ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1090×

19 examples

TechniqueUsed byProcedure example
T1090
Proxy
GroupVolt Typhoon

Volt Typhoon has used compromised devices and customized versions of open source tools such as FRP (Fast Reverse Proxy), Earthworm, and Impacket to proxy network traffic.

T1090
Proxy
GroupAPT41

APT41 used a tool called CLASSFON to covertly proxy network communications.

T1090
Proxy
GroupMuddyWater

MuddyWater has used NordVPN to proxy phishing emails, making them appear to originate from France.

T1090
Proxy
GroupGamaredon Group

Gamaredon Group has used the Cloudflare Tunnel client to proxy C2 traffic.

T1090
Proxy
GroupSandworm Team

Sandworm Team's BCS-server tool can create an internal proxy server to redirect traffic from the adversary-controlled C2 to internal servers which may not be connected to the internet, but are interconnected locally.

T1090
Proxy
GroupScattered Spider

Scattered Spider has used proxy networks to hamper detection and has installed legitimate proxy tools on VMware vCenter and adversary-controlled VMs.

T1090
Proxy
GroupContagious Interview

Contagious Interview has leveraged Astrill VPN for C2.

T1090
Proxy
GroupWindigo

Windigo has delivered a generic Windows proxy Win32/Glubteta.M. Windigo has also used multiple reverse proxy chains as part of their C2 infrastructure.

T1090
Proxy
GroupPOLONIUM

POLONIUM has used the AirVPN service for operational activity.

T1090
Proxy
GroupMoustachedBouncer

MoustachedBouncer has used a reverse proxy tool similar to the GitHub repository revsocks.

T1090
Proxy
GroupBlue Mockingbird

Blue Mockingbird has used FRP, ssf, and Venom to establish SOCKS proxy connections.

T1090
Proxy
GroupTurla

Turla RPC backdoors have included local UPnP RPC proxies.

T1090
Proxy
GroupCinnamon Tempest

Cinnamon Tempest has used a customized version of the Iox port-forwarding and proxy tool.

T1090
Proxy
GroupMirrorFace

MirrorFace has used the GO Simple Tunnel (GOST) proxy tool.

T1090
Proxy
GroupFox Kitten

Fox Kitten has used the open source reverse proxy tools including FRPC and Go Proxy to establish connections from C2 to local servers.

T1090
Proxy
GroupEarth Lusca

Earth Lusca adopted Cloudflare as a proxy for compromised servers.

T1090
Proxy
GroupLAPSUS$

LAPSUS$ has leverage NordVPN for its egress points when targeting intended victims.

T1090
Proxy
GroupCopyKittens

CopyKittens has used the AirVPN service for operational activity.

T1090
Proxy
GroupMagic Hound

Magic Hound has used Fast Reverse Proxy (FRP) for RDP traffic.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.