Real-world descriptions of how a group, tool or campaign used a technique.
47 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1090 Proxy |
MalwarereGeorg | reGeorg can establish an HTTP or SOCKS proxy to tunnel data in and out of a network. |
| T1090 Proxy |
MalwareUrsnif | Ursnif has used a peer-to-peer (P2P) network for C2. |
| T1090 Proxy |
MalwareRansomHub | RansomHub can use a proxy to connect to remote SFTP servers. |
| T1090 Proxy |
MalwareLITTLELAMB.WOOLTEA | LITTLELAMB.WOOLTEA has the ability to function as a SOCKS proxy. |
| T1090 Proxy |
MalwareHavoc | Havoc has the ability to route HTTP/S communications through designated proxies. |
| T1090 Proxy |
MalwareAuditCred | AuditCred can utilize proxy for communications. |
| T1090 Proxy |
MalwareRainyDay | RainyDay can use proxy tools including boost_proxy_client for reverse proxy functionality. |
| T1090 Proxy |
MalwareNETWIRE | NETWIRE can implement use of proxies to pivot traffic. |
| T1090 Proxy |
MalwareAria-body | Aria-body has the ability to use a reverse SOCKS proxy module. |
| T1090 Proxy |
MalwareBADHATCH | BADHATCH can use SOCKS4 and SOCKS5 proxies to connect to actor-controlled C2 servers. BADHATCH can also emulate a reverse proxy on a compromised machine to connect with actor-controlled C2 servers. |
| T1090 Proxy |
MalwareSombRAT | SombRAT has the ability to use an embedded SOCKS proxy in C2 communications. |
| T1090 Proxy |
MalwareHOPLIGHT | HOPLIGHT has multiple proxy options that mask traffic between the malware and the remote operators. |
| T1090 Proxy |
MalwareGreen Lambert | Green Lambert can use proxies for C2 traffic. |
| T1090 Proxy |
MalwareBisonal | Bisonal has supported use of a proxy server. |
| T1090 Proxy |
MalwareKEYPLUG | KEYPLUG has used Cloudflare CDN associated infrastructure to redirect C2 communications to malicious domains. |
| T1090 Proxy |
MalwareXTunnel | XTunnel relays traffic between a C2 server and a victim. |
| T1090 Proxy |
MalwareTSCookie | TSCookie has the ability to proxy communications with command and control (C2) servers. |
| T1090 Proxy |
MalwareTYPEFRAME | A TYPEFRAME variant can force the compromised system to function as a proxy server. |
| T1090 Proxy |
MalwareSagerunex | Sagerunex uses several proxy configuration settings to ensure connectivity. |
| T1090 Proxy |
MalwareSDBbot | SDBbot has the ability to use port forwarding to establish a proxy between a target host and C2. |
| T1090 Proxy |
MalwareGoBear | GoBear implements SOCKS5 proxy functionality. |
| T1090 Proxy |
MalwareBADCALL | BADCALL functions as a proxy server between the victim and C2 server. |
| T1090 Proxy |
MalwareKapeka | Kapeka can identify system proxy settings via `WinHttpGetIEProxyConfigForCurrentUser()` during initialization and utilize these settings for subsequent command and control operations. |
| T1090 Proxy |
MalwareSamurai | Samurai has the ability to proxy connections to specified remote IPs and ports through a a proxy module. |
| T1090 Proxy |
MalwarePLEAD | PLEAD has the ability to proxy network communications. |
| T1090 Proxy |
MalwareCardinal RAT | Cardinal RAT can act as a reverse proxy. |
| T1090 Proxy |
MalwareNeo-reGeorg | Neo-reGeorg has the ability to establish a SOCKS5 proxy on a compromised web server. |
| T1090 Proxy |
MalwareHARDRAIN | HARDRAIN uses the command |
| T1090 Proxy |
MalwareFunnyDream | FunnyDream can identify and use configured proxies in a compromised network for C2 communication. |
| T1090 Proxy |
MalwareKessel | Kessel can use a proxy during exfiltration if set in the configuration. |
| T1090 Proxy |
MalwareZxShell | ZxShell can set up an HTTP or SOCKS proxy. |
| T1090 Proxy |
MalwareZIPLINE | ZIPLINE can create a proxy server on compromised hosts. |
| T1090 Proxy |
MalwareKOCTOPUS | KOCTOPUS has deployed a modified version of Invoke-Ngrok to expose open local ports to the Internet. |
| T1090 Proxy |
MalwareLunarWeb | LunarWeb has the ability to use a HTTP proxy server for C&C communications. |
| T1090 Proxy |
MalwareSocksbot | Socksbot can start SOCKS proxy threads. |
| T1090 Proxy |
MalwarejRAT | jRAT can serve as a SOCKS proxy server. |
| T1090 Proxy |
MalwareDridex | Dridex contains a backconnect module for tunneling network traffic through a victim's computer. Infected computers become part of a P2P botnet that can relay C2 traffic to other infected peers. |
| T1090 Proxy |
MalwareVasport | Vasport is capable of tunneling though a proxy. |
| T1090 Proxy |
MalwareWarzoneRAT | WarzoneRAT has the capability to act as a reverse proxy. |
| T1090 Proxy |
Toolngrok | ngrok can be used to proxy connections to machines located behind NAT or firewalls. |
| T1090 Proxy |
ToolFRP | FRP can proxy communications through a server in public IP space to local servers located behind a NAT or firewall. |
| T1090 Proxy |
ToolPoshC2 | PoshC2 contains modules that allow for use of proxies in command and control. |
| T1090 Proxy |
Toolnetsh | netsh can be used to set up a proxy tunnel to allow remote host access to an infected host. |
| T1090 Proxy |
ToolRemcos | Remcos uses the infected hosts as SOCKS5 proxies to allow for tunneling and proxying. |
| T1090 Proxy |
ToolHTRAN | HTRAN can proxy TCP socket connections to obfuscate command and control infrastructure. |
| T1090 Proxy |
ToolQuasarRAT | QuasarRAT can communicate over a reverse proxy using SOCKS5. |
| T1090 Proxy |
MalwareKali365 | Kali365 has leveraged Cloudflare workers as reverse proxy infrastructure. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.