appearing to be legitimate web traffic. DNS filtering blocks known C2 domains before connections are established.

Keep learning

More terms in the IronSights Glossary.