ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1090×

47 examples

TechniqueUsed byProcedure example
T1090
Proxy
MalwarereGeorg

reGeorg can establish an HTTP or SOCKS proxy to tunnel data in and out of a network.

T1090
Proxy
MalwareUrsnif

Ursnif has used a peer-to-peer (P2P) network for C2.

T1090
Proxy
MalwareRansomHub

RansomHub can use a proxy to connect to remote SFTP servers.

T1090
Proxy
MalwareLITTLELAMB.WOOLTEA

LITTLELAMB.WOOLTEA has the ability to function as a SOCKS proxy.

T1090
Proxy
MalwareHavoc

Havoc has the ability to route HTTP/S communications through designated proxies.

T1090
Proxy
MalwareAuditCred

AuditCred can utilize proxy for communications.

T1090
Proxy
MalwareRainyDay

RainyDay can use proxy tools including boost_proxy_client for reverse proxy functionality.

T1090
Proxy
MalwareNETWIRE

NETWIRE can implement use of proxies to pivot traffic.

T1090
Proxy
MalwareAria-body

Aria-body has the ability to use a reverse SOCKS proxy module.

T1090
Proxy
MalwareBADHATCH

BADHATCH can use SOCKS4 and SOCKS5 proxies to connect to actor-controlled C2 servers. BADHATCH can also emulate a reverse proxy on a compromised machine to connect with actor-controlled C2 servers.

T1090
Proxy
MalwareSombRAT

SombRAT has the ability to use an embedded SOCKS proxy in C2 communications.

T1090
Proxy
MalwareHOPLIGHT

HOPLIGHT has multiple proxy options that mask traffic between the malware and the remote operators.

T1090
Proxy
MalwareGreen Lambert

Green Lambert can use proxies for C2 traffic.

T1090
Proxy
MalwareBisonal

Bisonal has supported use of a proxy server.

T1090
Proxy
MalwareKEYPLUG

KEYPLUG has used Cloudflare CDN associated infrastructure to redirect C2 communications to malicious domains.

T1090
Proxy
MalwareXTunnel

XTunnel relays traffic between a C2 server and a victim.

T1090
Proxy
MalwareTSCookie

TSCookie has the ability to proxy communications with command and control (C2) servers.

T1090
Proxy
MalwareTYPEFRAME

A TYPEFRAME variant can force the compromised system to function as a proxy server.

T1090
Proxy
MalwareSagerunex

Sagerunex uses several proxy configuration settings to ensure connectivity.

T1090
Proxy
MalwareSDBbot

SDBbot has the ability to use port forwarding to establish a proxy between a target host and C2.

T1090
Proxy
MalwareGoBear

GoBear implements SOCKS5 proxy functionality.

T1090
Proxy
MalwareBADCALL

BADCALL functions as a proxy server between the victim and C2 server.

T1090
Proxy
MalwareKapeka

Kapeka can identify system proxy settings via `WinHttpGetIEProxyConfigForCurrentUser()` during initialization and utilize these settings for subsequent command and control operations.

T1090
Proxy
MalwareSamurai

Samurai has the ability to proxy connections to specified remote IPs and ports through a a proxy module.

T1090
Proxy
MalwarePLEAD

PLEAD has the ability to proxy network communications.

T1090
Proxy
MalwareCardinal RAT

Cardinal RAT can act as a reverse proxy.

T1090
Proxy
MalwareNeo-reGeorg

Neo-reGeorg has the ability to establish a SOCKS5 proxy on a compromised web server.

T1090
Proxy
MalwareHARDRAIN

HARDRAIN uses the command cmd.exe /c netsh firewall add portopening TCP 443 "adp" and makes the victim machine function as a proxy server.

T1090
Proxy
MalwareFunnyDream

FunnyDream can identify and use configured proxies in a compromised network for C2 communication.

T1090
Proxy
MalwareKessel

Kessel can use a proxy during exfiltration if set in the configuration.

T1090
Proxy
MalwareZxShell

ZxShell can set up an HTTP or SOCKS proxy.

T1090
Proxy
MalwareZIPLINE

ZIPLINE can create a proxy server on compromised hosts.

T1090
Proxy
MalwareKOCTOPUS

KOCTOPUS has deployed a modified version of Invoke-Ngrok to expose open local ports to the Internet.

T1090
Proxy
MalwareLunarWeb

LunarWeb has the ability to use a HTTP proxy server for C&C communications.

T1090
Proxy
MalwareSocksbot

Socksbot can start SOCKS proxy threads.

T1090
Proxy
MalwarejRAT

jRAT can serve as a SOCKS proxy server.

T1090
Proxy
MalwareDridex

Dridex contains a backconnect module for tunneling network traffic through a victim's computer. Infected computers become part of a P2P botnet that can relay C2 traffic to other infected peers.

T1090
Proxy
MalwareVasport

Vasport is capable of tunneling though a proxy.

T1090
Proxy
MalwareWarzoneRAT

WarzoneRAT has the capability to act as a reverse proxy.

T1090
Proxy
Toolngrok

ngrok can be used to proxy connections to machines located behind NAT or firewalls.

T1090
Proxy
ToolFRP

FRP can proxy communications through a server in public IP space to local servers located behind a NAT or firewall.

T1090
Proxy
ToolPoshC2

PoshC2 contains modules that allow for use of proxies in command and control.

T1090
Proxy
Toolnetsh

netsh can be used to set up a proxy tunnel to allow remote host access to an infected host.

T1090
Proxy
ToolRemcos

Remcos uses the infected hosts as SOCKS5 proxies to allow for tunneling and proxying.

T1090
Proxy
ToolHTRAN

HTRAN can proxy TCP socket connections to obfuscate command and control infrastructure.

T1090
Proxy
ToolQuasarRAT

QuasarRAT can communicate over a reverse proxy using SOCKS5.

T1090
Proxy
MalwareKali365

Kali365 has leveraged Cloudflare workers as reverse proxy infrastructure.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.