Real-world descriptions of how a group, tool or campaign used a technique.
23 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1090.001 Internal Proxy |
MalwareNinja | Ninja can proxy C2 communications including to and from internal agents without internet connectivity. |
| T1090.001 Internal Proxy |
MalwareBRICKSTORM | BRICKSTORM has leveraged SOCKS Proxy to pivot into victim networks in attempts to resemble legitimate administrative traffic. |
| T1090.001 Internal Proxy |
MalwareStuxnet | Stuxnet installs an RPC server for P2P communications. |
| T1090.001 Internal Proxy |
MalwareGomir | Gomir can start a reverse proxy to initiate connections to arbitrary endpoints in victim networks. |
| T1090.001 Internal Proxy |
MalwareMafalda | Mafalda can create a named pipe to listen for and send data to a named pipe-based C2 server. |
| T1090.001 Internal Proxy |
MalwareInvisiMole | InvisiMole can function as a proxy to create a server that relays communication between the client and C&C server, or between two clients. |
| T1090.001 Internal Proxy |
MalwareKazuar | Kazuar has used internal nodes on the compromised network for C2 communications. |
| T1090.001 Internal Proxy |
MalwareFatDuke | FatDuke can used pipes to connect machines with restricted internet access to remote machines via other infected hosts. |
| T1090.001 Internal Proxy |
MalwareMiniDuke | MiniDuke can can use a named pipe to forward communications from one compromised machine with internet access to other compromised machines. |
| T1090.001 Internal Proxy |
MalwarePay2Key | Pay2Key has designated machines in the compromised network to serve as reverse proxy pivot points to channel communications with C2. |
| T1090.001 Internal Proxy |
MalwareGlassWorm | GlassWorm has leveraged peer-to-peer software to facilitate communications within the victim network to include the software WebRTC. GlassWorm has also established a SOCKS proxy to interact with victim devices that also acted as a proxy node for follow-on behaviors. |
| T1090.001 Internal Proxy |
MalwareHikit | Hikit supports peer connections. |
| T1090.001 Internal Proxy |
MalwareDrovorub | Drovorub can use a port forwarding rule on its agent module to relay network traffic through the client module to a remote host on the same network. |
| T1090.001 Internal Proxy |
MalwareHiddenFace | HiddenFace can act as an internal HTTP proxy within the targeted environment. |
| T1090.001 Internal Proxy |
MalwareCobalt Strike | Cobalt Strike can be configured to have commands relayed over a peer-to-peer network of infected hosts. This can be used to limit the number of egress points, or provide access to a host without direct internet access. |
| T1090.001 Internal Proxy |
MalwareCHOPSTICK | CHOPSTICK used a proxy server between victims and the C2 server. |
| T1090.001 Internal Proxy |
MalwareWinnti for Windows | The Winnti for Windows HTTP/S C2 mode can make use of a local proxy. |
| T1090.001 Internal Proxy |
MalwaremetaMain | metaMain can create a named pipe to listen for and send data to a named pipe-based C2 server. |
| T1090.001 Internal Proxy |
MalwareStarProxy | StarProxy has proxied traffic between infected devices and their C2 servers. |
| T1090.001 Internal Proxy |
MalwareBACKSPACE | The "ZJ" variant of BACKSPACE allows "ZJ link" infections with Internet access to relay traffic from "ZJ listen" to a command server. |
| T1090.001 Internal Proxy |
ToolSliver | Sliver has a built-in SOCKS5 proxying capability allowing for Sliver clients to proxy network traffic through other clients within a victim network. |
| T1090.001 Internal Proxy |
ToolMythic | Mythic can leverage a peer-to-peer C2 profile between agents. |
| T1090.001 Internal Proxy |
MalwareDuqu | Duqu can be configured to have commands relayed over a peer-to-peer network of infected hosts if some of the hosts do not have Internet access. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.