Internal Proxy

T1090.001

Sub-technique of T1090 Proxy.View on attack.mitre.org

About this technique

Adversaries may use an internal proxy to direct command and control traffic between two or more systems in a compromised environment. Many tools exist that enable traffic redirection through proxies or port redirection, including HTRAN, ZXProxy, and ZXPortMap. Adversaries use internal proxies to manage command and control communications inside a compromised environment, to reduce the number of simultaneous outbound network connections, to provide resiliency in the face of connection loss, or to ride over existing trusted communications paths between infected systems to avoid suspicion. Internal proxy connections may use common peer-to-peer (p2p) networking protocols, such as SMB, to better blend in with the environment.

By using a compromised internal system as a proxy, adversaries may conceal the true destination of C2 traffic while reducing the need for numerous connections to external systems.

Detection rules8

Rules on DetectionCode tagged with T1090.001.

Sigma6

RuleLevelLog source
HackTool - SharpChisel Executionhighwindows / process_creation
PUA - Chisel Tunneling Tool Executionhighwindows / process_creation
RDP over Reverse SSH Tunnel WFPhighwindows / NULL
Renamed Cloudflared.EXE Executionhighwindows / process_creation
Cloudflared Portable Executionmediumwindows / process_creation
Cloudflared Quick Tunnel Executionmediumwindows / process_creation

Splunk2

RuleTypeRiskData source
Windows Proxy Via NetshAnomalyNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Windows Proxy Via RegistryAnomalyNULLSysmon EventID 13

Groups9

Software23

Campaigns3

Procedure examples35

Groups9

Used byProcedure example
GroupAPT39

APT39 used custom tools to create SOCK5 and custom protocol proxies between infected hosts.

GroupFIN13

FIN13 has utilized a proxy tool to communicate between compromised assets.

GroupHigaisa

Higaisa discovered system proxy settings and used them if available.

GroupLazarus Group

Lazarus Group has used a compromised router to serve as a proxy between a victim network's corporate and restricted segments.

GroupLotus Blossom

Lotus Blossom has used publicly available tools such as the Venom proxy tool to proxy traffic out of victim environments.

GroupStrider

Strider has used local servers with both local network and Internet access to act as internal proxy nodes to exfiltrate data from other parts of the network without direct Internet access.

GroupTurla

Turla has compromised internal network systems to act as a proxy to forward traffic to C2.

GroupVelvet Ant

Velvet Ant has tunneled traffic from victims through an internal, compromised host to proxy communications to command and control nodes.

View all 9 groups examples

Software23

Used byProcedure example
MalwareBACKSPACE

The "ZJ" variant of BACKSPACE allows "ZJ link" infections with Internet access to relay traffic from "ZJ listen" to a command server.

MalwareBRICKSTORM

BRICKSTORM has leveraged SOCKS Proxy to pivot into victim networks in attempts to resemble legitimate administrative traffic.

MalwareCHOPSTICK

CHOPSTICK used a proxy server between victims and the C2 server.

MalwareCobalt Strike

Cobalt Strike can be configured to have commands relayed over a peer-to-peer network of infected hosts. This can be used to limit the number of egress points, or provide access to a host without direct internet access.

MalwareDrovorub

Drovorub can use a port forwarding rule on its agent module to relay network traffic through the client module to a remote host on the same network.

MalwareDuqu

Duqu can be configured to have commands relayed over a peer-to-peer network of infected hosts if some of the hosts do not have Internet access.

MalwareFatDuke

FatDuke can used pipes to connect machines with restricted internet access to remote machines via other infected hosts.

MalwareGlassWorm

GlassWorm has leveraged peer-to-peer software to facilitate communications within the victim network to include the software WebRTC. GlassWorm has also established a SOCKS proxy to interact with victim devices that also acted as a proxy node for follow-on behaviors.

View all 23 software examples

Campaigns3

Used byProcedure example
CampaignAPT28 Nearest Neighbor Campaign

During APT28 Nearest Neighbor Campaign, APT28 used the built-in netsh portproxy command to create internal proxies on compromised systems.

CampaignOperation Wocao

During Operation Wocao, threat actors proxied traffic through multiple infected systems.

CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 used SSH port forwarding capabilities on public-facing systems, and configured at least one instance of Cobalt Strike to use a network pipe over SMB.

References1

  1. Trend Micro APT Attack Tools Open source
    Wilhoit, K. (2013, March 4). In-Depth Look: APT Attack Tools of the Trade. Retrieved December 2, 2015.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.