There are many C2 Frameworks that use popular legitimate domains such as google, twitter, github, discord, … in order to fly undetected under SOC’s radar. The complete list of these domains can be found here : https://lots-project.com/ Here is an example of a such frameworks : GitHub - 3ct0s/disctopia-c2: Windows Backdoor that is controlled through Discord
Disctopia Command and Control Disctopia is an open source Python Discord Bot that works as a backdoor that you can…github.com