Adversaries may establish command and control capabilities over commonly used application layer protocols such as HTTP(S), OPC, RDP, telnet, DNP3, and modbus. These protocols may be used to disguise adversary actions as benign network traffic. Stuxnet uses a thread to monitor a data block DB890 of sequence A or B. This thread is constantly running and probing this block (every 5 minutes) on infected PLCs. Triton can communicate with the implant utilizing the TriStation ‘get main processor diagnostic data’ command and looks for a specifically crafted packet body from which it extracts a command value.”]
Source: https://collaborate.mitre.org/attackics/index.php/Technique/T0869