FORENSIA

ATT&CK · T1090.003 · sub-technique

Multi-hop Proxy

Tactics: command-and-control

About

Adversaries may chain together multiple proxies to disguise the source of malicious traffic. Typically, a defender will be able to identify the last proxy traffic traversed before it enters their network; the defender may or may not be able to identify any previous proxies before the last-hop proxy. This technique makes identifying the original source of the malicious traffic even more difficult by requiring the defender to trace malicious traffic through several proxies to identify its source. For example, adversaries may construct or use onion routing networks – such as the publicly available Tor network – to transport encrypted C2 traffic through a compromised population, allowing communication with any device within the network. Adversaries may also use operational relay box (ORB) networks composed of virtual private servers (VPS), Internet of Things (IoT) devices, smart devices, and end-of-life routers to obfuscate their operations. In the case of network infrastructure, it is possible for an adversary to leverage multiple compromised devices to create a multi-hop proxy chain (i.e., Network Devices). By leveraging Patch System Image on routers, adversaries can add custom code to the affected network devices that will implement onion routing between those nodes. This method is dependent upon the Network Boundary Bridging method allowing the adversaries to cross the protected network boundary of the Internet perimeter and into the organization’s Wide-Area Network (WAN). Protocols such as ICMP may be used as a transport. Similarly, adversaries may abuse peer-to-peer (P2P) and blockchain-oriented infrastructure to implement routing between a decentralized network of peers.

Platforms: ESXi, Linux, macOS, Network Devices, WindowsParent: T1090 ProxyMITRE ATT&CK ↗

Used by actors

11 known groups

Software

22 malware/tools implement this

UroburosTorKeydnapDokMacSpyGreyEnergyWannaCryDridexUrsnifAttorStrongPityIndustroyerSiloscapeKobalosCyclops BlinkAsyncRATNinjaNGLiteNKAbuseFRPBOLDMOVESystemBC

Corpus indicators tagged with this technique

429 indicators in the corpus carry T1090.003.

IndicatorTypeFamilySevSrc
cve-2017-18377cve851
cve-2025-34117cve851
cve-2021-25646cve851
cve-2025-34037cve851
cve-2014-2321cve851
cve-2021-4045cve851
cve-2020-17456cve851
cve-2013-7471cve851
cve-2007-5693cve851
cve-2026-5815cve851
41999a3d0da035ff8068905c90235ea50121329cb0661e38d745974ebf5e3ae2hash802
51d39aa39478beeac94f2d12f682eccehashransomware802
0b4c112c98993f01ed761e72c2f82827aa49876034df461c1762e95281876c6bhash802
52fda5c1b9704544f32ee98d9060e689hashransomware802
78945c844fc23dd3446cf17987edeeb6cc21986820c92df82a126af24a5a38d1hash802
04ccc8f9f5e343f94ad9f41f08439b545d4b8486hash802
254568375315d86121b74db2eb8bfd8ac6bf192768c6ab5d05ca7e66b8990102hash802
bf0b36dcbbc60dbf83ecac7c56534271e53a16817909306ecc6f15f7b6106730hash802
3a69aedb78677993384dfe9b476e3d26hash802
2227df1207d2c90db46610bd98909032hash802
0a14b993fdac34f7a05b6d9d22f5fa9cfc711134hash802
55c0235188c16bd2e18a21fa78d9a39c220b8b73hash802
1a92cf241f86584361097d5735948a8170007206db56fe88739c9048767ab862hash802
22c860931f2ed22897b81ef8da16980fc24b2573ec884a153b3ff5df9e0f8cffhash802
2e04dc8bee038a5771373fc4dbaa4e45f653cd649928199e9ce8098c8b27d64ehash802
51ead7f0490bfe6b432120bbbd63b807277d016911664fb264640bb8b007d756hash802
69f524815eeb3b2069ff41a8a12cae0537de8ad9bd856d694fa21bb2af8fada8hash802
79aec671ceb205db1769da6898c9659c7c8297b13929e593050523438c09a44fhash802
a29cdca72822c1f236c53c181d03f0c45907a45f2ef3c4c2da3ef839bfd3b7a6hash802
ca5fd64932a82d3e24a19fe94d8b7636847f4335b8fd8795a63cfa0107e67048hash802

Showing the top 30 by severity of 429.