Real-world descriptions of how a group, tool or campaign used a technique.
12 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1090.003 Multi-hop Proxy |
GroupVolt Typhoon | Volt Typhoon has used multi-hop proxies for command-and-control infrastructure. |
| T1090.003 Multi-hop Proxy |
GroupGamaredon Group | Gamaredon Group has used Tor for C2 traffic. |
| T1090.003 Multi-hop Proxy |
GroupZIRCONIUM | ZIRCONIUM has utilized an ORB (operational relay box) network – consisting compromised devices such as small office and home office (SOHO) routers, IoT devices, and leased virtual private servers (VPS) – to proxy traffic. |
| T1090.003 Multi-hop Proxy |
GroupLeviathan | Leviathan has used multi-hop proxies to disguise the source of their malicious traffic. |
| T1090.003 Multi-hop Proxy |
GroupLotus Blossom | Lotus Blossom has used tools such as the publicly available HTran tool for proxying traffic in victim environments. |
| T1090.003 Multi-hop Proxy |
GroupAPT29 | A backdoor used by APT29 created a Tor hidden service to forward traffic from the Tor client to local ports 3389 (RDP), 139 (Netbios), and 445 (SMB) enabling full remote access from outside the network and has also used TOR. |
| T1090.003 Multi-hop Proxy |
GroupMedusa Group | Medusa Group has used TOR nodes for communications. |
| T1090.003 Multi-hop Proxy |
GroupEmber Bear | Ember Bear has configured multi-hop proxies via ProxyChains within victim environments. |
| T1090.003 Multi-hop Proxy |
GroupAPT28 | APT28 has routed traffic over Tor and VPN servers to obfuscate their activities. |
| T1090.003 Multi-hop Proxy |
GroupFIN4 | |
| T1090.003 Multi-hop Proxy |
GroupInception | Inception used chains of compromised routers to proxy C2 communications between them and cloud service providers. |
| T1090.003 Multi-hop Proxy |
GroupShinyHunters | ShinyHunters has used Tor to host their DLS. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.