Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1090 Proxy |
MalwareSocksbot | Socksbot can start SOCKS proxy threads. |
| T1090 Proxy |
MalwarejRAT | jRAT can serve as a SOCKS proxy server. |
| T1090 Proxy |
MalwareDridex | Dridex contains a backconnect module for tunneling network traffic through a victim's computer. Infected computers become part of a P2P botnet that can relay C2 traffic to other infected peers. |
| T1090 Proxy |
MalwareVasport | Vasport is capable of tunneling though a proxy. |
| T1090 Proxy |
MalwareWarzoneRAT | WarzoneRAT has the capability to act as a reverse proxy. |
| T1090 Proxy |
Toolngrok | ngrok can be used to proxy connections to machines located behind NAT or firewalls. |
| T1090 Proxy |
ToolFRP | FRP can proxy communications through a server in public IP space to local servers located behind a NAT or firewall. |
| T1090 Proxy |
ToolPoshC2 | PoshC2 contains modules that allow for use of proxies in command and control. |
| T1090 Proxy |
Toolnetsh | netsh can be used to set up a proxy tunnel to allow remote host access to an infected host. |
| T1090 Proxy |
ToolRemcos | Remcos uses the infected hosts as SOCKS5 proxies to allow for tunneling and proxying. |
| T1090 Proxy |
ToolHTRAN | HTRAN can proxy TCP socket connections to obfuscate command and control infrastructure. |
| T1090 Proxy |
ToolQuasarRAT | QuasarRAT can communicate over a reverse proxy using SOCKS5. |
| T1090 Proxy |
MalwareKali365 | Kali365 has leveraged Cloudflare workers as reverse proxy infrastructure. |
| T1090.001 Internal Proxy |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 used SSH port forwarding capabilities on public-facing systems, and configured at least one instance of Cobalt Strike to use a network pipe over SMB. |
| T1090.001 Internal Proxy |
CampaignAPT28 Nearest Neighbor Campaign | During APT28 Nearest Neighbor Campaign, APT28 used the built-in |
| T1090.001 Internal Proxy |
CampaignOperation Wocao | During Operation Wocao, threat actors proxied traffic through multiple infected systems. |
| T1090.001 Internal Proxy |
GroupVolt Typhoon | Volt Typhoon has used the built-in netsh `port proxy` command to create proxies on compromised systems to facilitate access. |
| T1090.001 Internal Proxy |
GroupStrider | Strider has used local servers with both local network and Internet access to act as internal proxy nodes to exfiltrate data from other parts of the network without direct Internet access. |
| T1090.001 Internal Proxy |
GroupAPT39 | APT39 used custom tools to create SOCK5 and custom protocol proxies between infected hosts. |
| T1090.001 Internal Proxy |
GroupHigaisa | Higaisa discovered system proxy settings and used them if available. |
| T1090.001 Internal Proxy |
GroupTurla | Turla has compromised internal network systems to act as a proxy to forward traffic to C2. |
| T1090.001 Internal Proxy |
GroupLotus Blossom | Lotus Blossom has used publicly available tools such as the Venom proxy tool to proxy traffic out of victim environments. |
| T1090.001 Internal Proxy |
GroupLazarus Group | Lazarus Group has used a compromised router to serve as a proxy between a victim network's corporate and restricted segments. |
| T1090.001 Internal Proxy |
GroupVelvet Ant | Velvet Ant has tunneled traffic from victims through an internal, compromised host to proxy communications to command and control nodes. |
| T1090.001 Internal Proxy |
GroupFIN13 | FIN13 has utilized a proxy tool to communicate between compromised assets. |
| T1090.001 Internal Proxy |
MalwareNinja | Ninja can proxy C2 communications including to and from internal agents without internet connectivity. |
| T1090.001 Internal Proxy |
MalwareBRICKSTORM | BRICKSTORM has leveraged SOCKS Proxy to pivot into victim networks in attempts to resemble legitimate administrative traffic. |
| T1090.001 Internal Proxy |
MalwareStuxnet | Stuxnet installs an RPC server for P2P communications. |
| T1090.001 Internal Proxy |
MalwareGomir | Gomir can start a reverse proxy to initiate connections to arbitrary endpoints in victim networks. |
| T1090.001 Internal Proxy |
MalwareMafalda | Mafalda can create a named pipe to listen for and send data to a named pipe-based C2 server. |
| T1090.001 Internal Proxy |
MalwareInvisiMole | InvisiMole can function as a proxy to create a server that relays communication between the client and C&C server, or between two clients. |
| T1090.001 Internal Proxy |
MalwareKazuar | Kazuar has used internal nodes on the compromised network for C2 communications. |
| T1090.001 Internal Proxy |
MalwareFatDuke | FatDuke can used pipes to connect machines with restricted internet access to remote machines via other infected hosts. |
| T1090.001 Internal Proxy |
MalwareMiniDuke | MiniDuke can can use a named pipe to forward communications from one compromised machine with internet access to other compromised machines. |
| T1090.001 Internal Proxy |
MalwarePay2Key | Pay2Key has designated machines in the compromised network to serve as reverse proxy pivot points to channel communications with C2. |
| T1090.001 Internal Proxy |
MalwareGlassWorm | GlassWorm has leveraged peer-to-peer software to facilitate communications within the victim network to include the software WebRTC. GlassWorm has also established a SOCKS proxy to interact with victim devices that also acted as a proxy node for follow-on behaviors. |
| T1090.001 Internal Proxy |
MalwareHikit | Hikit supports peer connections. |
| T1090.001 Internal Proxy |
MalwareDrovorub | Drovorub can use a port forwarding rule on its agent module to relay network traffic through the client module to a remote host on the same network. |
| T1090.001 Internal Proxy |
MalwareHiddenFace | HiddenFace can act as an internal HTTP proxy within the targeted environment. |
| T1090.001 Internal Proxy |
MalwareCobalt Strike | Cobalt Strike can be configured to have commands relayed over a peer-to-peer network of infected hosts. This can be used to limit the number of egress points, or provide access to a host without direct internet access. |
| T1090.001 Internal Proxy |
MalwareCHOPSTICK | CHOPSTICK used a proxy server between victims and the C2 server. |
| T1090.001 Internal Proxy |
MalwareWinnti for Windows | The Winnti for Windows HTTP/S C2 mode can make use of a local proxy. |
| T1090.001 Internal Proxy |
MalwaremetaMain | metaMain can create a named pipe to listen for and send data to a named pipe-based C2 server. |
| T1090.001 Internal Proxy |
MalwareStarProxy | StarProxy has proxied traffic between infected devices and their C2 servers. |
| T1090.001 Internal Proxy |
MalwareBACKSPACE | The "ZJ" variant of BACKSPACE allows "ZJ link" infections with Internet access to relay traffic from "ZJ listen" to a command server. |
| T1090.001 Internal Proxy |
ToolSliver | Sliver has a built-in SOCKS5 proxying capability allowing for Sliver clients to proxy network traffic through other clients within a victim network. |
| T1090.001 Internal Proxy |
ToolMythic | Mythic can leverage a peer-to-peer C2 profile between agents. |
| T1090.001 Internal Proxy |
MalwareDuqu | Duqu can be configured to have commands relayed over a peer-to-peer network of infected hosts if some of the hosts do not have Internet access. |
| T1090.002 External Proxy |
CampaignQuad7 Activity | Quad7 Activity has initialized SOCKS5 proxies on compromised devices. |
| T1090.002 External Proxy |
GroupGALLIUM | GALLIUM used a modified version of HTRAN to redirect connections between networks. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.