ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1090.002×

11 examples

TechniqueUsed byProcedure example
T1090.002
External Proxy
MalwareTrickBot

TrickBot has been known to reach a command and control server via one of nine proxy IP addresses.

T1090.002
External Proxy
MalwareInvisiMole

InvisiMole InvisiMole can identify proxy servers used by the victim and use them for C2 communication.

T1090.002
External Proxy
MalwareQUIETEXIT

QUIETEXIT can proxy traffic via SOCKS.

T1090.002
External Proxy
MalwareOkrum

Okrum can identify proxy servers configured and used by the victim, and use it to make HTTP requests to C2 its server.

T1090.002
External Proxy
MalwareRegin

Regin leveraged several compromised universities as proxies to obscure its origin.

T1090.002
External Proxy
MalwareShimRat

ShimRat can use pre-configured HTTP proxies.

T1090.002
External Proxy
MalwareWinnti for Windows

The Winnti for Windows HTTP/S C2 mode can make use of an external proxy.

T1090.002
External Proxy
MalwarePOWERSTATS

POWERSTATS has connected to C2 servers through proxies.

T1090.002
External Proxy
MalwareQakBot

QakBot has a module that can proxy C2 communications.

T1090.002
External Proxy
Toolevilginx2

evilginx2 can route traffic via SOCKS5 and HTTP(S) proxies between an intended phishing victim's machine and legitimate websites.

T1090.002
External Proxy
ToolMythic

Mythic can leverage a modified SOCKS5 proxy to tunnel egress C2 traffic.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.