T1090 Proxy — ATT&CK Technique
Adversaries may use a connection proxy to direct network traffic between systems or act as an intermediary for network communications to a command and control server to avoid direct connections to their infrastructure. Many tools exist that enable traffic redirection through proxies or port redirection, including HTRAN, ZXProxy, and ZXPortMap. Adversaries use these types of proxies to manage command and control communications, reduce the number of simultaneous outbound network connections, provide resiliency in the face of connection loss, or to ride over existing trusted communications paths between victims to avoid suspicion. Adversaries may chain together multiple proxies to further disguise the source of malicious traffic. Adversaries can also take advantage of routing schemes in Content Delivery Networks (CDNs) to proxy command and control traffic.
Detection coverage (30)
- Kalambur Backdoor Curl TOR SOCKS Proxy Execution high
- OpenCanary - HTTPPROXY Login Attempt high
- Malicious IP Address Sign-In Failure Rate high
- Malicious IP Address Sign-In Suspicious high
- Sign-In From Malware Infected IP high
- Communication To Ngrok Tunneling Service - Linux high
- Connection Proxy low
- PUA - Fast Reverse Proxy (FRP) Execution high
- PUA- IOX Tunneling Tool Execution high
- PUA - NPS Tunneling Tool Execution high
- Potentially Suspicious Usage Of Qemu medium
- Communication To LocaltoNet Tunneling Service Initiated - Linux high
- Ngrok Usage with Remote Desktop Service high
- Communication To LocaltoNet Tunneling Service Initiated high
- Communication To Ngrok Tunneling Service Initiated high
- Suspicious TCP Tunnel Via PowerShell Script medium
- Cloudflared Tunnel Execution medium
- Cloudflared Tunnel Connections Cleanup medium
- HackTool - Htran/NATBypass Execution high
- New Port Forwarding Rule Added Via Netsh.EXE medium
- RDP Port Forwarding Rule Added Via Netsh.EXE high
- New PortProxy Registry Entry Added medium
- Cisco IOS XE Tunnel Interface Configuration
- Okta Non-Standard VPN Usage
- Linux Ngrok Reverse Proxy Usage
- Linux Proxy Socks Curl
- Windows Devtunnels Execution
- Windows Devtunnels Image Loaded
- Windows Ngrok Reverse Proxy Usage
- Ngrok Reverse Proxy on Network
Malware using this technique
- Sagerunex
- NETWIRE
- ZIPLINE
- RansomHub
- KOCTOPUS
- SDBbot
- SombRAT
- HTRAN
- FRP
- Havoc
- AuditCred
- ZxShell
- HOPLIGHT
- WarzoneRAT
- ngrok
- LITTLELAMB.WOOLTEA
- Neo-reGeorg
- Remcos
- BADCALL
- BADHATCH
- GoBear
- netsh
- PLEAD
- Dridex
- HARDRAIN
- Kessel
- TSCookie
- PoshC2
- TYPEFRAME
- reGeorg
- jRAT
- Green Lambert
- FunnyDream
- KEYPLUG
- RainyDay
- Cardinal RAT
- Socksbot
- Vasport
- QuasarRAT
- Kapeka
- Ursnif
- Aria-body
- Bisonal
- XTunnel
- LunarWeb
- Samurai