FORENSIA

ATT&CK · T1090.001 · sub-technique

Internal Proxy

Tactics: command-and-control

About

Adversaries may use an internal proxy to direct command and control traffic between two or more systems in a compromised environment. Many tools exist that enable traffic redirection through proxies or port redirection, including HTRAN, ZXProxy, and ZXPortMap. Adversaries use internal proxies to manage command and control communications inside a compromised environment, to reduce the number of simultaneous outbound network connections, to provide resiliency in the face of connection loss, or to ride over existing trusted communications paths between infected systems to avoid suspicion. Internal proxy connections may use common peer-to-peer (p2p) networking protocols, such as SMB, to better blend in with the environment. By using a compromised internal system as a proxy, adversaries may conceal the true destination of C2 traffic while reducing the need for numerous connections to external systems.

Platforms: ESXi, Linux, macOS, Network Devices, WindowsParent: T1090 ProxyMITRE ATT&CK ↗

Used by actors

9 known groups

Software

23 malware/tools implement this

HikitCHOPSTICKBACKSPACEDuquMiniDukeWinnti for WindowsCobalt StrikeInvisiMoleKazuarDrovorubFatDukePay2KeyStuxnetSliverMythicmetaMainMafaldaNinjaGomirStarProxyGlassWormBRICKSTORMHiddenFace

Corpus indicators tagged with this technique

165 indicators in the corpus carry T1090.001.

IndicatorTypeFamilySevSrc
cve-2025-1055cveransomware853
cve-2023-52271cveransomware853
cve-2025-61155cveransomware853
84b573305b732a8372a082c057242953hash803
458653300b48c90a8659b9e9cadc13717bce42b6hash803
130fdc32de36a362e65c7138b560eb8d8f6ae599hash803
123e80a34508c4dede7cc70e76931fcchash803
fdef9e489f773319f55f92f712d1b7b5447d59a632b8f4173d1b161d3759ad92hashphishing802
2654c08491a0f7c4a3dfc6282de5638bhash803
a7bd8869293212e1671df90d2d41b96d4933eb9408b1111bd830e111a91bb202hashphishing802
625b6535321d58bb5c613e85332bf731hash803
b8eed63ab9cbdca494f26a6f66bfd4a0a693b3f0hash803
873f1277a42de5c82f869459e7fb7c94554a642bhash803
b42159d68ba58d7857c091b5acc59e30e50a854b15f7ce04b61ff6c11cdf0156hash803
9c44bc9373377831c45dd0ac2661a28ehash803
681075027553546c119ec447eb8df84633dcffcehash803
6f9fbe29f8cc2788e2bc9d631e0eea2a8e9837076837b55838005a0e654f0a9ehashransomware803
f4d77958a12a0778283d3e679b24b18f82e332c4hash803
00e195d94d3b1f7092eb9ed132f89d1bhash803
2064ef387ac9e51ba72b32004d99e8a0b291dbab24ed8db30f437abf1b40cb49hashphishing802
57e26f6e3b311a1064c946b69159ee05abedf9228b2f95c65536429e7ac7fb24hashphishing802
84ad78b2bab946c3677fdc28ebd8a774hash803
89f8e42c825d09a0a50e99bbf7304d7037be33ea362a57d34f87fa7981f80126hashphishing802
b1b7aaa5bd4408a4d3003a9fabcdd041hash803
b439749a581ac5a29b5c9d91fc092bf4ceaa76a4hash803
d0da2832ae1e13a98f7ce7e33a66c1b0d9797b81f69ece134e4462ea55ac923ehashransomware803
e952c18272efa1c3d73d0a5381bcf443c02743fehash803
f8d93c1769e877aae7e7d5c289a467b5ae371c7ahash803
f918535f974591ef031bd0f30a8171e3da27a6754e6426a8ba095f83195661c8hashransomware801
42692bd13333623e9085d0c1326574a3391efcbf18158bb04972103c9ee4a3b8hash803

Showing the top 30 by severity of 165.