ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1090×

10 examples

TechniqueUsed byProcedure example
T1090
Proxy
CampaignSharePoint ToolShell Exploitation

During SharePoint ToolShell Exploitation, threat actors used Fast Reverse Proxy to communicate with C2.

T1090
Proxy
CampaignRedDelta Modified PlugX Infection Chain Operations

Mustang Panda proxied communication through the Cloudflare CDN service during RedDelta Modified PlugX Infection Chain Operations.

T1090
Proxy
CampaignRedPenguin

During RedPenguin, UNC3886 used malware capable of establishing a SOCKS proxy connection to a specified IP and port.

T1090
Proxy
CampaignOperation Sharpshooter

For Operation Sharpshooter, the threat actors used the ExpressVPN service to hide their location.

T1090
Proxy
CampaignOperation MidnightEclipse

During Operation MidnightEclipse, threat actors used the GO Simple Tunnel reverse proxy tool.

T1090
Proxy
CampaignSalesforce Data Exfiltration

During Salesforce Data Exfiltration, threat actors used Mullvad VPN IPs to proxy voice phishing calls.

T1090
Proxy
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, the adversaries utilized the rsocx tool identified as `r.exe` and `rsocx.exe` to tunnel within the internal infrastructure using a Reverse SOCKS Proxy.

T1090
Proxy
CampaignOperation Wocao

During Operation Wocao, threat actors used a custom proxy tool called "Agent" which has support for multiple hops.

T1090
Proxy
CampaignC0017

During C0017, APT41 used the Cloudflare CDN to proxy C2 traffic.

T1090
Proxy
CampaignC0027

During C0027, Scattered Spider installed the open-source rsocx reverse proxy tool on a targeted ESXi appliance.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.