Technique with 4 sub-techniques.View on attack.mitre.org
Adversaries may use a connection proxy to direct network traffic between systems or act as an intermediary for network communications to a command and control server to avoid direct connections to their infrastructure. Many tools exist that enable traffic redirection through proxies or port redirection, including HTRAN, ZXProxy, and ZXPortMap. Adversaries use these types of proxies to manage command and control communications, reduce the number of simultaneous outbound network connections, provide resiliency in the face of connection loss, or to ride over existing trusted communications paths between victims to avoid suspicion. Adversaries may chain together multiple proxies to further disguise the source of malicious traffic.
Adversaries can also take advantage of routing schemes in Content Delivery Networks (CDNs) to proxy command and control traffic.
Rules on DetectionCode tagged with T1090 or one of its sub-techniques.
| Rule | Type | Risk | Data source | Technique |
|---|---|---|---|---|
| Cisco IOS XE Tunnel Interface Configuration | Anomaly | NULL | Cisco IOS Logs | T1090 |
| Cisco SA - Access to Anonymizer Services | Anomaly | NULL | Cisco Secure Access DNS | T1090.003 |
| Cisco Secure Firewall - Connection to File Sharing Domain | Anomaly | NULL | Cisco Secure Firewall Threat Defense Connection Event | T1090.002 |
| Linux Ngrok Reverse Proxy Usage | Anomaly | NULL | Sysmon for Linux EventID 1 | T1090 |
| Linux Proxy Socks Curl | TTP | NULL | Sysmon for Linux EventID 1 | T1090 |
| Ngrok Reverse Proxy on Network | Anomaly | NULL | Sysmon EventID 22 | T1090 |
| Okta Non-Standard VPN Usage | TTP | NULL | Okta | T1090 |
| TOR Traffic | TTP | NULL | Palo Alto Network Traffic, Cisco Secure Firewall Threat Defense Connection Event | T1090.003 |
| Windows Devtunnels Execution | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1090 |
| Windows Devtunnels Image Loaded | Anomaly | NULL | Sysmon EventID 7 | T1090 |
| Windows Ngrok Reverse Proxy Usage | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1090 |
| Windows Proxy Via Netsh | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1090.001 |
| Windows Proxy Via Registry | Anomaly | NULL | Sysmon EventID 13 | T1090.001 |
| Windows TOR Client Execution | Anomaly | NULL | CrowdStrike ProcessRollup2, Sysmon EventID 1, Windows Event Log Security 4688 | T1090.003 |
| Used by | Procedure example |
|---|---|
| GroupAPT41 | APT41 used a tool called CLASSFON to covertly proxy network communications. |
| GroupBlue Mockingbird | Blue Mockingbird has used FRP, ssf, and Venom to establish SOCKS proxy connections. |
| GroupCinnamon Tempest | Cinnamon Tempest has used a customized version of the Iox port-forwarding and proxy tool. |
| GroupContagious Interview | Contagious Interview has leveraged Astrill VPN for C2. |
| GroupCopyKittens | CopyKittens has used the AirVPN service for operational activity. |
| GroupEarth Lusca | Earth Lusca adopted Cloudflare as a proxy for compromised servers. |
| GroupFox Kitten | Fox Kitten has used the open source reverse proxy tools including FRPC and Go Proxy to establish connections from C2 to local servers. |
| GroupGamaredon Group | Gamaredon Group has used the Cloudflare Tunnel client to proxy C2 traffic. |
| Used by | Procedure example |
|---|---|
| MalwareAria-body | Aria-body has the ability to use a reverse SOCKS proxy module. |
| MalwareAuditCred | AuditCred can utilize proxy for communications. |
| MalwareBADCALL | BADCALL functions as a proxy server between the victim and C2 server. |
| MalwareBADHATCH | BADHATCH can use SOCKS4 and SOCKS5 proxies to connect to actor-controlled C2 servers. BADHATCH can also emulate a reverse proxy on a compromised machine to connect with actor-controlled C2 servers. |
| MalwareBisonal | Bisonal has supported use of a proxy server. |
| MalwareCardinal RAT | Cardinal RAT can act as a reverse proxy. |
| MalwareDridex | Dridex contains a backconnect module for tunneling network traffic through a victim's computer. Infected computers become part of a P2P botnet that can relay C2 traffic to other infected peers. |
| ToolFRP | FRP can proxy communications through a server in public IP space to local servers located behind a NAT or firewall. |
| Used by | Procedure example |
|---|---|
| Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, the adversaries utilized the rsocx tool identified as `r.exe` and `rsocx.exe` to tunnel within the internal infrastructure using a Reverse SOCKS Proxy. |
| CampaignC0017 | During C0017, APT41 used the Cloudflare CDN to proxy C2 traffic. |
| CampaignC0027 | During C0027, Scattered Spider installed the open-source rsocx reverse proxy tool on a targeted ESXi appliance. |
| CampaignOperation MidnightEclipse | During Operation MidnightEclipse, threat actors used the GO Simple Tunnel reverse proxy tool. |
| CampaignOperation Sharpshooter | For Operation Sharpshooter, the threat actors used the ExpressVPN service to hide their location. |
| CampaignOperation Wocao | During Operation Wocao, threat actors used a custom proxy tool called "Agent" which has support for multiple hops. |
| CampaignRedDelta Modified PlugX Infection Chain Operations | Mustang Panda proxied communication through the Cloudflare CDN service during RedDelta Modified PlugX Infection Chain Operations. |
| CampaignRedPenguin | During RedPenguin, UNC3886 used malware capable of establishing a SOCKS proxy connection to a specified IP and port. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.