Proxy

T1090

Technique with 4 sub-techniques.View on attack.mitre.org

About this technique

Adversaries may use a connection proxy to direct network traffic between systems or act as an intermediary for network communications to a command and control server to avoid direct connections to their infrastructure. Many tools exist that enable traffic redirection through proxies or port redirection, including HTRAN, ZXProxy, and ZXPortMap. Adversaries use these types of proxies to manage command and control communications, reduce the number of simultaneous outbound network connections, provide resiliency in the face of connection loss, or to ride over existing trusted communications paths between victims to avoid suspicion. Adversaries may chain together multiple proxies to further disguise the source of malicious traffic.

Adversaries can also take advantage of routing schemes in Content Delivery Networks (CDNs) to proxy command and control traffic.

Detection rules45

Rules on DetectionCode tagged with T1090 or one of its sub-techniques.

Sigma31

RuleLevelLog sourceTechnique
Communication To LocaltoNet Tunneling Service Initiatedhighwindows / network_connectionT1090
Communication To LocaltoNet Tunneling Service Initiated - Linuxhighlinux / network_connectionT1090
Communication To Ngrok Tunneling Service - Linuxhighlinux / network_connectionT1090
Communication To Ngrok Tunneling Service Initiatedhighwindows / network_connectionT1090
DNS Query Tor .Onion Address - Sysmonhighwindows / dns_queryT1090.003
HackTool - Htran/NATBypass Executionhighwindows / process_creationT1090
HackTool - SharpChisel Executionhighwindows / process_creationT1090.001
Malicious IP Address Sign-In Failure Ratehighazure / NULLT1090
Malicious IP Address Sign-In Suspicioushighazure / NULLT1090
Ngrok Usage with Remote Desktop Servicehighwindows / NULLT1090
OpenCanary - HTTPPROXY Login Attempthighopencanary / applicationT1090
PUA - Chisel Tunneling Tool Executionhighwindows / process_creationT1090.001
PUA - Fast Reverse Proxy (FRP) Executionhighwindows / process_creationT1090
PUA - NPS Tunneling Tool Executionhighwindows / process_creationT1090
PUA- IOX Tunneling Tool Executionhighwindows / process_creationT1090

Splunk14

RuleTypeRiskData sourceTechnique
Cisco IOS XE Tunnel Interface ConfigurationAnomalyNULLCisco IOS LogsT1090
Cisco SA - Access to Anonymizer ServicesAnomalyNULLCisco Secure Access DNST1090.003
Cisco Secure Firewall - Connection to File Sharing DomainAnomalyNULLCisco Secure Firewall Threat Defense Connection EventT1090.002
Linux Ngrok Reverse Proxy UsageAnomalyNULLSysmon for Linux EventID 1T1090
Linux Proxy Socks CurlTTPNULLSysmon for Linux EventID 1T1090
Ngrok Reverse Proxy on NetworkAnomalyNULLSysmon EventID 22T1090
Okta Non-Standard VPN UsageTTPNULLOktaT1090
TOR TrafficTTPNULLPalo Alto Network Traffic, Cisco Secure Firewall Threat Defense Connection EventT1090.003
Windows Devtunnels ExecutionAnomalyNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2T1090
Windows Devtunnels Image LoadedAnomalyNULLSysmon EventID 7T1090
Windows Ngrok Reverse Proxy UsageAnomalyNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2T1090
Windows Proxy Via NetshAnomalyNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2T1090.001
Windows Proxy Via RegistryAnomalyNULLSysmon EventID 13T1090.001
Windows TOR Client ExecutionAnomalyNULLCrowdStrike ProcessRollup2, Sysmon EventID 1, Windows Event Log Security 4688T1090.003

Sub-techniques4

IDNameExamples
T1090.001Internal Proxy35
T1090.002External Proxy23
T1090.003Multi-hop Proxy43
T1090.004Domain Fronting5

Groups19

Software47

Show 23 more

Campaigns10

Procedure examples76

Groups19

Used byProcedure example
GroupAPT41

APT41 used a tool called CLASSFON to covertly proxy network communications.

GroupBlue Mockingbird

Blue Mockingbird has used FRP, ssf, and Venom to establish SOCKS proxy connections.

GroupCinnamon Tempest

Cinnamon Tempest has used a customized version of the Iox port-forwarding and proxy tool.

GroupContagious Interview

Contagious Interview has leveraged Astrill VPN for C2.

GroupCopyKittens

CopyKittens has used the AirVPN service for operational activity.

GroupEarth Lusca

Earth Lusca adopted Cloudflare as a proxy for compromised servers.

GroupFox Kitten

Fox Kitten has used the open source reverse proxy tools including FRPC and Go Proxy to establish connections from C2 to local servers.

GroupGamaredon Group

Gamaredon Group has used the Cloudflare Tunnel client to proxy C2 traffic.

View all 19 groups examples

Software47

Used byProcedure example
MalwareAria-body

Aria-body has the ability to use a reverse SOCKS proxy module.

MalwareAuditCred

AuditCred can utilize proxy for communications.

MalwareBADCALL

BADCALL functions as a proxy server between the victim and C2 server.

MalwareBADHATCH

BADHATCH can use SOCKS4 and SOCKS5 proxies to connect to actor-controlled C2 servers. BADHATCH can also emulate a reverse proxy on a compromised machine to connect with actor-controlled C2 servers.

MalwareBisonal

Bisonal has supported use of a proxy server.

MalwareCardinal RAT

Cardinal RAT can act as a reverse proxy.

MalwareDridex

Dridex contains a backconnect module for tunneling network traffic through a victim's computer. Infected computers become part of a P2P botnet that can relay C2 traffic to other infected peers.

ToolFRP

FRP can proxy communications through a server in public IP space to local servers located behind a NAT or firewall.

View all 47 software examples

Campaigns10

Used byProcedure example
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, the adversaries utilized the rsocx tool identified as `r.exe` and `rsocx.exe` to tunnel within the internal infrastructure using a Reverse SOCKS Proxy.

CampaignC0017

During C0017, APT41 used the Cloudflare CDN to proxy C2 traffic.

CampaignC0027

During C0027, Scattered Spider installed the open-source rsocx reverse proxy tool on a targeted ESXi appliance.

CampaignOperation MidnightEclipse

During Operation MidnightEclipse, threat actors used the GO Simple Tunnel reverse proxy tool.

CampaignOperation Sharpshooter

For Operation Sharpshooter, the threat actors used the ExpressVPN service to hide their location.

CampaignOperation Wocao

During Operation Wocao, threat actors used a custom proxy tool called "Agent" which has support for multiple hops.

CampaignRedDelta Modified PlugX Infection Chain Operations

Mustang Panda proxied communication through the Cloudflare CDN service during RedDelta Modified PlugX Infection Chain Operations.

CampaignRedPenguin

During RedPenguin, UNC3886 used malware capable of establishing a SOCKS proxy connection to a specified IP and port.

View all 10 campaigns examples

References1

  1. Trend Micro APT Attack Tools Open source
    Wilhoit, K. (2013, March 4). In-Depth Look: APT Attack Tools of the Trade. Retrieved December 2, 2015.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.