ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1090.003×

12 examples

TechniqueUsed byProcedure example
T1090.003
Multi-hop Proxy
GroupVolt Typhoon

Volt Typhoon has used multi-hop proxies for command-and-control infrastructure.

T1090.003
Multi-hop Proxy
GroupGamaredon Group

Gamaredon Group has used Tor for C2 traffic.

T1090.003
Multi-hop Proxy
GroupZIRCONIUM

ZIRCONIUM has utilized an ORB (operational relay box) network – consisting compromised devices such as small office and home office (SOHO) routers, IoT devices, and leased virtual private servers (VPS) – to proxy traffic.

T1090.003
Multi-hop Proxy
GroupLeviathan

Leviathan has used multi-hop proxies to disguise the source of their malicious traffic.

T1090.003
Multi-hop Proxy
GroupLotus Blossom

Lotus Blossom has used tools such as the publicly available HTran tool for proxying traffic in victim environments.

T1090.003
Multi-hop Proxy
GroupAPT29

A backdoor used by APT29 created a Tor hidden service to forward traffic from the Tor client to local ports 3389 (RDP), 139 (Netbios), and 445 (SMB) enabling full remote access from outside the network and has also used TOR.

T1090.003
Multi-hop Proxy
GroupMedusa Group

Medusa Group has used TOR nodes for communications.

T1090.003
Multi-hop Proxy
GroupEmber Bear

Ember Bear has configured multi-hop proxies via ProxyChains within victim environments.

T1090.003
Multi-hop Proxy
GroupAPT28

APT28 has routed traffic over Tor and VPN servers to obfuscate their activities.

T1090.003
Multi-hop Proxy
GroupFIN4

FIN4 has used Tor to log in to victims' email accounts.

T1090.003
Multi-hop Proxy
GroupInception

Inception used chains of compromised routers to proxy C2 communications between them and cloud service providers.

T1090.003
Multi-hop Proxy
GroupShinyHunters

ShinyHunters has used Tor to host their DLS.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.