Group Purchasing
Group Purchasing

Network Artifacts of Trusted Service Abuse

Network Artifacts of Trusted Service Abuse (PDF, 2.71MB)Published: 06 Aug, 2026

The ever-increasing adoption of trusted services and their interconnectivity with private resources provides new opportunities for malicious communication channels. Traditional indicators of compromise, such as IP/Domain reputation or beacon detection, are most effective against adversary-owned infrastructure but yield limited signals when communication channels run atop trusted services.

This study contrasts normal user traffic with known malicious activity to identify alternative indicators from four public C2 frameworks (DaaC2, DBC2, gdog, Callidus) operating on Dropbox, Discord, Gmail, and OneNote, using 51 packet captures (3 baselines, 6 automated browser tests and 6 framework tests per service).

Across four detection tiers, Reputation-based detection failed to identify any C2 channels; Beacon Detection was marginally viable when using clustering (2/4); Traffic Metadata was partially viable, with mixed results other than JA4 fingerprints (100% detection); and Traffic Patterns proved most viable, with both TLS session resumption near-zero (vs 22%+ for browser) and a 2.6x upload/download ratio gap (1.41 vs 0.55 means). Structural and behavioral indicators, such as TLS session resumption and JA4 fingerprinting, outperform reputation in detecting trusted service abuse.

FAQ

It uses the SANS PICERL lifecycle - Preparation, Identification, Containment, Eradication, Recovery, and Lessons Learned - adapted to the safety and operational constraints of industrial control system environments. 

In IT, endpoint tools can isolate individual hosts remotely. In OT, containment typically means physical or logical isolation of the whole network at a firewall, router, or switch, and the decision is usually made by facility or safety managers rather than cybersecurity staff alone. 

No - ransomware attacks rarely compromise lower-level process systems like PLCs directly. They more commonly disrupt higher-level systems such as HMIs, engineering workstations, and SCADA platforms used for visibility and control. 

No - paying the ransom does not remove the initial access broker or ransomware affiliate from the environment. A full forensic investigation and containment effort is still required after payment to fully restore security.

At least annually, according to the framework, though more frequent exercises are preferable, along with regular drills of critical technical procedures in lab or digital twin environments to avoid disrupting live operations.