ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1090.002×

11 examples

TechniqueUsed byProcedure example
T1090.002
External Proxy
GroupGALLIUM

GALLIUM used a modified version of HTRAN to redirect connections between networks.

T1090.002
External Proxy
GroupAPT3

An APT3 downloader establishes SOCKS5 connections for its initial C2.

T1090.002
External Proxy
GroupmenuPass

menuPass has used a global service provider's IP as a proxy for C2 traffic from a victim.

T1090.002
External Proxy
GroupMuddyWater

MuddyWater has controlled POWERSTATS from behind a proxy network to obfuscate the C2 location. MuddyWater has used a series of compromised websites that victims connected to randomly to relay information to command and control (C2). MuddyWater has also used go-socks5 variants to bypass firewalls and Network Address Translation (NAT), to communicate with a hardcoded C2 server, and to exfiltrate data.

T1090.002
External Proxy
GroupAPT39

APT39 has used various tools to proxy C2 communications.

T1090.002
External Proxy
GroupFIN5

FIN5 maintains access to victim environments by using FLIPSIDE to create a proxy for a backup RDP tunnel.

T1090.002
External Proxy
GroupAPT29

APT29 uses compromised residential endpoints as proxies for defense evasion and network access.

T1090.002
External Proxy
GroupAPT28

APT28 used other victims as proxies to relay command traffic, for instance using a compromised Georgian military email server as a hop point to NATO victims. The group has also used a tool that acts as a proxy to allow C2 even if the victim is behind a router. APT28 has also used a machine to relay and obscure communications between CHOPSTICK and their server.

T1090.002
External Proxy
GroupTonto Team

Tonto Team has routed their traffic through an external server in order to obfuscate their location.

T1090.002
External Proxy
GroupLazarus Group

Lazarus Group has used multiple proxies to obfuscate network traffic from victims.

T1090.002
External Proxy
GroupSilence

Silence has used ProxyBot, which allows the attacker to redirect traffic from the current node to the backconnect server via Sock4\Socks5.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.