Real-world descriptions of how a group, tool or campaign used a technique.
23 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1090.003 Multi-hop Proxy |
MalwareNinja | Ninja has the ability to use a proxy chain with up to 255 hops when using TCP. |
| T1090.003 Multi-hop Proxy |
MalwareUrsnif | |
| T1090.003 Multi-hop Proxy |
MalwareStrongPity | StrongPity can use multiple layers of proxy servers to hide terminal nodes in its infrastructure. |
| T1090.003 Multi-hop Proxy |
MalwareGreyEnergy | GreyEnergy has used Tor relays for Command and Control servers. |
| T1090.003 Multi-hop Proxy |
MalwareBOLDMOVE | BOLDMOVE is capable of relaying traffic from command and control servers to follow-on systems. |
| T1090.003 Multi-hop Proxy |
MalwareSystemBC | SystemBC has used multiple proxy layers, such as SOCKS5 and Tor, for C2 communication. SystemBC has also leveraged Tor for encrypting and concealing C2 traffic. The server component of SystemBC has used SOCKS5 for C2 communication. |
| T1090.003 Multi-hop Proxy |
MalwareKeydnap | Keydnap uses a copy of tor2web proxy for HTTPS communications. |
| T1090.003 Multi-hop Proxy |
MalwareSiloscape | |
| T1090.003 Multi-hop Proxy |
MalwareNGLite | NGLite has abused NKN infrastructure for its C2 communication. |
| T1090.003 Multi-hop Proxy |
MalwareWannaCry | |
| T1090.003 Multi-hop Proxy |
MalwareUroburos | Uroburos can use implants on multiple compromised machines to proxy communications through its worldwide P2P network. |
| T1090.003 Multi-hop Proxy |
MalwareAttor | |
| T1090.003 Multi-hop Proxy |
MalwareKobalos | Kobalos can chain together multiple compromised machines as proxies to reach their final targets. |
| T1090.003 Multi-hop Proxy |
MalwareCyclops Blink | Cyclops Blink has used Tor nodes for C2 traffic. |
| T1090.003 Multi-hop Proxy |
MalwareNKAbuse | NKAbuse has abused the NKN public blockchain protocol for its C2 communications. |
| T1090.003 Multi-hop Proxy |
MalwareIndustroyer | Industroyer used Tor nodes for C2. |
| T1090.003 Multi-hop Proxy |
MalwareDridex | Dridex can use multiple layers of proxy servers to hide terminal nodes in its infrastructure. |
| T1090.003 Multi-hop Proxy |
MalwareDok | |
| T1090.003 Multi-hop Proxy |
MalwareMacSpy | |
| T1090.003 Multi-hop Proxy |
ToolFRP | The FRP client can be configured to connect to the server through a proxy. |
| T1090.003 Multi-hop Proxy |
ToolAsyncRAT | |
| T1090.003 Multi-hop Proxy |
ToolTor | Traffic traversing the Tor network will be forwarded to multiple nodes before exiting the Tor network and continuing on to its intended destination. |
| T1090.003 Multi-hop Proxy |
MalwareMini Shai-Hulud | Mini Shai-Hulud has the ability to exfiltrate stolen credentials via the Session messenger network. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.