Sub-technique of T1090 Proxy.View on attack.mitre.org
Adversaries may use an internal proxy to direct command and control traffic between two or more systems in a compromised environment. Many tools exist that enable traffic redirection through proxies or port redirection, including HTRAN, ZXProxy, and ZXPortMap. Adversaries use internal proxies to manage command and control communications inside a compromised environment, to reduce the number of simultaneous outbound network connections, to provide resiliency in the face of connection loss, or to ride over existing trusted communications paths between infected systems to avoid suspicion. Internal proxy connections may use common peer-to-peer (p2p) networking protocols, such as SMB, to better blend in with the environment.
By using a compromised internal system as a proxy, adversaries may conceal the true destination of C2 traffic while reducing the need for numerous connections to external systems.
Rules on DetectionCode tagged with T1090.001.
| Rule | Level | Log source |
|---|---|---|
| HackTool - SharpChisel Execution | high | windows / process_creation |
| PUA - Chisel Tunneling Tool Execution | high | windows / process_creation |
| RDP over Reverse SSH Tunnel WFP | high | windows / NULL |
| Renamed Cloudflared.EXE Execution | high | windows / process_creation |
| Cloudflared Portable Execution | medium | windows / process_creation |
| Cloudflared Quick Tunnel Execution | medium | windows / process_creation |
| Rule | Type | Risk | Data source |
|---|---|---|---|
| Windows Proxy Via Netsh | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Windows Proxy Via Registry | Anomaly | NULL | Sysmon EventID 13 |
| Used by | Procedure example |
|---|---|
| GroupAPT39 | APT39 used custom tools to create SOCK5 and custom protocol proxies between infected hosts. |
| GroupFIN13 | FIN13 has utilized a proxy tool to communicate between compromised assets. |
| GroupHigaisa | Higaisa discovered system proxy settings and used them if available. |
| GroupLazarus Group | Lazarus Group has used a compromised router to serve as a proxy between a victim network's corporate and restricted segments. |
| GroupLotus Blossom | Lotus Blossom has used publicly available tools such as the Venom proxy tool to proxy traffic out of victim environments. |
| GroupStrider | Strider has used local servers with both local network and Internet access to act as internal proxy nodes to exfiltrate data from other parts of the network without direct Internet access. |
| GroupTurla | Turla has compromised internal network systems to act as a proxy to forward traffic to C2. |
| GroupVelvet Ant | Velvet Ant has tunneled traffic from victims through an internal, compromised host to proxy communications to command and control nodes. |
| Used by | Procedure example |
|---|---|
| MalwareBACKSPACE | The "ZJ" variant of BACKSPACE allows "ZJ link" infections with Internet access to relay traffic from "ZJ listen" to a command server. |
| MalwareBRICKSTORM | BRICKSTORM has leveraged SOCKS Proxy to pivot into victim networks in attempts to resemble legitimate administrative traffic. |
| MalwareCHOPSTICK | CHOPSTICK used a proxy server between victims and the C2 server. |
| MalwareCobalt Strike | Cobalt Strike can be configured to have commands relayed over a peer-to-peer network of infected hosts. This can be used to limit the number of egress points, or provide access to a host without direct internet access. |
| MalwareDrovorub | Drovorub can use a port forwarding rule on its agent module to relay network traffic through the client module to a remote host on the same network. |
| MalwareDuqu | Duqu can be configured to have commands relayed over a peer-to-peer network of infected hosts if some of the hosts do not have Internet access. |
| MalwareFatDuke | FatDuke can used pipes to connect machines with restricted internet access to remote machines via other infected hosts. |
| MalwareGlassWorm | GlassWorm has leveraged peer-to-peer software to facilitate communications within the victim network to include the software WebRTC. GlassWorm has also established a SOCKS proxy to interact with victim devices that also acted as a proxy node for follow-on behaviors. |
| Used by | Procedure example |
|---|---|
| CampaignAPT28 Nearest Neighbor Campaign | During APT28 Nearest Neighbor Campaign, APT28 used the built-in |
| CampaignOperation Wocao | During Operation Wocao, threat actors proxied traffic through multiple infected systems. |
| CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 used SSH port forwarding capabilities on public-facing systems, and configured at least one instance of Cobalt Strike to use a network pipe over SMB. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.