Real-world descriptions of how a group, tool or campaign used a technique.
19 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1090 Proxy |
GroupVolt Typhoon | Volt Typhoon has used compromised devices and customized versions of open source tools such as FRP (Fast Reverse Proxy), Earthworm, and Impacket to proxy network traffic. |
| T1090 Proxy |
GroupAPT41 | APT41 used a tool called CLASSFON to covertly proxy network communications. |
| T1090 Proxy |
GroupMuddyWater | MuddyWater has used NordVPN to proxy phishing emails, making them appear to originate from France. |
| T1090 Proxy |
GroupGamaredon Group | Gamaredon Group has used the Cloudflare Tunnel client to proxy C2 traffic. |
| T1090 Proxy |
GroupSandworm Team | Sandworm Team's BCS-server tool can create an internal proxy server to redirect traffic from the adversary-controlled C2 to internal servers which may not be connected to the internet, but are interconnected locally. |
| T1090 Proxy |
GroupScattered Spider | Scattered Spider has used proxy networks to hamper detection and has installed legitimate proxy tools on VMware vCenter and adversary-controlled VMs. |
| T1090 Proxy |
GroupContagious Interview | Contagious Interview has leveraged Astrill VPN for C2. |
| T1090 Proxy |
GroupWindigo | Windigo has delivered a generic Windows proxy Win32/Glubteta.M. Windigo has also used multiple reverse proxy chains as part of their C2 infrastructure. |
| T1090 Proxy |
GroupPOLONIUM | POLONIUM has used the AirVPN service for operational activity. |
| T1090 Proxy |
GroupMoustachedBouncer | MoustachedBouncer has used a reverse proxy tool similar to the GitHub repository revsocks. |
| T1090 Proxy |
GroupBlue Mockingbird | Blue Mockingbird has used FRP, ssf, and Venom to establish SOCKS proxy connections. |
| T1090 Proxy |
GroupTurla | Turla RPC backdoors have included local UPnP RPC proxies. |
| T1090 Proxy |
GroupCinnamon Tempest | Cinnamon Tempest has used a customized version of the Iox port-forwarding and proxy tool. |
| T1090 Proxy |
GroupMirrorFace | MirrorFace has used the GO Simple Tunnel (GOST) proxy tool. |
| T1090 Proxy |
GroupFox Kitten | Fox Kitten has used the open source reverse proxy tools including FRPC and Go Proxy to establish connections from C2 to local servers. |
| T1090 Proxy |
GroupEarth Lusca | Earth Lusca adopted Cloudflare as a proxy for compromised servers. |
| T1090 Proxy |
GroupLAPSUS$ | LAPSUS$ has leverage NordVPN for its egress points when targeting intended victims. |
| T1090 Proxy |
GroupCopyKittens | CopyKittens has used the AirVPN service for operational activity. |
| T1090 Proxy |
GroupMagic Hound | Magic Hound has used Fast Reverse Proxy (FRP) for RDP traffic. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.