logoalt Hacker News

lisbbblast Sunday at 9:08 PM1 replyview on HN

But the malware was encoded as an image, how is it runnable on the target's smartphone?


Replies

richbelllast Sunday at 10:43 PM

The purpose of command and control servers is to send and receive data to victims devices.

A secondary goal is to do so while evading detection. This is why many threat actors piggy-back off of legitimate services, it disguises the malware communications and avoids directly exposing the upstream C2 instance.