ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1090.002
External Proxy
GroupAPT3

An APT3 downloader establishes SOCKS5 connections for its initial C2.

T1090.002
External Proxy
GroupmenuPass

menuPass has used a global service provider's IP as a proxy for C2 traffic from a victim.

T1090.002
External Proxy
GroupMuddyWater

MuddyWater has controlled POWERSTATS from behind a proxy network to obfuscate the C2 location. MuddyWater has used a series of compromised websites that victims connected to randomly to relay information to command and control (C2). MuddyWater has also used go-socks5 variants to bypass firewalls and Network Address Translation (NAT), to communicate with a hardcoded C2 server, and to exfiltrate data.

T1090.002
External Proxy
GroupAPT39

APT39 has used various tools to proxy C2 communications.

T1090.002
External Proxy
GroupFIN5

FIN5 maintains access to victim environments by using FLIPSIDE to create a proxy for a backup RDP tunnel.

T1090.002
External Proxy
GroupAPT29

APT29 uses compromised residential endpoints as proxies for defense evasion and network access.

T1090.002
External Proxy
GroupAPT28

APT28 used other victims as proxies to relay command traffic, for instance using a compromised Georgian military email server as a hop point to NATO victims. The group has also used a tool that acts as a proxy to allow C2 even if the victim is behind a router. APT28 has also used a machine to relay and obscure communications between CHOPSTICK and their server.

T1090.002
External Proxy
GroupTonto Team

Tonto Team has routed their traffic through an external server in order to obfuscate their location.

T1090.002
External Proxy
GroupLazarus Group

Lazarus Group has used multiple proxies to obfuscate network traffic from victims.

T1090.002
External Proxy
GroupSilence

Silence has used ProxyBot, which allows the attacker to redirect traffic from the current node to the backconnect server via Sock4\Socks5.

T1090.002
External Proxy
MalwareTrickBot

TrickBot has been known to reach a command and control server via one of nine proxy IP addresses.

T1090.002
External Proxy
MalwareInvisiMole

InvisiMole InvisiMole can identify proxy servers used by the victim and use them for C2 communication.

T1090.002
External Proxy
MalwareQUIETEXIT

QUIETEXIT can proxy traffic via SOCKS.

T1090.002
External Proxy
MalwareOkrum

Okrum can identify proxy servers configured and used by the victim, and use it to make HTTP requests to C2 its server.

T1090.002
External Proxy
MalwareRegin

Regin leveraged several compromised universities as proxies to obscure its origin.

T1090.002
External Proxy
MalwareShimRat

ShimRat can use pre-configured HTTP proxies.

T1090.002
External Proxy
MalwareWinnti for Windows

The Winnti for Windows HTTP/S C2 mode can make use of an external proxy.

T1090.002
External Proxy
MalwarePOWERSTATS

POWERSTATS has connected to C2 servers through proxies.

T1090.002
External Proxy
MalwareQakBot

QakBot has a module that can proxy C2 communications.

T1090.002
External Proxy
Toolevilginx2

evilginx2 can route traffic via SOCKS5 and HTTP(S) proxies between an intended phishing victim's machine and legitimate websites.

T1090.002
External Proxy
ToolMythic

Mythic can leverage a modified SOCKS5 proxy to tunnel egress C2 traffic.

T1090.003
Multi-hop Proxy
CampaignRedPenguin

During RedPenguin, UNC3886 used infrastructure associated with operational relay box (ORB) networks.

T1090.003
Multi-hop Proxy
CampaignSPACEHOP Activity

SPACEHOP Activity has routed traffic through chains of compromised network devices to proxy C2 communications.

T1090.003
Multi-hop Proxy
CampaignSalesforce Data Exfiltration

During Salesforce Data Exfiltration, threat actors used Tor IPs for voice calls and for the collection of stolen data.

T1090.003
Multi-hop Proxy
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, the adversaries utilized Tor nodes for C2.

