What are command-and-control (C2) callbacks?

Malicious hacker attacks have been on the rise in the last couple of years. One of the most damaging attacks, often executed over DNS, is accomplished through command and control, also called C2 or C&C callbacks. Let’s have a look at how the hackers use this technique to infect their victims.
What is a C2 server?
A command-and-control server is a computer that is controlled by a cybercriminal. Command-and-control servers are used by attackers to maintain communications and send commands to systems inside a target network compromised by malware. These systems can include computers, smartphones, and even IoT devices connected to the network.
How are C2 servers used?
C2 servers act as command centres from where malware receives their commands. They are also used to collect and store stolen data. Establishing C2 communications is a vital step for attackers to access network resources.
The attacker starts by infecting a computer, which may sit behind a firewall. This can be achieved in several ways:
- Via a phishing email that tricks an unsuspected employee into clicking a link to a malicious website or opening an attachment that executes malicious code.
- Through security holes in browser plugins.
- By downloading malicious apps.
- With malicious code brought in on external devices, e.g. USB sticks.
- Via other infected software.
Once a machine is compromised, the hacker will ping the infected computer or device for a callback to test the new connection. The infected computer will then carry out the commands from the attacker’s C2 server and may install additional software. The attacker now has complete control of the victim’s computer and can execute any code. The malicious code will typically spread to more computers, creating a botnet – a network of infected machines. In this way, an attacker who is not authorised to access a company’s network can obtain full control of that network.
What Can Hackers Accomplish Through Command and Control?
C2 attacks pose real dangers to shipping companies, with potentially severe operational, financial and reputational risks. Typically, attackers want to achieve the following:
- Data exfiltration. Sensitive data, such as credentials, operational documents, financial data, employee records, and other sensitive information, can be copied or transferred to an attacker’s server.
- Shutdown. An attacker can shut down one or several machines, or even bring down a company’s network, ultimately bringing normal operations to a halt.
- Distributed denial of service. DDoS attacks disrupt or shut down web servers as well as entire networks. DDoS attacks overwhelm server or networks by flooding them with internet traffic. Once a botnet is established, an attacker can instruct each bot to send a request to the targeted IP address, creating a jam of requests for the targeted server. Legitimate traffic to the attacked IP address is denied.
Source: Dualog by Rune Larsen, Service Mark
Related News.
September 3, 2026
Cyprus Maritime Innovation takes Centre Stage at SMM Hamburg 2026
Underscoring its expanding role as a premier international hub for cutting-edge maritime technology and sustainable shipping, the Republic of Cyprus…
September 3, 2026
Trump seeks to refill US oil reserve with Venezuela deal but faces long delay
U.S. President Donald Trump said on the 30th (local time) that he would refill the U.S. Strategic Petroleum Reserve, which has been depleted with…
September 3, 2026
US Navy Official visits South Korean Shipyards in private
With U.S. President Donald Trump pushing a plan to allow overseas construction of U.S. warships, attention is focusing on whether the building of…
September 3, 2026
SES and De Boer Marine expand collaboration with FlexMaritime deployment across Global Markets
SES, a leading space solutions company, and De Boer Marine, a leading provider of top-quality marine equipment and maritime connectivity services,…
September 3, 2026
New ESG guidance to help maritime industry turn sustainability into commercial advantage
New framework helps shipowners and ports align ESG strategy with access to capital, charterer expectations and long-term asset value. Maritime…
September 3, 2026
Britannia P&I Club analysis finds four in five crew deaths linked to illness rather than accidents
New report highlights cardiovascular disease as leading cause of fatalities and raises concerns over mental health risks among younger seafarers.…
September 3, 2026
The Swedish Club launches new Loss Prevention podcast, Knot Another Lesson
The Swedish Club has launched Knot Another Lesson, a new podcast exploring the practical lessons, emerging risks and operational challenges shaping…
September 3, 2026
Lloyd’s Register appoints Jens Grunenberg as Senior Representative for Germany
Lloyd’s Register has appointed Jens Grunenberg as its Senior Representative for Germany, effective 1 September. Based in Hamburg, Grunenberg will…
September 3, 2026
Indian Register of Shipping sets sights on Hamburg for European Expansion
Indian Register of Shipping, a leading international classification society and full member of the International Association of Classification…
September 3, 2026
MOL completes Merger of 6 Ship Management Companies
Unifying Management of Over 200 Vessels and Strengthening Safety Mitsui O.S.K. Lines, announced that it has completed the integration of the MOL…
Subscribe to our newsletter!
if you dont want to swim alone in the ocean of news, sign up for the newsletter, and you will receive daily all the important news of world shipping!
Design & Development by P.KAN.DESIGNER
© 2026 Cyprus Shipping News. All rights reserved
Design & Development by P.KAN.DESIGNER
© 2026 Cyprus Shipping News. All rights reserved























