Multi-hop Proxy

T1090.003

Sub-technique of T1090 Proxy.View on attack.mitre.org

About this technique

Adversaries may chain together multiple proxies to disguise the source of malicious traffic. Typically, a defender will be able to identify the last proxy traffic traversed before it enters their network; the defender may or may not be able to identify any previous proxies before the last-hop proxy. This technique makes identifying the original source of the malicious traffic even more difficult by requiring the defender to trace malicious traffic through several proxies to identify its source.

For example, adversaries may construct or use onion routing networks – such as the publicly available Tor network – to transport encrypted C2 traffic through a compromised population, allowing communication with any device within the network. Adversaries may also use operational relay box (ORB) networks composed of virtual private servers (VPS), Internet of Things (IoT) devices, smart devices, and end-of-life routers to obfuscate their operations.

In the case of network infrastructure, it is possible for an adversary to leverage multiple compromised devices to create a multi-hop proxy chain (i.e., Network Devices). By leveraging Patch System Image on routers, adversaries can add custom code to the affected network devices that will implement onion routing between those nodes. This method is dependent upon the Network Boundary Bridging method allowing the adversaries to cross the protected network boundary of the Internet perimeter and into the organization’s Wide-Area Network (WAN). Protocols such as ICMP may be used as a transport.

Similarly, adversaries may abuse peer-to-peer (P2P) and blockchain-oriented infrastructure to implement routing between a decentralized network of peers.

Detection rules6

Rules on DetectionCode tagged with T1090.003.

Sigma3

RuleLevelLog source
DNS Query Tor .Onion Address - Sysmonhighwindows / dns_query
Query Tor Onion Address - DNS Clienthighwindows / NULL
Tor Client/Browser Executionhighwindows / process_creation

Splunk3

RuleTypeRiskData source
Cisco SA - Access to Anonymizer ServicesAnomalyNULLCisco Secure Access DNS
TOR TrafficTTPNULLPalo Alto Network Traffic, Cisco Secure Firewall Threat Defense Connection Event
Windows TOR Client ExecutionAnomalyNULLCrowdStrike ProcessRollup2, Sysmon EventID 1, Windows Event Log Security 4688

Groups12

Software23

Campaigns8

Procedure examples43

Groups12

Used byProcedure example
GroupAPT28

APT28 has routed traffic over Tor and VPN servers to obfuscate their activities.

GroupAPT29

A backdoor used by APT29 created a Tor hidden service to forward traffic from the Tor client to local ports 3389 (RDP), 139 (Netbios), and 445 (SMB) enabling full remote access from outside the network and has also used TOR.

GroupEmber Bear

Ember Bear has configured multi-hop proxies via ProxyChains within victim environments.

GroupFIN4

FIN4 has used Tor to log in to victims' email accounts.

GroupGamaredon Group

Gamaredon Group has used Tor for C2 traffic.

GroupInception

Inception used chains of compromised routers to proxy C2 communications between them and cloud service providers.

GroupLeviathan

Leviathan has used multi-hop proxies to disguise the source of their malicious traffic.

GroupLotus Blossom

Lotus Blossom has used tools such as the publicly available HTran tool for proxying traffic in victim environments.

View all 12 groups examples

Software23

Used byProcedure example
ToolAsyncRAT

AsyncRAT can proxy C2 through a Tor client.

MalwareAttor

Attor has used Tor for C2 communication.

MalwareBOLDMOVE

BOLDMOVE is capable of relaying traffic from command and control servers to follow-on systems.

MalwareCyclops Blink

Cyclops Blink has used Tor nodes for C2 traffic.

MalwareDok

Dok downloads and installs Tor via homebrew.

MalwareDridex

Dridex can use multiple layers of proxy servers to hide terminal nodes in its infrastructure.

ToolFRP

The FRP client can be configured to connect to the server through a proxy.

MalwareGreyEnergy

GreyEnergy has used Tor relays for Command and Control servers.

View all 23 software examples

Campaigns8

Used byProcedure example
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, the adversaries utilized Tor nodes for C2.

CampaignCostaRicto

During CostaRicto, the threat actors used a layer of proxies to manage C2 communications.

CampaignFLORAHOX Activity

FLORAHOX Activity has routed traffic through a customized Tor relay network layer.

CampaignOperation Wocao

During Operation Wocao, threat actors executed commands through the installed web shell via Tor exit nodes.

CampaignQuad7 Activity

Quad7 Activity has routed traffic through chains of compromised network devices for password spray attacks.

CampaignRedPenguin

During RedPenguin, UNC3886 used infrastructure associated with operational relay box (ORB) networks.

CampaignSalesforce Data Exfiltration

During Salesforce Data Exfiltration, threat actors used Tor IPs for voice calls and for the collection of stolen data.

CampaignSPACEHOP Activity

SPACEHOP Activity has routed traffic through chains of compromised network devices to proxy C2 communications.

References3

  1. NGLite Trojan Open source
    Robert Falcone, Jeff White, and Peter Renals. (2021, November 7). Targeted Attack Campaign Against ManageEngine ADSelfService Plus Delivers Godzilla Webshells, NGLite Trojan and KdcSponge Stealer. Retrieved February 8, 2024.
  2. ORB Mandiant Open source
    Raggi, Michael. (2024, May 22). IOC Extinction? China-Nexus Cyber Espionage Actors Use ORB Networks to Raise Cost on Defenders. Retrieved July 8, 2024.
  3. Onion Routing Open source
    Wikipedia. (n.d.). Onion Routing. Retrieved October 20, 2020.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.