T1090.003
Multi-hop Proxy
CampaignOperation Wocao

During Operation Wocao, threat actors executed commands through the installed web shell via Tor exit nodes.

T1090.003
Multi-hop Proxy
CampaignQuad7 Activity

Quad7 Activity has routed traffic through chains of compromised network devices for password spray attacks.

T1090.003
Multi-hop Proxy
CampaignFLORAHOX Activity

FLORAHOX Activity has routed traffic through a customized Tor relay network layer.

T1090.003
Multi-hop Proxy
CampaignCostaRicto

During CostaRicto, the threat actors used a layer of proxies to manage C2 communications.

T1090.003
Multi-hop Proxy
GroupVolt Typhoon

Volt Typhoon has used multi-hop proxies for command-and-control infrastructure.

T1090.003
Multi-hop Proxy
GroupGamaredon Group

Gamaredon Group has used Tor for C2 traffic.

T1090.003
Multi-hop Proxy
GroupZIRCONIUM

ZIRCONIUM has utilized an ORB (operational relay box) network – consisting compromised devices such as small office and home office (SOHO) routers, IoT devices, and leased virtual private servers (VPS) – to proxy traffic.

T1090.003
Multi-hop Proxy
GroupLeviathan

Leviathan has used multi-hop proxies to disguise the source of their malicious traffic.

T1090.003
Multi-hop Proxy
GroupLotus Blossom

Lotus Blossom has used tools such as the publicly available HTran tool for proxying traffic in victim environments.

T1090.003
Multi-hop Proxy
GroupAPT29

A backdoor used by APT29 created a Tor hidden service to forward traffic from the Tor client to local ports 3389 (RDP), 139 (Netbios), and 445 (SMB) enabling full remote access from outside the network and has also used TOR.

T1090.003
Multi-hop Proxy
GroupMedusa Group

Medusa Group has used TOR nodes for communications.

T1090.003
Multi-hop Proxy
GroupEmber Bear

Ember Bear has configured multi-hop proxies via ProxyChains within victim environments.

T1090.003
Multi-hop Proxy
GroupAPT28

APT28 has routed traffic over Tor and VPN servers to obfuscate their activities.

T1090.003
Multi-hop Proxy
GroupFIN4

FIN4 has used Tor to log in to victims' email accounts.

T1090.003
Multi-hop Proxy
GroupInception

Inception used chains of compromised routers to proxy C2 communications between them and cloud service providers.

T1090.003
Multi-hop Proxy
MalwareNinja

Ninja has the ability to use a proxy chain with up to 255 hops when using TCP.

T1090.003
Multi-hop Proxy
MalwareUrsnif

Ursnif has used Tor for C2.

T1090.003
Multi-hop Proxy
MalwareStrongPity

StrongPity can use multiple layers of proxy servers to hide terminal nodes in its infrastructure.

T1090.003
Multi-hop Proxy
MalwareGreyEnergy

GreyEnergy has used Tor relays for Command and Control servers.

T1090.003
Multi-hop Proxy
MalwareBOLDMOVE

BOLDMOVE is capable of relaying traffic from command and control servers to follow-on systems.

T1090.003
Multi-hop Proxy
MalwareSystemBC

SystemBC has used multiple proxy layers, such as SOCKS5 and Tor, for C2 communication. SystemBC has also leveraged Tor for encrypting and concealing C2 traffic. The server component of SystemBC has used SOCKS5 for C2 communication.

T1090.003
Multi-hop Proxy
MalwareKeydnap

Keydnap uses a copy of tor2web proxy for HTTPS communications.

T1090.003
Multi-hop Proxy
MalwareSiloscape

Siloscape uses Tor to communicate with C2.

T1090.003
Multi-hop Proxy
MalwareNGLite

NGLite has abused NKN infrastructure for its C2 communication.

T1090.003
Multi-hop Proxy
MalwareWannaCry

WannaCry uses Tor for command and control traffic.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.