Real-world descriptions of how a group, tool or campaign used a technique.
11 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1090.002 External Proxy |
MalwareTrickBot | TrickBot has been known to reach a command and control server via one of nine proxy IP addresses. |
| T1090.002 External Proxy |
MalwareInvisiMole | InvisiMole InvisiMole can identify proxy servers used by the victim and use them for C2 communication. |
| T1090.002 External Proxy |
MalwareQUIETEXIT | QUIETEXIT can proxy traffic via SOCKS. |
| T1090.002 External Proxy |
MalwareOkrum | Okrum can identify proxy servers configured and used by the victim, and use it to make HTTP requests to C2 its server. |
| T1090.002 External Proxy |
MalwareRegin | Regin leveraged several compromised universities as proxies to obscure its origin. |
| T1090.002 External Proxy |
MalwareShimRat | ShimRat can use pre-configured HTTP proxies. |
| T1090.002 External Proxy |
MalwareWinnti for Windows | The Winnti for Windows HTTP/S C2 mode can make use of an external proxy. |
| T1090.002 External Proxy |
MalwarePOWERSTATS | POWERSTATS has connected to C2 servers through proxies. |
| T1090.002 External Proxy |
MalwareQakBot | QakBot has a module that can proxy C2 communications. |
| T1090.002 External Proxy |
Toolevilginx2 | evilginx2 can route traffic via SOCKS5 and HTTP(S) proxies between an intended phishing victim's machine and legitimate websites. |
| T1090.002 External Proxy |
ToolMythic | Mythic can leverage a modified SOCKS5 proxy to tunnel egress C2 traffic. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.