Real-world descriptions of how a group, tool or campaign used a technique.
11362 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1090 Proxy |
MalwareNETWIRE | NETWIRE can implement use of proxies to pivot traffic. |
| T1090 Proxy |
MalwareAria-body | Aria-body has the ability to use a reverse SOCKS proxy module. |
| T1090 Proxy |
MalwareBADHATCH | BADHATCH can use SOCKS4 and SOCKS5 proxies to connect to actor-controlled C2 servers. BADHATCH can also emulate a reverse proxy on a compromised machine to connect with actor-controlled C2 servers. |
| T1090 Proxy |
MalwareSombRAT | SombRAT has the ability to use an embedded SOCKS proxy in C2 communications. |
| T1090 Proxy |
MalwareHOPLIGHT | HOPLIGHT has multiple proxy options that mask traffic between the malware and the remote operators. |
| T1090 Proxy |
MalwareGreen Lambert | Green Lambert can use proxies for C2 traffic. |
| T1090 Proxy |
MalwareBisonal | Bisonal has supported use of a proxy server. |
| T1090 Proxy |
MalwareKEYPLUG | KEYPLUG has used Cloudflare CDN associated infrastructure to redirect C2 communications to malicious domains. |
| T1090 Proxy |
MalwareXTunnel | XTunnel relays traffic between a C2 server and a victim. |
| T1090 Proxy |
MalwareTSCookie | TSCookie has the ability to proxy communications with command and control (C2) servers. |
| T1090 Proxy |
MalwareTYPEFRAME | A TYPEFRAME variant can force the compromised system to function as a proxy server. |
| T1090 Proxy |
MalwareSagerunex | Sagerunex uses several proxy configuration settings to ensure connectivity. |
| T1090 Proxy |
MalwareSDBbot | SDBbot has the ability to use port forwarding to establish a proxy between a target host and C2. |
| T1090 Proxy |
MalwareGoBear | GoBear implements SOCKS5 proxy functionality. |
| T1090 Proxy |
MalwareBADCALL | BADCALL functions as a proxy server between the victim and C2 server. |
| T1090 Proxy |
MalwareKapeka | Kapeka can identify system proxy settings via `WinHttpGetIEProxyConfigForCurrentUser()` during initialization and utilize these settings for subsequent command and control operations. |
| T1090 Proxy |
MalwareSamurai | Samurai has the ability to proxy connections to specified remote IPs and ports through a a proxy module. |
| T1090 Proxy |
MalwarePLEAD | PLEAD has the ability to proxy network communications. |
| T1090 Proxy |
MalwareCardinal RAT | Cardinal RAT can act as a reverse proxy. |
| T1090 Proxy |
MalwareNeo-reGeorg | Neo-reGeorg has the ability to establish a SOCKS5 proxy on a compromised web server. |
| T1090 Proxy |
MalwareHARDRAIN | HARDRAIN uses the command |
| T1090 Proxy |
MalwareFunnyDream | FunnyDream can identify and use configured proxies in a compromised network for C2 communication. |
| T1090 Proxy |
MalwareKessel | Kessel can use a proxy during exfiltration if set in the configuration. |
| T1090 Proxy |
MalwareZxShell | ZxShell can set up an HTTP or SOCKS proxy. |
| T1090 Proxy |
MalwareZIPLINE | ZIPLINE can create a proxy server on compromised hosts. |
| T1090 Proxy |
MalwareKOCTOPUS | KOCTOPUS has deployed a modified version of Invoke-Ngrok to expose open local ports to the Internet. |
| T1090 Proxy |
MalwareLunarWeb | LunarWeb has the ability to use a HTTP proxy server for C&C communications. |
| T1090 Proxy |
MalwareSocksbot | Socksbot can start SOCKS proxy threads. |
| T1090 Proxy |
MalwarejRAT | jRAT can serve as a SOCKS proxy server. |
| T1090 Proxy |
MalwareDridex | Dridex contains a backconnect module for tunneling network traffic through a victim's computer. Infected computers become part of a P2P botnet that can relay C2 traffic to other infected peers. |
| T1090 Proxy |
MalwareVasport | Vasport is capable of tunneling though a proxy. |
| T1090 Proxy |
MalwareWarzoneRAT | WarzoneRAT has the capability to act as a reverse proxy. |
| T1090 Proxy |
Toolngrok | ngrok can be used to proxy connections to machines located behind NAT or firewalls. |
| T1090 Proxy |
ToolFRP | FRP can proxy communications through a server in public IP space to local servers located behind a NAT or firewall. |
| T1090 Proxy |
ToolPoshC2 | PoshC2 contains modules that allow for use of proxies in command and control. |
| T1090 Proxy |
Toolnetsh | netsh can be used to set up a proxy tunnel to allow remote host access to an infected host. |
| T1090 Proxy |
ToolRemcos | Remcos uses the infected hosts as SOCKS5 proxies to allow for tunneling and proxying. |
| T1090 Proxy |
ToolHTRAN | HTRAN can proxy TCP socket connections to obfuscate command and control infrastructure. |
| T1090 Proxy |
ToolQuasarRAT | QuasarRAT can communicate over a reverse proxy using SOCKS5. |
| T1090 Proxy |
MalwareKali365 | Kali365 has leveraged Cloudflare workers as reverse proxy infrastructure. |
| T1090.001 Internal Proxy |
MalwareNinja | Ninja can proxy C2 communications including to and from internal agents without internet connectivity. |
| T1090.001 Internal Proxy |
MalwareBRICKSTORM | BRICKSTORM has leveraged SOCKS Proxy to pivot into victim networks in attempts to resemble legitimate administrative traffic. |
| T1090.001 Internal Proxy |
MalwareStuxnet | Stuxnet installs an RPC server for P2P communications. |
| T1090.001 Internal Proxy |
MalwareGomir | Gomir can start a reverse proxy to initiate connections to arbitrary endpoints in victim networks. |
| T1090.001 Internal Proxy |
MalwareMafalda | Mafalda can create a named pipe to listen for and send data to a named pipe-based C2 server. |
| T1090.001 Internal Proxy |
MalwareInvisiMole | InvisiMole can function as a proxy to create a server that relays communication between the client and C&C server, or between two clients. |
| T1090.001 Internal Proxy |
MalwareKazuar | Kazuar has used internal nodes on the compromised network for C2 communications. |
| T1090.001 Internal Proxy |
MalwareFatDuke | FatDuke can used pipes to connect machines with restricted internet access to remote machines via other infected hosts. |
| T1090.001 Internal Proxy |
MalwareMiniDuke | MiniDuke can can use a named pipe to forward communications from one compromised machine with internet access to other compromised machines. |
| T1090.001 Internal Proxy |
MalwarePay2Key | Pay2Key has designated machines in the compromised network to serve as reverse proxy pivot points to channel communications with C2. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.