# T1102.002 Bidirectional Communication

> As of 2026-10-05, T1102.002 (Bidirectional Communication) appears in 139 tracked threats, first reported 2026-02-04 and most recently 2026-10-02, with linked actors including APT38, TeamPCP, Lazarus Group; it most often appears alongside T1071.001 (Web Protocols).

- **Tracked threats:** 139 (29 critical, 99 high, 11 medium)
- **First seen:** 2026-02-04
- **Last seen:** 2026-10-02
- **Threat actors:** 65
- **Detection rules:** 425 (counts only; Blue tier and above)

## Key facts

- **ID:** T1102.002
- **Framework:** MITRE ATT&CK
- **Tactics:** Command and Control
- **Matrix:** Enterprise
- **Parent:** T1102
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1102/002/

## Activity timeline

T1102.002 first appeared in tracked threats on 2026-02-04 and was most recently reported on 2026-10-02. The busiest month was 2026-07 with 39 reports, and 139 of the 139 threats were reported in the twelve months to 2026-10.

## How adversaries use it

T1102.002 Bidirectional Communication is catalogued by MITRE ATT&CK under the Command and Control tactic in the Enterprise matrix, as a sub-technique of [T1102 Web Service](https://intel.threadlinqs.com/technique/T1102). Threadlinqs maps 139 of 2623 tracked threats (5.3%) to it; by severity that is 29 critical, 99 high, 11 medium.

Threats that use T1102.002 most often also use [T1071.001 Web Protocols](https://intel.threadlinqs.com/technique/T1071.001) (105 threats), [T1204.002 Malicious File](https://intel.threadlinqs.com/technique/T1204.002) (82 threats), [T1027 Obfuscated Files or Information](https://intel.threadlinqs.com/technique/T1027) (81 threats), [T1036.005 Match Legitimate Resource Name or Location](https://intel.threadlinqs.com/technique/T1036.005) (81 threats), [T1082 System Information Discovery](https://intel.threadlinqs.com/technique/T1082) (81 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

65 tracked threat actors appear in the threats that use T1102.002; the most frequent are [APT38](https://intel.threadlinqs.com/actor/APT38) (6), [TeamPCP](https://intel.threadlinqs.com/actor/TeamPCP) (6), [Lazarus Group](https://intel.threadlinqs.com/actor/Lazarus%20Group) (5), [Andariel](https://intel.threadlinqs.com/actor/Andariel) (4), [MuddyWater](https://intel.threadlinqs.com/actor/MuddyWater) (4).

## Mitigations

MITRE ATT&CK lists 2 mitigations for T1102.002.

- [M1021 Restrict Web-Based Content](https://attack.mitre.org/mitigations/M1021/)
- [M1031 Network Intrusion Prevention](https://attack.mitre.org/mitigations/M1031/)

## Data sources

Telemetry that can reveal T1102.002, per MITRE ATT&CK.

- Network Traffic — Network Connection Creation, Network Traffic Content, Network Traffic Flow

## Threat actors using it

- [APT38](https://intel.threadlinqs.com/actor/APT38) — 6
- [TeamPCP](https://intel.threadlinqs.com/actor/TeamPCP) — 6
- [Lazarus Group](https://intel.threadlinqs.com/actor/Lazarus%20Group) — 5
- [Andariel](https://intel.threadlinqs.com/actor/Andariel) — 4
- [MuddyWater](https://intel.threadlinqs.com/actor/MuddyWater) — 4
- [Sapphire Sleet](https://intel.threadlinqs.com/actor/Sapphire%20Sleet) — 4
- [Stardust Chollima](https://intel.threadlinqs.com/actor/Stardust%20Chollima) — 4
- [APT28](https://intel.threadlinqs.com/actor/APT28) — 3
- [Cavern Manticore](https://intel.threadlinqs.com/actor/Cavern%20Manticore) — 3
- [UAT-11795](https://intel.threadlinqs.com/actor/UAT-11795) — 3
- [APT36](https://intel.threadlinqs.com/actor/APT36) — 2
- [APT37](https://intel.threadlinqs.com/actor/APT37) — 2

## Tracked threats

The 30 most recent of 139 tracked threats that use T1102.002.

