ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1090
Proxy
GroupGamaredon Group

Gamaredon Group has used the Cloudflare Tunnel client to proxy C2 traffic.

T1090
Proxy
GroupSandworm Team

Sandworm Team's BCS-server tool can create an internal proxy server to redirect traffic from the adversary-controlled C2 to internal servers which may not be connected to the internet, but are interconnected locally.

T1090
Proxy
GroupScattered Spider

Scattered Spider has used proxy networks to hamper detection and has installed legitimate proxy tools on VMware vCenter and adversary-controlled VMs.

T1090
Proxy
GroupContagious Interview

Contagious Interview has leveraged Astrill VPN for C2.

T1090
Proxy
GroupWindigo

Windigo has delivered a generic Windows proxy Win32/Glubteta.M. Windigo has also used multiple reverse proxy chains as part of their C2 infrastructure.

T1090
Proxy
GroupPOLONIUM

POLONIUM has used the AirVPN service for operational activity.

T1090
Proxy
GroupMoustachedBouncer

MoustachedBouncer has used a reverse proxy tool similar to the GitHub repository revsocks.

T1090
Proxy
GroupBlue Mockingbird

Blue Mockingbird has used FRP, ssf, and Venom to establish SOCKS proxy connections.

T1090
Proxy
GroupTurla

Turla RPC backdoors have included local UPnP RPC proxies.

T1090
Proxy
GroupCinnamon Tempest

Cinnamon Tempest has used a customized version of the Iox port-forwarding and proxy tool.

T1090
Proxy
GroupMirrorFace

MirrorFace has used the GO Simple Tunnel (GOST) proxy tool.

T1090
Proxy
GroupFox Kitten

Fox Kitten has used the open source reverse proxy tools including FRPC and Go Proxy to establish connections from C2 to local servers.

T1090
Proxy
GroupEarth Lusca

Earth Lusca adopted Cloudflare as a proxy for compromised servers.

T1090
Proxy
GroupLAPSUS$

LAPSUS$ has leverage NordVPN for its egress points when targeting intended victims.

T1090
Proxy
GroupCopyKittens

CopyKittens has used the AirVPN service for operational activity.

T1090
Proxy
GroupMagic Hound

Magic Hound has used Fast Reverse Proxy (FRP) for RDP traffic.

T1090
Proxy
MalwarereGeorg

reGeorg can establish an HTTP or SOCKS proxy to tunnel data in and out of a network.

T1090
Proxy
MalwareUrsnif

Ursnif has used a peer-to-peer (P2P) network for C2.

T1090
Proxy
MalwareRansomHub

RansomHub can use a proxy to connect to remote SFTP servers.

T1090
Proxy
MalwareLITTLELAMB.WOOLTEA

LITTLELAMB.WOOLTEA has the ability to function as a SOCKS proxy.

T1090
Proxy
MalwareHavoc

Havoc has the ability to route HTTP/S communications through designated proxies.

T1090
Proxy
MalwareAuditCred

AuditCred can utilize proxy for communications.

T1090
Proxy
MalwareRainyDay

RainyDay can use proxy tools including boost_proxy_client for reverse proxy functionality.

T1090
Proxy
MalwareNETWIRE

NETWIRE can implement use of proxies to pivot traffic.

T1090
Proxy
MalwareAria-body

Aria-body has the ability to use a reverse SOCKS proxy module.

T1090
Proxy
MalwareBADHATCH

BADHATCH can use SOCKS4 and SOCKS5 proxies to connect to actor-controlled C2 servers. BADHATCH can also emulate a reverse proxy on a compromised machine to connect with actor-controlled C2 servers.

T1090
Proxy
MalwareSombRAT

SombRAT has the ability to use an embedded SOCKS proxy in C2 communications.

T1090
Proxy
MalwareHOPLIGHT

HOPLIGHT has multiple proxy options that mask traffic between the malware and the remote operators.

T1090
Proxy
MalwareGreen Lambert

Green Lambert can use proxies for C2 traffic.

T1090
Proxy
MalwareBisonal

Bisonal has supported use of a proxy server.

T1090
Proxy
MalwareKEYPLUG

KEYPLUG has used Cloudflare CDN associated infrastructure to redirect C2 communications to malicious domains.

T1090
Proxy
MalwareXTunnel

XTunnel relays traffic between a C2 server and a victim.

T1090
Proxy
MalwareTSCookie

TSCookie has the ability to proxy communications with command and control (C2) servers.

T1090
Proxy
MalwareTYPEFRAME

A TYPEFRAME variant can force the compromised system to function as a proxy server.

T1090
Proxy
MalwareSagerunex

Sagerunex uses several proxy configuration settings to ensure connectivity.

T1090
Proxy
MalwareSDBbot

SDBbot has the ability to use port forwarding to establish a proxy between a target host and C2.

T1090
Proxy
MalwareGoBear

GoBear implements SOCKS5 proxy functionality.

T1090
Proxy
MalwareBADCALL

BADCALL functions as a proxy server between the victim and C2 server.

T1090
Proxy
MalwareKapeka

Kapeka can identify system proxy settings via `WinHttpGetIEProxyConfigForCurrentUser()` during initialization and utilize these settings for subsequent command and control operations.

T1090
Proxy
MalwareSamurai

Samurai has the ability to proxy connections to specified remote IPs and ports through a a proxy module.

T1090
Proxy
MalwarePLEAD

PLEAD has the ability to proxy network communications.

T1090
Proxy
MalwareCardinal RAT

Cardinal RAT can act as a reverse proxy.

T1090
Proxy
MalwareNeo-reGeorg

Neo-reGeorg has the ability to establish a SOCKS5 proxy on a compromised web server.

T1090
Proxy
MalwareHARDRAIN

HARDRAIN uses the command cmd.exe /c netsh firewall add portopening TCP 443 "adp" and makes the victim machine function as a proxy server.

T1090
Proxy
MalwareFunnyDream

FunnyDream can identify and use configured proxies in a compromised network for C2 communication.

T1090
Proxy
MalwareKessel

Kessel can use a proxy during exfiltration if set in the configuration.

T1090
Proxy
MalwareZxShell

ZxShell can set up an HTTP or SOCKS proxy.

T1090
Proxy
MalwareZIPLINE

ZIPLINE can create a proxy server on compromised hosts.

T1090
Proxy
MalwareKOCTOPUS

KOCTOPUS has deployed a modified version of Invoke-Ngrok to expose open local ports to the Internet.

T1090
Proxy
MalwareLunarWeb

LunarWeb has the ability to use a HTTP proxy server for C&C communications.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.