Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1090.002 External Proxy |
GroupAPT3 | An APT3 downloader establishes SOCKS5 connections for its initial C2. |
| T1090.002 External Proxy |
GroupmenuPass | menuPass has used a global service provider's IP as a proxy for C2 traffic from a victim. |
| T1090.002 External Proxy |
GroupMuddyWater | MuddyWater has controlled POWERSTATS from behind a proxy network to obfuscate the C2 location. MuddyWater has used a series of compromised websites that victims connected to randomly to relay information to command and control (C2). MuddyWater has also used go-socks5 variants to bypass firewalls and Network Address Translation (NAT), to communicate with a hardcoded C2 server, and to exfiltrate data. |
| T1090.002 External Proxy |
GroupAPT39 | APT39 has used various tools to proxy C2 communications. |
| T1090.002 External Proxy |
GroupFIN5 | FIN5 maintains access to victim environments by using FLIPSIDE to create a proxy for a backup RDP tunnel. |
| T1090.002 External Proxy |
GroupAPT29 | APT29 uses compromised residential endpoints as proxies for defense evasion and network access. |
| T1090.002 External Proxy |
GroupAPT28 | APT28 used other victims as proxies to relay command traffic, for instance using a compromised Georgian military email server as a hop point to NATO victims. The group has also used a tool that acts as a proxy to allow C2 even if the victim is behind a router. APT28 has also used a machine to relay and obscure communications between CHOPSTICK and their server. |
| T1090.002 External Proxy |
GroupTonto Team | Tonto Team has routed their traffic through an external server in order to obfuscate their location. |
| T1090.002 External Proxy |
GroupLazarus Group | Lazarus Group has used multiple proxies to obfuscate network traffic from victims. |
| T1090.002 External Proxy |
GroupSilence | Silence has used ProxyBot, which allows the attacker to redirect traffic from the current node to the backconnect server via Sock4\Socks5. |
| T1090.002 External Proxy |
MalwareTrickBot | TrickBot has been known to reach a command and control server via one of nine proxy IP addresses. |
| T1090.002 External Proxy |
MalwareInvisiMole | InvisiMole InvisiMole can identify proxy servers used by the victim and use them for C2 communication. |
| T1090.002 External Proxy |
MalwareQUIETEXIT | QUIETEXIT can proxy traffic via SOCKS. |
| T1090.002 External Proxy |
MalwareOkrum | Okrum can identify proxy servers configured and used by the victim, and use it to make HTTP requests to C2 its server. |
| T1090.002 External Proxy |
MalwareRegin | Regin leveraged several compromised universities as proxies to obscure its origin. |
| T1090.002 External Proxy |
MalwareShimRat | ShimRat can use pre-configured HTTP proxies. |
| T1090.002 External Proxy |
MalwareWinnti for Windows | The Winnti for Windows HTTP/S C2 mode can make use of an external proxy. |
| T1090.002 External Proxy |
MalwarePOWERSTATS | POWERSTATS has connected to C2 servers through proxies. |
| T1090.002 External Proxy |
MalwareQakBot | QakBot has a module that can proxy C2 communications. |
| T1090.002 External Proxy |
Toolevilginx2 | evilginx2 can route traffic via SOCKS5 and HTTP(S) proxies between an intended phishing victim's machine and legitimate websites. |
| T1090.002 External Proxy |
ToolMythic | Mythic can leverage a modified SOCKS5 proxy to tunnel egress C2 traffic. |
| T1090.003 Multi-hop Proxy |
CampaignRedPenguin | During RedPenguin, UNC3886 used infrastructure associated with operational relay box (ORB) networks. |
| T1090.003 Multi-hop Proxy |
CampaignSPACEHOP Activity | SPACEHOP Activity has routed traffic through chains of compromised network devices to proxy C2 communications. |
| T1090.003 Multi-hop Proxy |
