Real-world descriptions of how a group, tool or campaign used a technique.
9 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1090.001 Internal Proxy |
GroupVolt Typhoon | Volt Typhoon has used the built-in netsh `port proxy` command to create proxies on compromised systems to facilitate access. |
| T1090.001 Internal Proxy |
GroupStrider | Strider has used local servers with both local network and Internet access to act as internal proxy nodes to exfiltrate data from other parts of the network without direct Internet access. |
| T1090.001 Internal Proxy |
GroupAPT39 | APT39 used custom tools to create SOCK5 and custom protocol proxies between infected hosts. |
| T1090.001 Internal Proxy |
GroupHigaisa | Higaisa discovered system proxy settings and used them if available. |
| T1090.001 Internal Proxy |
GroupTurla | Turla has compromised internal network systems to act as a proxy to forward traffic to C2. |
| T1090.001 Internal Proxy |
GroupLotus Blossom | Lotus Blossom has used publicly available tools such as the Venom proxy tool to proxy traffic out of victim environments. |
| T1090.001 Internal Proxy |
GroupLazarus Group | Lazarus Group has used a compromised router to serve as a proxy between a victim network's corporate and restricted segments. |
| T1090.001 Internal Proxy |
GroupVelvet Ant | Velvet Ant has tunneled traffic from victims through an internal, compromised host to proxy communications to command and control nodes. |
| T1090.001 Internal Proxy |
GroupFIN13 | FIN13 has utilized a proxy tool to communicate between compromised assets. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.