ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1090.003×

23 examples

TechniqueUsed byProcedure example
T1090.003
Multi-hop Proxy
MalwareNinja

Ninja has the ability to use a proxy chain with up to 255 hops when using TCP.

T1090.003
Multi-hop Proxy
MalwareUrsnif

Ursnif has used Tor for C2.

T1090.003
Multi-hop Proxy
MalwareStrongPity

StrongPity can use multiple layers of proxy servers to hide terminal nodes in its infrastructure.

T1090.003
Multi-hop Proxy
MalwareGreyEnergy

GreyEnergy has used Tor relays for Command and Control servers.

T1090.003
Multi-hop Proxy
MalwareBOLDMOVE

BOLDMOVE is capable of relaying traffic from command and control servers to follow-on systems.

T1090.003
Multi-hop Proxy
MalwareSystemBC

SystemBC has used multiple proxy layers, such as SOCKS5 and Tor, for C2 communication. SystemBC has also leveraged Tor for encrypting and concealing C2 traffic. The server component of SystemBC has used SOCKS5 for C2 communication.

T1090.003
Multi-hop Proxy
MalwareKeydnap

Keydnap uses a copy of tor2web proxy for HTTPS communications.

T1090.003
Multi-hop Proxy
MalwareSiloscape

Siloscape uses Tor to communicate with C2.

T1090.003
Multi-hop Proxy
MalwareNGLite

NGLite has abused NKN infrastructure for its C2 communication.

T1090.003
Multi-hop Proxy
MalwareWannaCry

WannaCry uses Tor for command and control traffic.

T1090.003
Multi-hop Proxy
MalwareUroburos

Uroburos can use implants on multiple compromised machines to proxy communications through its worldwide P2P network.

T1090.003
Multi-hop Proxy
MalwareAttor

Attor has used Tor for C2 communication.

T1090.003
Multi-hop Proxy
MalwareKobalos

Kobalos can chain together multiple compromised machines as proxies to reach their final targets.

T1090.003
Multi-hop Proxy
MalwareCyclops Blink

Cyclops Blink has used Tor nodes for C2 traffic.

T1090.003
Multi-hop Proxy
MalwareNKAbuse

NKAbuse has abused the NKN public blockchain protocol for its C2 communications.

T1090.003
Multi-hop Proxy
MalwareIndustroyer

Industroyer used Tor nodes for C2.

T1090.003
Multi-hop Proxy
MalwareDridex

Dridex can use multiple layers of proxy servers to hide terminal nodes in its infrastructure.

T1090.003
Multi-hop Proxy
MalwareDok

Dok downloads and installs Tor via homebrew.

T1090.003
Multi-hop Proxy
MalwareMacSpy

MacSpy uses Tor for command and control.

T1090.003
Multi-hop Proxy
ToolFRP

The FRP client can be configured to connect to the server through a proxy.

T1090.003
Multi-hop Proxy
ToolAsyncRAT

AsyncRAT can proxy C2 through a Tor client.

T1090.003
Multi-hop Proxy
ToolTor

Traffic traversing the Tor network will be forwarded to multiple nodes before exiting the Tor network and continuing on to its intended destination.

T1090.003
Multi-hop Proxy
MalwareMini Shai-Hulud

Mini Shai-Hulud has the ability to exfiltrate stolen credentials via the Session messenger network.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.