ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1090.001×

23 examples

TechniqueUsed byProcedure example
T1090.001
Internal Proxy
MalwareNinja

Ninja can proxy C2 communications including to and from internal agents without internet connectivity.

T1090.001
Internal Proxy
MalwareBRICKSTORM

BRICKSTORM has leveraged SOCKS Proxy to pivot into victim networks in attempts to resemble legitimate administrative traffic.

T1090.001
Internal Proxy
MalwareStuxnet

Stuxnet installs an RPC server for P2P communications.

T1090.001
Internal Proxy
MalwareGomir

Gomir can start a reverse proxy to initiate connections to arbitrary endpoints in victim networks.

T1090.001
Internal Proxy
MalwareMafalda

Mafalda can create a named pipe to listen for and send data to a named pipe-based C2 server.

T1090.001
Internal Proxy
MalwareInvisiMole

InvisiMole can function as a proxy to create a server that relays communication between the client and C&C server, or between two clients.

T1090.001
Internal Proxy
MalwareKazuar

Kazuar has used internal nodes on the compromised network for C2 communications.

T1090.001
Internal Proxy
MalwareFatDuke

FatDuke can used pipes to connect machines with restricted internet access to remote machines via other infected hosts.

T1090.001
Internal Proxy
MalwareMiniDuke

MiniDuke can can use a named pipe to forward communications from one compromised machine with internet access to other compromised machines.

T1090.001
Internal Proxy
MalwarePay2Key

Pay2Key has designated machines in the compromised network to serve as reverse proxy pivot points to channel communications with C2.

T1090.001
Internal Proxy
MalwareGlassWorm

GlassWorm has leveraged peer-to-peer software to facilitate communications within the victim network to include the software WebRTC. GlassWorm has also established a SOCKS proxy to interact with victim devices that also acted as a proxy node for follow-on behaviors.

T1090.001
Internal Proxy
MalwareHikit

Hikit supports peer connections.

T1090.001
Internal Proxy
MalwareDrovorub

Drovorub can use a port forwarding rule on its agent module to relay network traffic through the client module to a remote host on the same network.

T1090.001
Internal Proxy
MalwareHiddenFace

HiddenFace can act as an internal HTTP proxy within the targeted environment.

T1090.001
Internal Proxy
MalwareCobalt Strike

Cobalt Strike can be configured to have commands relayed over a peer-to-peer network of infected hosts. This can be used to limit the number of egress points, or provide access to a host without direct internet access.

T1090.001
Internal Proxy
MalwareCHOPSTICK

CHOPSTICK used a proxy server between victims and the C2 server.

T1090.001
Internal Proxy
MalwareWinnti for Windows

The Winnti for Windows HTTP/S C2 mode can make use of a local proxy.

T1090.001
Internal Proxy
MalwaremetaMain

metaMain can create a named pipe to listen for and send data to a named pipe-based C2 server.

T1090.001
Internal Proxy
MalwareStarProxy

StarProxy has proxied traffic between infected devices and their C2 servers.

T1090.001
Internal Proxy
MalwareBACKSPACE

The "ZJ" variant of BACKSPACE allows "ZJ link" infections with Internet access to relay traffic from "ZJ listen" to a command server.

T1090.001
Internal Proxy
ToolSliver

Sliver has a built-in SOCKS5 proxying capability allowing for Sliver clients to proxy network traffic through other clients within a victim network.

T1090.001
Internal Proxy
ToolMythic

Mythic can leverage a peer-to-peer C2 profile between agents.

T1090.001
Internal Proxy
MalwareDuqu

Duqu can be configured to have commands relayed over a peer-to-peer network of infected hosts if some of the hosts do not have Internet access.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.