- [Antino Backdoor Uses Outlook and OneDrive for C2 in China-Nexus Espionage Campaign (UAT-11587)](https://intel.threadlinqs.com/threat/TL-2026-2848) — high — 2026-10-02
- [AhnLab ASEC August 2026 APT Attack Trend Report (South Korea): LNK Spear Phishing Delivering XenoRAT and…](https://intel.threadlinqs.com/threat/TL-2026-2800) — high — 2026-09-30
- [CVE-2019-18935 Telerik UI Deserialization Exploited to Deploy Web Shells and a WordPress Scanner on IIS…](https://intel.threadlinqs.com/threat/TL-2026-2726) — critical — 2026-09-28
- [OS-Aware Phishing Kit Fans Fake iCloud Alert into ScreenConnect RMM, Apple ID, and M365 AiTM Harvesters](https://intel.threadlinqs.com/threat/TL-2026-2704) — high — 2026-09-27
- [CARBONATO Botnet Exploits Exposed Docker Daemons to Deploy AI Agent Framework, Prioritizes AI API Key Theft](https://intel.threadlinqs.com/threat/TL-2026-2689) — high — 2026-09-27
- [Malicious Google Ads Campaign Targets Ledger Hardware Wallet Users to Steal BIP-39 Recovery Phrases via…](https://intel.threadlinqs.com/threat/TL-2026-2673) — high — 2026-09-26
- [Carbonato botnet: AI-agent-driven worm hijacks unauthenticated Docker daemons on port 2375 and installs the…](https://intel.threadlinqs.com/threat/TL-2026-2639) — high — 2026-09-24
- [DPRK-Linked Graphalgo Campaign Abuses HashiCorp Terraform Registry with Malicious Providers and Go Modules…](https://intel.threadlinqs.com/threat/TL-2026-2635) — high — 2026-09-23
- [ClosedQuorum: Go-Based Windows Implant Delegates Post-Compromise Decisions to a Four-Model LLM Voting Panel](https://intel.threadlinqs.com/threat/TL-2026-2621) — medium — 2026-09-22
- [Trusted AI Platforms Weaponized as Malware Distribution Channels: Claude Artifacts, ChatGPT, and Grok Abused…](https://intel.threadlinqs.com/threat/TL-2026-2604) — high — 2026-09-21
- [indexed-btree npm Campaign: Runtime-Triggered Loader Evades Install-Script Defenses via BTree.prototype.set()](https://intel.threadlinqs.com/threat/TL-2026-2590) — high — 2026-09-20
- [GHAPPIER Loader: npm Supply-Chain Compromise of @dforge-core/dforge-mcp Linked to DPRK PolinRider Campaign](https://intel.threadlinqs.com/threat/TL-2026-2588) — high — 2026-09-20
- [AI-Powered Polymorphic Malware Queries LLMs at Runtime to Evade Signature Detection: PROMPTFLUX and…](https://intel.threadlinqs.com/threat/TL-2026-2559) — medium — 2026-09-18
- [SilkParasite Infrastructure Links SpiceRAT, NodeEdgeRAT, and NomadRAT to Four-Year China-Nexus Campaign…](https://intel.threadlinqs.com/threat/TL-2026-2554) — high — 2026-09-17
- [Iranian State Actors Deploy CHOSEN BRICK Windows Malware to Spy on Dissidents, Activists, and Journalists](https://intel.threadlinqs.com/threat/TL-2026-2543) — high — 2026-09-16
- [Chosen Brick: Iranian State-Sponsored Windows Surveillance Malware Exposed by US, UK, and Dutch Agencies](https://intel.threadlinqs.com/threat/TL-2026-2534) — high — 2026-09-16
- [PhantomRaven: LLM-Generated npm Information Stealer Used for Bug Bounty Hunting](https://intel.threadlinqs.com/threat/TL-2026-2531) — high — 2026-09-16
- [Iranian MOIS-Linked Actor Uses Telegram-Controlled HEAVYGRAM/CHOSEN BRICK Malware Against Dissidents and…](https://intel.threadlinqs.com/threat/TL-2026-2526) — high — 2026-09-15
- [ScreenConnect Backdoor Delivered via SSA-Impersonation Phishing Lure](https://intel.threadlinqs.com/threat/TL-2026-2594) — medium — 2026-09-14
- [GemStuffer: AI Agent Swarm Floods RubyGems With 2,000+ Malicious Packages, Achieves RCE via RubyDoc.info…](https://intel.threadlinqs.com/threat/TL-2026-2462) — high — 2026-09-12
- [OpenAI Agent Swarm ("GemStuffer") Flooded RubyGems With 2,000+ Malicious Packages, Achieved RCE on…](https://intel.threadlinqs.com/threat/TL-2026-2459) — high — 2026-09-12
- [APT-C-60 Spear-Phishing Campaign Delivering SpyGlace via Proton Drive, RAR/LNK and Legitimate Developer…](https://intel.threadlinqs.com/threat/TL-2026-2371) — high — 2026-09-07
- [DOJ/FBI Seize $560,000 in Hamas-Linked Cryptocurrency Fundraising Network](https://intel.threadlinqs.com/threat/TL-2026-2309) — medium — 2026-09-03
- [APT28-Linked HOOKEDGE Backdoor Targets Diplomatic and Government Organizations in Romania, Spain, and Türkiye](https://intel.threadlinqs.com/threat/TL-2026-2213) — high — 2026-08-29
- [Threat Actors Abuse Trusted AI Platforms (Claude, ChatGPT, Grok) to Distribute Malware](https://intel.threadlinqs.com/threat/TL-2026-2197) — high — 2026-08-29
- [npm Supply-Chain Compromise: @7nohe/openapi-react-query-codegen Ships "Trinitite" Credential-Harvesting Worm](https://intel.threadlinqs.com/threat/TL-2026-2193) — critical — 2026-08-28
- [July 2026 Domestic APT Attack Trends (South Korea): LNK-Based Spear Phishing Delivering XenoRAT and…](https://intel.threadlinqs.com/threat/TL-2026-2180) — high — 2026-08-28
- ["The Com" cross-platform criminal ecosystem: Discord/Telegram/Roblox/Minecraft/X abused for malware…](https://intel.threadlinqs.com/threat/TL-2026-2155) — high — 2026-08-26
- [Sophos X-Ops: Attackers Impersonate Claude, ChatGPT, Copilot and Perplexity to Distribute Infostealers…](https://intel.threadlinqs.com/threat/TL-2026-2120) — high — 2026-08-23
- [VECT 2.0 Ransomware's Nonce-Reuse Flaw Turns It Into an Accidental Wiper for Files Over 128KB](https://intel.threadlinqs.com/threat/TL-2026-2116) — high — 2026-08-22

