Real-world descriptions of how a group, tool or campaign used a technique.
10 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1090 Proxy |
CampaignSharePoint ToolShell Exploitation | During SharePoint ToolShell Exploitation, threat actors used Fast Reverse Proxy to communicate with C2. |
| T1090 Proxy |
CampaignRedDelta Modified PlugX Infection Chain Operations | Mustang Panda proxied communication through the Cloudflare CDN service during RedDelta Modified PlugX Infection Chain Operations. |
| T1090 Proxy |
CampaignRedPenguin | During RedPenguin, UNC3886 used malware capable of establishing a SOCKS proxy connection to a specified IP and port. |
| T1090 Proxy |
CampaignOperation Sharpshooter | For Operation Sharpshooter, the threat actors used the ExpressVPN service to hide their location. |
| T1090 Proxy |
CampaignOperation MidnightEclipse | During Operation MidnightEclipse, threat actors used the GO Simple Tunnel reverse proxy tool. |
| T1090 Proxy |
CampaignSalesforce Data Exfiltration | During Salesforce Data Exfiltration, threat actors used Mullvad VPN IPs to proxy voice phishing calls. |
| T1090 Proxy |
Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, the adversaries utilized the rsocx tool identified as `r.exe` and `rsocx.exe` to tunnel within the internal infrastructure using a Reverse SOCKS Proxy. |
| T1090 Proxy |
CampaignOperation Wocao | During Operation Wocao, threat actors used a custom proxy tool called "Agent" which has support for multiple hops. |
| T1090 Proxy |
CampaignC0017 | During C0017, APT41 used the Cloudflare CDN to proxy C2 traffic. |
| T1090 Proxy |
CampaignC0027 | During C0027, Scattered Spider installed the open-source rsocx reverse proxy tool on a targeted ESXi appliance. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.