CampaignSalesforce Data Exfiltration | During Salesforce Data Exfiltration, threat actors used Tor IPs for voice calls and for the collection of stolen data. |
| T1090.003 Multi-hop Proxy |
Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, the adversaries utilized Tor nodes for C2. |
| T1090.003 Multi-hop Proxy |
CampaignOperation Wocao | During Operation Wocao, threat actors executed commands through the installed web shell via Tor exit nodes. |
| T1090.003 Multi-hop Proxy |
CampaignQuad7 Activity | Quad7 Activity has routed traffic through chains of compromised network devices for password spray attacks. |
| T1090.003 Multi-hop Proxy |
CampaignFLORAHOX Activity | FLORAHOX Activity has routed traffic through a customized Tor relay network layer. |
| T1090.003 Multi-hop Proxy |
CampaignCostaRicto | During CostaRicto, the threat actors used a layer of proxies to manage C2 communications. |
| T1090.003 Multi-hop Proxy |
GroupVolt Typhoon | Volt Typhoon has used multi-hop proxies for command-and-control infrastructure. |
| T1090.003 Multi-hop Proxy |
GroupGamaredon Group | Gamaredon Group has used Tor for C2 traffic. |
| T1090.003 Multi-hop Proxy |
GroupZIRCONIUM | ZIRCONIUM has utilized an ORB (operational relay box) network – consisting compromised devices such as small office and home office (SOHO) routers, IoT devices, and leased virtual private servers (VPS) – to proxy traffic. |
| T1090.003 Multi-hop Proxy |
GroupLeviathan | Leviathan has used multi-hop proxies to disguise the source of their malicious traffic. |
| T1090.003 Multi-hop Proxy |
GroupLotus Blossom | Lotus Blossom has used tools such as the publicly available HTran tool for proxying traffic in victim environments. |
| T1090.003 Multi-hop Proxy |
GroupAPT29 | A backdoor used by APT29 created a Tor hidden service to forward traffic from the Tor client to local ports 3389 (RDP), 139 (Netbios), and 445 (SMB) enabling full remote access from outside the network and has also used TOR. |
| T1090.003 Multi-hop Proxy |
GroupMedusa Group | Medusa Group has used TOR nodes for communications. |
| T1090.003 Multi-hop Proxy |
GroupEmber Bear | Ember Bear has configured multi-hop proxies via ProxyChains within victim environments. |
| T1090.003 Multi-hop Proxy |
GroupAPT28 | APT28 has routed traffic over Tor and VPN servers to obfuscate their activities. |
| T1090.003 Multi-hop Proxy |
GroupFIN4 | |
| T1090.003 Multi-hop Proxy |
GroupInception | Inception used chains of compromised routers to proxy C2 communications between them and cloud service providers. |
| T1090.003 Multi-hop Proxy |
MalwareNinja | Ninja has the ability to use a proxy chain with up to 255 hops when using TCP. |
| T1090.003 Multi-hop Proxy |
MalwareUrsnif | |
| T1090.003 Multi-hop Proxy |
MalwareStrongPity | StrongPity can use multiple layers of proxy servers to hide terminal nodes in its infrastructure. |
| T1090.003 Multi-hop Proxy |
MalwareGreyEnergy | GreyEnergy has used Tor relays for Command and Control servers. |
| T1090.003 Multi-hop Proxy |
MalwareBOLDMOVE | BOLDMOVE is capable of relaying traffic from command and control servers to follow-on systems. |
| T1090.003 Multi-hop Proxy |
MalwareSystemBC | SystemBC has used multiple proxy layers, such as SOCKS5 and Tor, for C2 communication. SystemBC has also leveraged Tor for encrypting and concealing C2 traffic. The server component of SystemBC has used SOCKS5 for C2 communication. |
| T1090.003 Multi-hop Proxy |
MalwareKeydnap | Keydnap uses a copy of tor2web proxy for HTTPS communications. |
| T1090.003 Multi-hop Proxy |
MalwareSiloscape | |
| T1090.003 Multi-hop Proxy |
MalwareNGLite | NGLite has abused NKN infrastructure for its C2 communication. |
| T1090.003 Multi-hop Proxy |
MalwareWannaCry |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.