Real-world descriptions of how a group, tool or campaign used a technique.
21 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1572 Protocol Tunneling |
MalwareBRICKSTORM | BRICKSTORM has utilized a SOCKS proxy to tunnel access within the victim network and exfiltrate files from internal shares, code repositories, and other endpoints. BRICKSTORM has also leveraged Yamux for combining multiple concurrent logical streams over a single a socket. CISA BRICKSTORM UNC5221 AR25-338A February 2026CrowdStrike BRICKSTORM WARP PANDA UNC5221 December 2025Google BRICKSTORM September 2025Google UNC5221 BRICKSTORM SPAWNCHIMERA April 2024NVISO BRICKSTORM April 2025Picus Security BRICKSTORM UNC5221 October 2025Resecurity UNC5221 BRICKSTORM F5 Big-IP October 2025 |
| T1572 Protocol Tunneling |
MalwarereGeorg | reGeorg can tunnel TCP sessions including RDP, SSH, and SMB through HTTP. |
| T1572 Protocol Tunneling |
MalwareFLIPSIDE | FLIPSIDE uses RDP to tunnel traffic from a victim environment. |
| T1572 Protocol Tunneling |
MalwareUroburos | Uroburos has the ability to communicate over custom communications methodologies that ride over common network protocols including raw TCP and UDP sockets, HTTP, SMTP, and DNS. |
| T1572 Protocol Tunneling |
MalwareHiddenFace | HiddenFace can hide its IP lookup by using DNS over HTTPS (DoH) for C2. |
| T1572 Protocol Tunneling |
MalwareCobalt Strike | Cobalt Strike uses a custom command and control protocol that is encapsulated in HTTP, HTTPS, or DNS. In addition, it conducts peer-to-peer communication over Windows named pipes encapsulated in the SMB protocol. All protocols use their standard assigned ports. |
| T1572 Protocol Tunneling |
MalwareMilan | Milan can use a custom protocol tunneled through DNS or HTTP. |
| T1572 Protocol Tunneling |
MalwareCyclops Blink | Cyclops Blink can use DNS over HTTPS (DoH) to resolve C2 nodes. |
| T1572 Protocol Tunneling |
MalwareNeo-reGeorg | Neo-reGeorg can tunnel data in and out of targeted networks. |
| T1572 Protocol Tunneling |
MalwareFunnyDream | FunnyDream can connect to HTTP proxies via TCP to create a tunnel to C2. |
| T1572 Protocol Tunneling |
MalwareSPAWNCHIMERA | SPAWNCHIMERA has created SSH tunnels to facilitate C2 communications. |
| T1572 Protocol Tunneling |
MalwareHeyoka Backdoor | Heyoka Backdoor can use spoofed DNS requests to create a bidirectional tunnel between a compromised host and its C2 servers. |
| T1572 Protocol Tunneling |
MalwareLunarWeb | LunarWeb can run a custom binary protocol under HTTPS for C2. |
| T1572 Protocol Tunneling |
MalwareIndustroyer | Industroyer attempts to perform an HTTP CONNECT via an internal proxy to establish a tunnel. |
| T1572 Protocol Tunneling |
MalwareKevin | Kevin can use a custom protocol tunneled through DNS or HTTP. |
| T1572 Protocol Tunneling |
MalwareQakBot | The QakBot proxy module can encapsulate SOCKS5 protocol within its own proxy protocol. |
| T1572 Protocol Tunneling |
Toolngrok | ngrok can tunnel RDP and other services securely over internet connections. |
| T1572 Protocol Tunneling |
ToolFRP | FRP can tunnel SSH and Unix Domain Socket communications over TCP between external nodes and exposed resources behind firewalls or NAT. |
| T1572 Protocol Tunneling |
ToolBrute Ratel C4 | Brute Ratel C4 can use DNS over HTTPS for C2. |
| T1572 Protocol Tunneling |
ToolMythic | Mythic can use SOCKS proxies to tunnel traffic through another protocol. |
| T1572 Protocol Tunneling |
MalwareDuqu | Duqu uses a custom command and control protocol that communicates over commonly used ports, and is frequently encapsulated by application layer protocols. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.