ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1090
Proxy
MalwareSocksbot

Socksbot can start SOCKS proxy threads.

T1090
Proxy
MalwarejRAT

jRAT can serve as a SOCKS proxy server.

T1090
Proxy
MalwareDridex

Dridex contains a backconnect module for tunneling network traffic through a victim's computer. Infected computers become part of a P2P botnet that can relay C2 traffic to other infected peers.

T1090
Proxy
MalwareVasport

Vasport is capable of tunneling though a proxy.

T1090
Proxy
MalwareWarzoneRAT

WarzoneRAT has the capability to act as a reverse proxy.

T1090
Proxy
Toolngrok

ngrok can be used to proxy connections to machines located behind NAT or firewalls.

T1090
Proxy
ToolFRP

FRP can proxy communications through a server in public IP space to local servers located behind a NAT or firewall.

T1090
Proxy
ToolPoshC2

PoshC2 contains modules that allow for use of proxies in command and control.

T1090
Proxy
Toolnetsh

netsh can be used to set up a proxy tunnel to allow remote host access to an infected host.

T1090
Proxy
ToolRemcos

Remcos uses the infected hosts as SOCKS5 proxies to allow for tunneling and proxying.

T1090
Proxy
ToolHTRAN

HTRAN can proxy TCP socket connections to obfuscate command and control infrastructure.

T1090
Proxy
ToolQuasarRAT

QuasarRAT can communicate over a reverse proxy using SOCKS5.

T1090
Proxy
MalwareKali365

Kali365 has leveraged Cloudflare workers as reverse proxy infrastructure.

T1090.001
Internal Proxy
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 used SSH port forwarding capabilities on public-facing systems, and configured at least one instance of Cobalt Strike to use a network pipe over SMB.

T1090.001
Internal Proxy
CampaignAPT28 Nearest Neighbor Campaign

During APT28 Nearest Neighbor Campaign, APT28 used the built-in netsh portproxy command to create internal proxies on compromised systems.

T1090.001
Internal Proxy
CampaignOperation Wocao

During Operation Wocao, threat actors proxied traffic through multiple infected systems.

T1090.001
Internal Proxy
GroupVolt Typhoon

Volt Typhoon has used the built-in netsh `port proxy` command to create proxies on compromised systems to facilitate access.

T1090.001
Internal Proxy
GroupStrider

Strider has used local servers with both local network and Internet access to act as internal proxy nodes to exfiltrate data from other parts of the network without direct Internet access.

T1090.001
Internal Proxy
GroupAPT39

APT39 used custom tools to create SOCK5 and custom protocol proxies between infected hosts.

T1090.001
Internal Proxy
GroupHigaisa

Higaisa discovered system proxy settings and used them if available.

T1090.001
Internal Proxy
GroupTurla

Turla has compromised internal network systems to act as a proxy to forward traffic to C2.

T1090.001
Internal Proxy
GroupLotus Blossom

Lotus Blossom has used publicly available tools such as the Venom proxy tool to proxy traffic out of victim environments.

T1090.001
Internal Proxy
GroupLazarus Group

Lazarus Group has used a compromised router to serve as a proxy between a victim network's corporate and restricted segments.

T1090.001
Internal Proxy
GroupVelvet Ant

Velvet Ant has tunneled traffic from victims through an internal, compromised host to proxy communications to command and control nodes.

T1090.001
Internal Proxy
GroupFIN13

FIN13 has utilized a proxy tool to communicate between compromised assets.

T1090.001
Internal Proxy
MalwareNinja

Ninja can proxy C2 communications including to and from internal agents without internet connectivity.

T1090.001
Internal Proxy
MalwareBRICKSTORM

BRICKSTORM has leveraged SOCKS Proxy to pivot into victim networks in attempts to resemble legitimate administrative traffic.

T1090.001
Internal Proxy
MalwareStuxnet

Stuxnet installs an RPC server for P2P communications.

T1090.001
Internal Proxy
MalwareGomir

Gomir can start a reverse proxy to initiate connections to arbitrary endpoints in victim networks.

T1090.001
Internal Proxy
MalwareMafalda

Mafalda can create a named pipe to listen for and send data to a named pipe-based C2 server.

T1090.001
Internal Proxy
MalwareInvisiMole

InvisiMole can function as a proxy to create a server that relays communication between the client and C&C server, or between two clients.

T1090.001
Internal Proxy
MalwareKazuar

Kazuar has used internal nodes on the compromised network for C2 communications.

T1090.001
Internal Proxy
MalwareFatDuke

FatDuke can used pipes to connect machines with restricted internet access to remote machines via other infected hosts.

T1090.001
Internal Proxy
MalwareMiniDuke

MiniDuke can can use a named pipe to forward communications from one compromised machine with internet access to other compromised machines.

T1090.001
Internal Proxy
MalwarePay2Key

Pay2Key has designated machines in the compromised network to serve as reverse proxy pivot points to channel communications with C2.

T1090.001
Internal Proxy
MalwareGlassWorm

GlassWorm has leveraged peer-to-peer software to facilitate communications within the victim network to include the software WebRTC. GlassWorm has also established a SOCKS proxy to interact with victim devices that also acted as a proxy node for follow-on behaviors.

T1090.001
Internal Proxy
MalwareHikit

Hikit supports peer connections.

T1090.001
Internal Proxy
MalwareDrovorub

Drovorub can use a port forwarding rule on its agent module to relay network traffic through the client module to a remote host on the same network.

T1090.001
Internal Proxy
MalwareHiddenFace

HiddenFace can act as an internal HTTP proxy within the targeted environment.

T1090.001
Internal Proxy
MalwareCobalt Strike

Cobalt Strike can be configured to have commands relayed over a peer-to-peer network of infected hosts. This can be used to limit the number of egress points, or provide access to a host without direct internet access.

T1090.001
Internal Proxy
MalwareCHOPSTICK

CHOPSTICK used a proxy server between victims and the C2 server.

T1090.001
Internal Proxy
MalwareWinnti for Windows

The Winnti for Windows HTTP/S C2 mode can make use of a local proxy.

T1090.001
Internal Proxy
MalwaremetaMain

metaMain can create a named pipe to listen for and send data to a named pipe-based C2 server.

T1090.001
Internal Proxy
MalwareStarProxy

StarProxy has proxied traffic between infected devices and their C2 servers.

T1090.001
Internal Proxy
MalwareBACKSPACE

The "ZJ" variant of BACKSPACE allows "ZJ link" infections with Internet access to relay traffic from "ZJ listen" to a command server.

T1090.001
Internal Proxy
ToolSliver

Sliver has a built-in SOCKS5 proxying capability allowing for Sliver clients to proxy network traffic through other clients within a victim network.

T1090.001
Internal Proxy
ToolMythic

Mythic can leverage a peer-to-peer C2 profile between agents.

T1090.001
Internal Proxy
MalwareDuqu

Duqu can be configured to have commands relayed over a peer-to-peer network of infected hosts if some of the hosts do not have Internet access.

T1090.002
External Proxy
CampaignQuad7 Activity

Quad7 Activity has initialized SOCKS5 proxies on compromised devices.

T1090.002
External Proxy
GroupGALLIUM

GALLIUM used a modified version of HTRAN to redirect connections between networks.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.