Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1090 Proxy |
GroupGamaredon Group | Gamaredon Group has used the Cloudflare Tunnel client to proxy C2 traffic. |
| T1090 Proxy |
GroupSandworm Team | Sandworm Team's BCS-server tool can create an internal proxy server to redirect traffic from the adversary-controlled C2 to internal servers which may not be connected to the internet, but are interconnected locally. |
| T1090 Proxy |
GroupScattered Spider | Scattered Spider has used proxy networks to hamper detection and has installed legitimate proxy tools on VMware vCenter and adversary-controlled VMs. |
| T1090 Proxy |
GroupContagious Interview | Contagious Interview has leveraged Astrill VPN for C2. |
| T1090 Proxy |
GroupWindigo | Windigo has delivered a generic Windows proxy Win32/Glubteta.M. Windigo has also used multiple reverse proxy chains as part of their C2 infrastructure. |
| T1090 Proxy |
GroupPOLONIUM | POLONIUM has used the AirVPN service for operational activity. |
| T1090 Proxy |
GroupMoustachedBouncer | MoustachedBouncer has used a reverse proxy tool similar to the GitHub repository revsocks. |
| T1090 Proxy |
GroupBlue Mockingbird | Blue Mockingbird has used FRP, ssf, and Venom to establish SOCKS proxy connections. |
| T1090 Proxy |
GroupTurla | Turla RPC backdoors have included local UPnP RPC proxies. |
| T1090 Proxy |
GroupCinnamon Tempest | Cinnamon Tempest has used a customized version of the Iox port-forwarding and proxy tool. |
| T1090 Proxy |
GroupMirrorFace | MirrorFace has used the GO Simple Tunnel (GOST) proxy tool. |
| T1090 Proxy |
GroupFox Kitten | Fox Kitten has used the open source reverse proxy tools including FRPC and Go Proxy to establish connections from C2 to local servers. |
| T1090 Proxy |
GroupEarth Lusca | Earth Lusca adopted Cloudflare as a proxy for compromised servers. |
| T1090 Proxy |
GroupLAPSUS$ | LAPSUS$ has leverage NordVPN for its egress points when targeting intended victims. |
| T1090 Proxy |
GroupCopyKittens | CopyKittens has used the AirVPN service for operational activity. |
| T1090 Proxy |
GroupMagic Hound | Magic Hound has used Fast Reverse Proxy (FRP) for RDP traffic. |
| T1090 Proxy |
MalwarereGeorg | reGeorg can establish an HTTP or SOCKS proxy to tunnel data in and out of a network. |
| T1090 Proxy |
MalwareUrsnif | Ursnif has used a peer-to-peer (P2P) network for C2. |
| T1090 Proxy |
MalwareRansomHub | RansomHub can use a proxy to connect to remote SFTP servers. |
| T1090 Proxy |
MalwareLITTLELAMB.WOOLTEA | LITTLELAMB.WOOLTEA has the ability to function as a SOCKS proxy. |
| T1090 Proxy |
MalwareHavoc | Havoc has the ability to route HTTP/S communications through designated proxies. |
| T1090 Proxy |
MalwareAuditCred | AuditCred can utilize proxy for communications. |
| T1090 Proxy |
MalwareRainyDay | RainyDay can use proxy tools including boost_proxy_client for reverse proxy functionality. |
| T1090 Proxy |
MalwareNETWIRE | NETWIRE can implement use of proxies to pivot traffic. |
| T1090 Proxy |
MalwareAria-body | Aria-body has the ability to use a reverse SOCKS proxy module. |
| T1090 Proxy |
MalwareBADHATCH | BADHATCH can use SOCKS4 and SOCKS5 proxies to connect to actor-controlled C2 servers. BADHATCH can also emulate a reverse proxy on a compromised machine to connect with actor-controlled C2 servers. |
| T1090 Proxy |
MalwareSombRAT | SombRAT has the ability to use an embedded SOCKS proxy in C2 communications. |
| T1090 Proxy |
MalwareHOPLIGHT | HOPLIGHT has multiple proxy options that mask traffic between the malware and the remote operators. |
| T1090 Proxy |
MalwareGreen Lambert | Green Lambert can use proxies for C2 traffic. |
| T1090 Proxy |
MalwareBisonal | Bisonal has supported use of a proxy server. |
| T1090 Proxy |
MalwareKEYPLUG | KEYPLUG has used Cloudflare CDN associated infrastructure to redirect C2 communications to malicious domains. |
| T1090 Proxy |
MalwareXTunnel | XTunnel relays traffic between a C2 server and a victim. |
| T1090 Proxy |
MalwareTSCookie | TSCookie has the ability to proxy communications with command and control (C2) servers. |
| T1090 Proxy |
MalwareTYPEFRAME | A TYPEFRAME variant can force the compromised system to function as a proxy server. |
| T1090 Proxy |
MalwareSagerunex | Sagerunex uses several proxy configuration settings to ensure connectivity. |
| T1090 Proxy |
MalwareSDBbot | SDBbot has the ability to use port forwarding to establish a proxy between a target host and C2. |
| T1090 Proxy |
MalwareGoBear | GoBear implements SOCKS5 proxy functionality. |
| T1090 Proxy |
MalwareBADCALL | BADCALL functions as a proxy server between the victim and C2 server. |
| T1090 Proxy |
MalwareKapeka | Kapeka can identify system proxy settings via `WinHttpGetIEProxyConfigForCurrentUser()` during initialization and utilize these settings for subsequent command and control operations. |
| T1090 Proxy |
MalwareSamurai | Samurai has the ability to proxy connections to specified remote IPs and ports through a a proxy module. |
| T1090 Proxy |
MalwarePLEAD | PLEAD has the ability to proxy network communications. |
| T1090 Proxy |
MalwareCardinal RAT | Cardinal RAT can act as a reverse proxy. |
| T1090 Proxy |
MalwareNeo-reGeorg | Neo-reGeorg has the ability to establish a SOCKS5 proxy on a compromised web server. |
| T1090 Proxy |
MalwareHARDRAIN | HARDRAIN uses the command |
| T1090 Proxy |
MalwareFunnyDream | FunnyDream can identify and use configured proxies in a compromised network for C2 communication. |
| T1090 Proxy |
MalwareKessel | Kessel can use a proxy during exfiltration if set in the configuration. |
| T1090 Proxy |
MalwareZxShell | ZxShell can set up an HTTP or SOCKS proxy. |
| T1090 Proxy |
MalwareZIPLINE | ZIPLINE can create a proxy server on compromised hosts. |
| T1090 Proxy |
MalwareKOCTOPUS | KOCTOPUS has deployed a modified version of Invoke-Ngrok to expose open local ports to the Internet. |
| T1090 Proxy |
MalwareLunarWeb | LunarWeb has the ability to use a HTTP proxy server for C&C communications. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.