ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

11362 examples

TechniqueUsed byProcedure example
T1090.001
Internal Proxy
MalwareGlassWorm

GlassWorm has leveraged peer-to-peer software to facilitate communications within the victim network to include the software WebRTC. GlassWorm has also established a SOCKS proxy to interact with victim devices that also acted as a proxy node for follow-on behaviors.

T1090.001
Internal Proxy
MalwareHikit

Hikit supports peer connections.

T1090.001
Internal Proxy
MalwareDrovorub

Drovorub can use a port forwarding rule on its agent module to relay network traffic through the client module to a remote host on the same network.

T1090.001
Internal Proxy
MalwareHiddenFace

HiddenFace can act as an internal HTTP proxy within the targeted environment.

T1090.001
Internal Proxy
MalwareCobalt Strike

Cobalt Strike can be configured to have commands relayed over a peer-to-peer network of infected hosts. This can be used to limit the number of egress points, or provide access to a host without direct internet access.

T1090.001
Internal Proxy
MalwareCHOPSTICK

CHOPSTICK used a proxy server between victims and the C2 server.

T1090.001
Internal Proxy
MalwareWinnti for Windows

The Winnti for Windows HTTP/S C2 mode can make use of a local proxy.

T1090.001
Internal Proxy
MalwaremetaMain

metaMain can create a named pipe to listen for and send data to a named pipe-based C2 server.

T1090.001
Internal Proxy
MalwareStarProxy

StarProxy has proxied traffic between infected devices and their C2 servers.

T1090.001
Internal Proxy
MalwareBACKSPACE

The "ZJ" variant of BACKSPACE allows "ZJ link" infections with Internet access to relay traffic from "ZJ listen" to a command server.

T1090.001
Internal Proxy
ToolSliver

Sliver has a built-in SOCKS5 proxying capability allowing for Sliver clients to proxy network traffic through other clients within a victim network.

T1090.001
Internal Proxy
ToolMythic

Mythic can leverage a peer-to-peer C2 profile between agents.

T1090.001
Internal Proxy
MalwareDuqu

Duqu can be configured to have commands relayed over a peer-to-peer network of infected hosts if some of the hosts do not have Internet access.

T1090.002
External Proxy
MalwareTrickBot

TrickBot has been known to reach a command and control server via one of nine proxy IP addresses.

T1090.002
External Proxy
MalwareInvisiMole

InvisiMole InvisiMole can identify proxy servers used by the victim and use them for C2 communication.

T1090.002
External Proxy
MalwareQUIETEXIT

QUIETEXIT can proxy traffic via SOCKS.

T1090.002
External Proxy
MalwareOkrum

Okrum can identify proxy servers configured and used by the victim, and use it to make HTTP requests to C2 its server.

T1090.002
External Proxy
MalwareRegin

Regin leveraged several compromised universities as proxies to obscure its origin.

T1090.002
External Proxy
MalwareShimRat

ShimRat can use pre-configured HTTP proxies.

T1090.002
External Proxy
MalwareWinnti for Windows

The Winnti for Windows HTTP/S C2 mode can make use of an external proxy.

T1090.002
External Proxy
MalwarePOWERSTATS

POWERSTATS has connected to C2 servers through proxies.

T1090.002
External Proxy
MalwareQakBot

QakBot has a module that can proxy C2 communications.

T1090.002
External Proxy
Toolevilginx2

evilginx2 can route traffic via SOCKS5 and HTTP(S) proxies between an intended phishing victim's machine and legitimate websites.

T1090.002
External Proxy
ToolMythic

Mythic can leverage a modified SOCKS5 proxy to tunnel egress C2 traffic.

T1090.003
Multi-hop Proxy
MalwareNinja

Ninja has the ability to use a proxy chain with up to 255 hops when using TCP.

T1090.003
Multi-hop Proxy
MalwareUrsnif

Ursnif has used Tor for C2.

T1090.003
Multi-hop Proxy
MalwareStrongPity

StrongPity can use multiple layers of proxy servers to hide terminal nodes in its infrastructure.

T1090.003
Multi-hop Proxy
MalwareGreyEnergy

GreyEnergy has used Tor relays for Command and Control servers.

T1090.003
Multi-hop Proxy
MalwareBOLDMOVE

BOLDMOVE is capable of relaying traffic from command and control servers to follow-on systems.

T1090.003
Multi-hop Proxy
MalwareSystemBC

SystemBC has used multiple proxy layers, such as SOCKS5 and Tor, for C2 communication. SystemBC has also leveraged Tor for encrypting and concealing C2 traffic. The server component of SystemBC has used SOCKS5 for C2 communication.

T1090.003
Multi-hop Proxy
MalwareKeydnap

Keydnap uses a copy of tor2web proxy for HTTPS communications.

T1090.003
Multi-hop Proxy
MalwareSiloscape

Siloscape uses Tor to communicate with C2.

T1090.003
Multi-hop Proxy
MalwareNGLite

NGLite has abused NKN infrastructure for its C2 communication.

T1090.003
Multi-hop Proxy
MalwareWannaCry

WannaCry uses Tor for command and control traffic.

T1090.003
Multi-hop Proxy
MalwareUroburos

Uroburos can use implants on multiple compromised machines to proxy communications through its worldwide P2P network.

T1090.003
Multi-hop Proxy
MalwareAttor

Attor has used Tor for C2 communication.

T1090.003
Multi-hop Proxy
MalwareKobalos

Kobalos can chain together multiple compromised machines as proxies to reach their final targets.

T1090.003
Multi-hop Proxy
MalwareCyclops Blink

Cyclops Blink has used Tor nodes for C2 traffic.

T1090.003
Multi-hop Proxy
MalwareNKAbuse

NKAbuse has abused the NKN public blockchain protocol for its C2 communications.

T1090.003
Multi-hop Proxy
MalwareIndustroyer

Industroyer used Tor nodes for C2.

T1090.003
Multi-hop Proxy
MalwareDridex

Dridex can use multiple layers of proxy servers to hide terminal nodes in its infrastructure.

T1090.003
Multi-hop Proxy
MalwareDok

Dok downloads and installs Tor via homebrew.

T1090.003
Multi-hop Proxy
MalwareMacSpy

MacSpy uses Tor for command and control.

T1090.003
Multi-hop Proxy
ToolFRP

The FRP client can be configured to connect to the server through a proxy.

T1090.003
Multi-hop Proxy
ToolAsyncRAT

AsyncRAT can proxy C2 through a Tor client.

T1090.003
Multi-hop Proxy
ToolTor

Traffic traversing the Tor network will be forwarded to multiple nodes before exiting the Tor network and continuing on to its intended destination.

T1090.003
Multi-hop Proxy
MalwareMini Shai-Hulud

Mini Shai-Hulud has the ability to exfiltrate stolen credentials via the Session messenger network.

T1090.004
Domain Fronting
MalwareSMOKEDHAM

SMOKEDHAM has used a fronted domain to obfuscate its hard-coded C2 server domain.

T1090.004
Domain Fronting
MalwareCobalt Strike

Cobalt Strike has the ability to accept a value for HTTP Host Header to enable domain fronting.

T1090.004
Domain Fronting
Toolmeek

meek uses Domain Fronting to disguise the destination of network traffic as another server that is hosted in the same Content Delivery Network (CDN) as the intended destination.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.