## Related CVEs

CVEs referenced by the tracked threats that use T1102.002, most frequent first.

- [CVE-2025-55182](https://intel.threadlinqs.com/cve/CVE-2025-55182)
- [CVE-2025-9501](https://intel.threadlinqs.com/cve/CVE-2025-9501)
- [CVE-2025-8088](https://intel.threadlinqs.com/cve/CVE-2025-8088)
- [CVE-2017-0199](https://intel.threadlinqs.com/cve/CVE-2017-0199)
- [CVE-2017-11317](https://intel.threadlinqs.com/cve/CVE-2017-11317)
- [CVE-2018-0802](https://intel.threadlinqs.com/cve/CVE-2018-0802)
- [CVE-2018-13379](https://intel.threadlinqs.com/cve/CVE-2018-13379)
- [CVE-2019-18935](https://intel.threadlinqs.com/cve/CVE-2019-18935)
- [CVE-2020-0688](https://intel.threadlinqs.com/cve/CVE-2020-0688)
- [CVE-2020-1472](https://intel.threadlinqs.com/cve/CVE-2020-1472)
- [CVE-2021-26855](https://intel.threadlinqs.com/cve/CVE-2021-26855)
- [CVE-2022-40684](https://intel.threadlinqs.com/cve/CVE-2022-40684)
- [CVE-2022-41328](https://intel.threadlinqs.com/cve/CVE-2022-41328)
- [CVE-2022-42475](https://intel.threadlinqs.com/cve/CVE-2022-42475)
- [CVE-2023-27997](https://intel.threadlinqs.com/cve/CVE-2023-27997)
- [CVE-2023-36025](https://intel.threadlinqs.com/cve/CVE-2023-36025)
- [CVE-2023-48788](https://intel.threadlinqs.com/cve/CVE-2023-48788)
- [CVE-2024-21762](https://intel.threadlinqs.com/cve/CVE-2024-21762)
- [CVE-2024-55591](https://intel.threadlinqs.com/cve/CVE-2024-55591)
- [CVE-2024-6387](https://intel.threadlinqs.com/cve/CVE-2024-6387)
- [CVE-2025-20333](https://intel.threadlinqs.com/cve/CVE-2025-20333)
- [CVE-2025-20362](https://intel.threadlinqs.com/cve/CVE-2025-20362)
- [CVE-2025-29927](https://intel.threadlinqs.com/cve/CVE-2025-29927)
- [CVE-2025-39391](https://intel.threadlinqs.com/cve/CVE-2025-39391)
- [CVE-2025-48703](https://intel.threadlinqs.com/cve/CVE-2025-48703)
- [CVE-2025-49113](https://intel.threadlinqs.com/cve/CVE-2025-49113)
- [CVE-2025-59718](https://intel.threadlinqs.com/cve/CVE-2025-59718)
- [CVE-2025-59719](https://intel.threadlinqs.com/cve/CVE-2025-59719)
- [CVE-2025-64446](https://intel.threadlinqs.com/cve/CVE-2025-64446)
- [CVE-2025-68686](https://intel.threadlinqs.com/cve/CVE-2025-68686)

## Detection coverage

Threadlinqs maintains 425 detection rules mapped to T1102.002 (SPL 151, KQL 136, Sigma 138). Rule content is available to Blue tier accounts and above; this page shows counts only.

425 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Parent technique

[T1102 Web Service](https://intel.threadlinqs.com/technique/T1102) — 396 tracked threats at the technique level.

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1102.002
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
