What are command-and-control (C2) callbacks?

Malicious hacker attacks have been on the rise in the last couple of years. One of the most damaging attacks, often executed over DNS, is accomplished through command and control, also called C2 or C&C callbacks. Let’s have a look at how the hackers use this technique to infect their victims.
What is a C2 server?
A command-and-control server is a computer that is controlled by a cybercriminal. Command-and-control servers are used by attackers to maintain communications and send commands to systems inside a target network compromised by malware. These systems can include computers, smartphones, and even IoT devices connected to the network.
How are C2 servers used?
C2 servers act as command centres from where malware receives their commands. They are also used to collect and store stolen data. Establishing C2 communications is a vital step for attackers to access network resources.
The attacker starts by infecting a computer, which may sit behind a firewall. This can be achieved in several ways:
- Via a phishing email that tricks an unsuspected employee into clicking a link to a malicious website or opening an attachment that executes malicious code.
- Through security holes in browser plugins.
- By downloading malicious apps.
- With malicious code brought in on external devices, e.g. USB sticks.
- Via other infected software.
Once a machine is compromised, the hacker will ping the infected computer or device for a callback to test the new connection. The infected computer will then carry out the commands from the attacker’s C2 server and may install additional software. The attacker now has complete control of the victim’s computer and can execute any code. The malicious code will typically spread to more computers, creating a botnet – a network of infected machines. In this way, an attacker who is not authorised to access a company’s network can obtain full control of that network.
What Can Hackers Accomplish Through Command and Control?
C2 attacks pose real dangers to shipping companies, with potentially severe operational, financial and reputational risks. Typically, attackers want to achieve the following:
- Data exfiltration. Sensitive data, such as credentials, operational documents, financial data, employee records, and other sensitive information, can be copied or transferred to an attacker’s server.
- Shutdown. An attacker can shut down one or several machines, or even bring down a company’s network, ultimately bringing normal operations to a halt.
- Distributed denial of service. DDoS attacks disrupt or shut down web servers as well as entire networks. DDoS attacks overwhelm server or networks by flooding them with internet traffic. Once a botnet is established, an attacker can instruct each bot to send a request to the targeted IP address, creating a jam of requests for the targeted server. Legitimate traffic to the attacked IP address is denied.
Source: Dualog by Rune Larsen, Service Mark
Related News.
September 25, 2026
ISLAND OIL: Unveiling of the Sculpture “Cyprus’s Journey Through the Ages” in Protaras – A Tribute and Landmark to Cyprus’s Historical Memory and Cultural Heritage
In a modest ceremony marked by a moving atmosphere, the sculpture “Cyprus’s Journey Through the Ages”, created by acclaimed Cypriot sculptor…
September 25, 2026
World Maritime Day 2026 from Policy to Practice – powering Maritime Excellence
Global regulations will deliver safer, more resilient shipping when they are implemented worldwide. The international maritime community marks…
September 25, 2026
Diana Shipping announces Time Charter Contract for m/v DSI Polaris with Dai An Ocean Shipping
Diana Shipping , a global shipping company specializing in the ownership and bareboat charter-in of dry bulk vessels, announced that, through a…
September 25, 2026
Chief Economists Expect Global Economy to Stabilize, but Fiscal Constraints, Rising Living Costs and AI Investment Uncertainty Threaten Growth
The global economy is stabilizing, but the fiscal support that cushioned successive shocks since 2020 is unlikely to play the same role in the year…
September 25, 2026
V. welcomes its new graduate cohort as programme expands across the group
Twelve graduates from nine nationalities join 11th year of V.’s expanded international management programme. V., the global ship manager and marine…
September 25, 2026
From Policy to Practice: Why Seafarers Are the Key to Maritime Excellence
The shipping industry is no stranger to regulation. Seafarers and ship operators work within a vast framework of international conventions, national…
September 25, 2026
Intermodal Report – Week 38 2026
Please find below the Intermodal market report for week 38 2026. Intermodal Report Week 38 2026 Market Insight By Nikos Tagoulis, Head of…
September 25, 2026
Allied – Weekly Market Review – Week 38
Please find below the Allied Weekly Report for Week 38 | 2026 ALLIED - Weekly Market Report- Week 38
September 25, 2026
Record year on the Northeast Passage but Arctic shipping remains very limited
In 2025, a record 103 transit voyages were made via the Northeast Passage. However, this is still equivalent to only around a day and a half of…
September 25, 2026
[xclusiv] S&P Report 21th September 2026
Please find below the [xclusiv] latest Weekly S&P Report [xclusiv] 2026_09_21 Market Commentary: VLCCs: Freight Boom Reprices the Fleet The VLCC…
Subscribe to our newsletter!
if you dont want to swim alone in the ocean of news, sign up for the newsletter, and you will receive daily all the important news of world shipping!
Design & Development by P.KAN.DESIGNER
© 2026 Cyprus Shipping News. All rights reserved
Design & Development by P.KAN.DESIGNER
© 2026 Cyprus Shipping News. All rights reserved























