ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1090.001×

9 examples

TechniqueUsed byProcedure example
T1090.001
Internal Proxy
GroupVolt Typhoon

Volt Typhoon has used the built-in netsh `port proxy` command to create proxies on compromised systems to facilitate access.

T1090.001
Internal Proxy
GroupStrider

Strider has used local servers with both local network and Internet access to act as internal proxy nodes to exfiltrate data from other parts of the network without direct Internet access.

T1090.001
Internal Proxy
GroupAPT39

APT39 used custom tools to create SOCK5 and custom protocol proxies between infected hosts.

T1090.001
Internal Proxy
GroupHigaisa

Higaisa discovered system proxy settings and used them if available.

T1090.001
Internal Proxy
GroupTurla

Turla has compromised internal network systems to act as a proxy to forward traffic to C2.

T1090.001
Internal Proxy
GroupLotus Blossom

Lotus Blossom has used publicly available tools such as the Venom proxy tool to proxy traffic out of victim environments.

T1090.001
Internal Proxy
GroupLazarus Group

Lazarus Group has used a compromised router to serve as a proxy between a victim network's corporate and restricted segments.

T1090.001
Internal Proxy
GroupVelvet Ant

Velvet Ant has tunneled traffic from victims through an internal, compromised host to proxy communications to command and control nodes.

T1090.001
Internal Proxy
GroupFIN13

FIN13 has utilized a proxy tool to communicate between compromised assets.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.