Real-world descriptions of how a group, tool or campaign used a technique.
11 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1090.002 External Proxy |
GroupGALLIUM | GALLIUM used a modified version of HTRAN to redirect connections between networks. |
| T1090.002 External Proxy |
GroupAPT3 | An APT3 downloader establishes SOCKS5 connections for its initial C2. |
| T1090.002 External Proxy |
GroupmenuPass | menuPass has used a global service provider's IP as a proxy for C2 traffic from a victim. |
| T1090.002 External Proxy |
GroupMuddyWater | MuddyWater has controlled POWERSTATS from behind a proxy network to obfuscate the C2 location. MuddyWater has used a series of compromised websites that victims connected to randomly to relay information to command and control (C2). MuddyWater has also used go-socks5 variants to bypass firewalls and Network Address Translation (NAT), to communicate with a hardcoded C2 server, and to exfiltrate data. |
| T1090.002 External Proxy |
GroupAPT39 | APT39 has used various tools to proxy C2 communications. |
| T1090.002 External Proxy |
GroupFIN5 | FIN5 maintains access to victim environments by using FLIPSIDE to create a proxy for a backup RDP tunnel. |
| T1090.002 External Proxy |
GroupAPT29 | APT29 uses compromised residential endpoints as proxies for defense evasion and network access. |
| T1090.002 External Proxy |
GroupAPT28 | APT28 used other victims as proxies to relay command traffic, for instance using a compromised Georgian military email server as a hop point to NATO victims. The group has also used a tool that acts as a proxy to allow C2 even if the victim is behind a router. APT28 has also used a machine to relay and obscure communications between CHOPSTICK and their server. |
| T1090.002 External Proxy |
GroupTonto Team | Tonto Team has routed their traffic through an external server in order to obfuscate their location. |
| T1090.002 External Proxy |
GroupLazarus Group | Lazarus Group has used multiple proxies to obfuscate network traffic from victims. |
| T1090.002 External Proxy |
GroupSilence | Silence has used ProxyBot, which allows the attacker to redirect traffic from the current node to the backconnect server via Sock4\Socks5. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.