Yes, exactly.
If this kind of thing interests you, this article about Flame is absolutely fascinating:
http://www.symantec.com/content/en/us/enterprise/media/secur...
Hard to believe it was already almost six years ago.
> On both servers command and-control activity happens through a Web
application called Newsforyou. It processes the W32.Flamer client
interactions and provides a simple control panel. The control panel
allows the attackers to upload packages of code to deliver to
compromised clients, and download packages containing stolen client
data. However, in a technique not previously seen before the uploaded
and downloaded packages are encrypted, so infiltrating the
command-and-control server does not reveal the code or the stolen
client data. The command and-control server simply serves as a proxy
for the data and the data is encrypted and decrypted offline by the
attackers using keys unique to each client. This application also
contains functionality to communicate with clients compromised by
malware other than Flamer. The Web application was designed to be a
framework for supporting different malware campaigns.
> In addition to avoiding the compromise of their operations, preventing
both the uploading of rogue code and viewing of stolen data, the setup
also maintains a clear distinction of roles. The roles include those
responsible for setting up the server (admins), those responsible for
uploading packages and downloading stolen data through the control
panel (operators), and those holding the private key with the ability
to decrypt the stolen data (attack coordinators). The operators
themselves may actually be completely unaware of the contents in the
stolen data. This is due to design of the process to use data security
compartmentalization techniques, as shown in Figure 1.
> Despite these techniques, we were still able to determine that one of
the servers delivered a module instructing Flamer to commit suicide
and wipe itself off computers in late May 2012, an action we also
witnessed through compromised honeypots.
> Finally, access to the control panel required a password which is
stored as a hash. Despite brute force attempts at reversing the hash
to plain text, we were unable to determine the plain text password.
The whole thing is filled with gems like that. They controlled the virus with a PHP webapp called "news for you!" presumably with a sly winky face emoji appended to the <title> tag.