. /
XXE .li
| |

the future of c2: using quic and http/3 for stealthy comms

Thursday at 06:30 AM SteelHeart created by
BYTE
SteelHeart

Joined: Jul 2025

DEPOSIT: ...

Thursday at 06:30 AM
#1
most network monitors (firewalls/ids) are optimized for TCP and standard HTTP traffic. i've started moving all my C2 communication to QUIC / HTTP/3 over UDP.

the advantage:
it's faster, encrypted by default, and many old school network monitors just 'ignore' it or don't know how to inspect the encrypted headers properly yet.

i'm using a custom Go-based agent that mimics a Chrome browser's QUIC traffic pattern. it looks exactly like someone is just browsing a google service.

stay stealthy boyz!
BYTE
NIGHTJAR

Joined: Sep 2025

DEPOSIT: ...

Thursday at 06:45 AM
#2
http/3 for c2 is smart mate. its very hard to distinguish from normal web traffic :D
BYTE
jsonbigs

Joined: Sep 2025

DEPOSIT: ...

Thursday at 07:02 AM
#3
lol 'mimicking google traffic' is the ultimate bypass for workplace firewalls
BYTE
NIGHTJAR

Joined: Sep 2025

DEPOSIT: ...

Thursday at 07:15 AM
#4
wat library u using for quic? quic-go?
BYTE
eclipse_x

Joined: Feb 2026

DEPOSIT: ...

Thursday at 07:30 AM
#5
yep quic-go is the goat for this. very stable and easy to customize mate $$$
BYTE
fogbank_44

Joined: May 2025

DEPOSIT: ...

Thursday at 07:45 AM
#6
quic-go is great but a bit heavy for a small agent lol
BYTE
GRAVEWOOD

Joined: May 2025

DEPOSIT: ...

Thursday at 08:00 AM
#7
u can use custom headers to make it even stealthier mate. like pretending to be a zoom call :D
BYTE
paleridge

Joined: Dec 2025

DEPOSIT: ...

Thursday at 08:15 AM
#8
lol zoom call traffic is always allowed in most offices $$$
BYTE
neon_shadow

Joined: Jan 2026

DEPOSIT: ...

Thursday at 08:30 AM
#9
smart move bro. i'm going to switch to http/3 tonight lol
BYTE
GreenGoblin

Joined: Aug 2025

DEPOSIT: ...

Thursday at 08:45 AM
#10
how do u handle the cert pinning? some firewalls still try to mitm the traffic lol
BYTE
thornroot

Joined: Jul 2025

DEPOSIT: ...

Thursday at 09:00 AM
#11
u need to hardcode the server cert in the agent mate. if the cert changes, the agent just kills itself lol :D
BYTE
TurboBoost

Joined: May 2025

DEPOSIT: ...

Thursday at 09:15 AM
#12
suicide code. hardcore mate lol
BYTE
fogvale

Joined: Feb 2026

DEPOSIT: ...

Thursday at 09:30 AM
#13
it's better than getting caught $$$
BYTE
BLEAKWOOD

Joined: Jun 2025

DEPOSIT: ...

Thursday at 09:45 AM
#14
true lol. stay safe boyz! :D
BYTE
quartzmarsh_95

Joined: Jul 2025

DEPOSIT: ...

Thursday at 10:00 AM
#15
is it possible to use dns tunneling over http/3 for even more stealth?
BYTE
cloud_surfer

Joined: Mar 2026

DEPOSIT: ...

Thursday at 10:15 AM
#16
yep, doh (dns over https) using http/3 is the ultimate stealth combo mate :D
BYTE
NIGHTMOOR

Joined: Jan 2026

DEPOSIT: ...

Thursday at 10:30 AM
#17
doh + http/3 = invisible $$$
BYTE
OrbitKing

Joined: Apr 2025

DEPOSIT: ...

Thursday at 10:45 AM
#18
nice. i need to implement this for my next campaign lol
BYTE
GameOver

Joined: Sep 2025

DEPOSIT: ...

Thursday at 11:00 AM
#19
campaign? mate u r a pro lol :D
BYTE
mini_boss

Joined: Nov 2025

DEPOSIT: ...

Thursday at 11:15 AM
#20
stay safe mate $$$

Want to join the discussion?

You must be logged in to post a reply in this topic.