Real-world descriptions of how a group, tool or campaign used a technique.
11362 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1090.001 Internal Proxy |
MalwareGlassWorm | GlassWorm has leveraged peer-to-peer software to facilitate communications within the victim network to include the software WebRTC. GlassWorm has also established a SOCKS proxy to interact with victim devices that also acted as a proxy node for follow-on behaviors. |
| T1090.001 Internal Proxy |
MalwareHikit | Hikit supports peer connections. |
| T1090.001 Internal Proxy |
MalwareDrovorub | Drovorub can use a port forwarding rule on its agent module to relay network traffic through the client module to a remote host on the same network. |
| T1090.001 Internal Proxy |
MalwareHiddenFace | HiddenFace can act as an internal HTTP proxy within the targeted environment. |
| T1090.001 Internal Proxy |
MalwareCobalt Strike | Cobalt Strike can be configured to have commands relayed over a peer-to-peer network of infected hosts. This can be used to limit the number of egress points, or provide access to a host without direct internet access. |
| T1090.001 Internal Proxy |
MalwareCHOPSTICK | CHOPSTICK used a proxy server between victims and the C2 server. |
| T1090.001 Internal Proxy |
MalwareWinnti for Windows | The Winnti for Windows HTTP/S C2 mode can make use of a local proxy. |
| T1090.001 Internal Proxy |
MalwaremetaMain | metaMain can create a named pipe to listen for and send data to a named pipe-based C2 server. |
| T1090.001 Internal Proxy |
MalwareStarProxy | StarProxy has proxied traffic between infected devices and their C2 servers. |
| T1090.001 Internal Proxy |
MalwareBACKSPACE | The "ZJ" variant of BACKSPACE allows "ZJ link" infections with Internet access to relay traffic from "ZJ listen" to a command server. |
| T1090.001 Internal Proxy |
ToolSliver | Sliver has a built-in SOCKS5 proxying capability allowing for Sliver clients to proxy network traffic through other clients within a victim network. |
| T1090.001 Internal Proxy |
ToolMythic | Mythic can leverage a peer-to-peer C2 profile between agents. |
| T1090.001 Internal Proxy |
MalwareDuqu | Duqu can be configured to have commands relayed over a peer-to-peer network of infected hosts if some of the hosts do not have Internet access. |
| T1090.002 External Proxy |
MalwareTrickBot | TrickBot has been known to reach a command and control server via one of nine proxy IP addresses. |
| T1090.002 External Proxy |
MalwareInvisiMole | InvisiMole InvisiMole can identify proxy servers used by the victim and use them for C2 communication. |
| T1090.002 External Proxy |
MalwareQUIETEXIT | QUIETEXIT can proxy traffic via SOCKS. |
| T1090.002 External Proxy |
MalwareOkrum | Okrum can identify proxy servers configured and used by the victim, and use it to make HTTP requests to C2 its server. |
| T1090.002 External Proxy |
MalwareRegin | Regin leveraged several compromised universities as proxies to obscure its origin. |
| T1090.002 External Proxy |
MalwareShimRat | ShimRat can use pre-configured HTTP proxies. |
| T1090.002 External Proxy |
MalwareWinnti for Windows | The Winnti for Windows HTTP/S C2 mode can make use of an external proxy. |
| T1090.002 External Proxy |
MalwarePOWERSTATS | POWERSTATS has connected to C2 servers through proxies. |
| T1090.002 External Proxy |
MalwareQakBot | QakBot has a module that can proxy C2 communications. |
| T1090.002 External Proxy |
Toolevilginx2 | evilginx2 can route traffic via SOCKS5 and HTTP(S) proxies between an intended phishing victim's machine and legitimate websites. |
| T1090.002 External Proxy |
ToolMythic | Mythic can leverage a modified SOCKS5 proxy to tunnel egress C2 traffic. |
| T1090.003 Multi-hop Proxy |
MalwareNinja | Ninja has the ability to use a proxy chain with up to 255 hops when using TCP. |
| T1090.003 Multi-hop Proxy |
MalwareUrsnif | |
| T1090.003 Multi-hop Proxy |
MalwareStrongPity | StrongPity can use multiple layers of proxy servers to hide terminal nodes in its infrastructure. |
| T1090.003 Multi-hop Proxy |
MalwareGreyEnergy | GreyEnergy has used Tor relays for Command and Control servers. |
| T1090.003 Multi-hop Proxy |
MalwareBOLDMOVE | BOLDMOVE is capable of relaying traffic from command and control servers to follow-on systems. |
| T1090.003 Multi-hop Proxy |
MalwareSystemBC | SystemBC has used multiple proxy layers, such as SOCKS5 and Tor, for C2 communication. SystemBC has also leveraged Tor for encrypting and concealing C2 traffic. The server component of SystemBC has used SOCKS5 for C2 communication. |
| T1090.003 Multi-hop Proxy |
MalwareKeydnap | Keydnap uses a copy of tor2web proxy for HTTPS communications. |
| T1090.003 Multi-hop Proxy |
MalwareSiloscape | |
| T1090.003 Multi-hop Proxy |
MalwareNGLite | NGLite has abused NKN infrastructure for its C2 communication. |
| T1090.003 Multi-hop Proxy |
MalwareWannaCry | |
| T1090.003 Multi-hop Proxy |
MalwareUroburos | Uroburos can use implants on multiple compromised machines to proxy communications through its worldwide P2P network. |
| T1090.003 Multi-hop Proxy |
MalwareAttor | |
| T1090.003 Multi-hop Proxy |
MalwareKobalos | Kobalos can chain together multiple compromised machines as proxies to reach their final targets. |
| T1090.003 Multi-hop Proxy |
MalwareCyclops Blink | Cyclops Blink has used Tor nodes for C2 traffic. |
| T1090.003 Multi-hop Proxy |
MalwareNKAbuse | NKAbuse has abused the NKN public blockchain protocol for its C2 communications. |
| T1090.003 Multi-hop Proxy |
MalwareIndustroyer | Industroyer used Tor nodes for C2. |
| T1090.003 Multi-hop Proxy |
MalwareDridex | Dridex can use multiple layers of proxy servers to hide terminal nodes in its infrastructure. |
| T1090.003 Multi-hop Proxy |
MalwareDok | |
| T1090.003 Multi-hop Proxy |
MalwareMacSpy | |
| T1090.003 Multi-hop Proxy |
ToolFRP | The FRP client can be configured to connect to the server through a proxy. |
| T1090.003 Multi-hop Proxy |
ToolAsyncRAT | |
| T1090.003 Multi-hop Proxy |
ToolTor | Traffic traversing the Tor network will be forwarded to multiple nodes before exiting the Tor network and continuing on to its intended destination. |
| T1090.003 Multi-hop Proxy |
MalwareMini Shai-Hulud | Mini Shai-Hulud has the ability to exfiltrate stolen credentials via the Session messenger network. |
| T1090.004 Domain Fronting |
MalwareSMOKEDHAM | SMOKEDHAM has used a fronted domain to obfuscate its hard-coded C2 server domain. |
| T1090.004 Domain Fronting |
MalwareCobalt Strike | Cobalt Strike has the ability to accept a value for HTTP Host Header to enable domain fronting. |
| T1090.004 Domain Fronting |
Toolmeek | meek uses Domain Fronting to disguise the destination of network traffic as another server that is hosted in the same Content Delivery Network (CDN) as the intended destination. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.