T1090.003Multi-hop Proxy
T1090.003 — Multi-hop Proxy is a MITRE ATT&CK technique in the Command and Control tactic. Clankerusecase tracks 12 detection use cases covering it and 6 threat-intel articles citing it.
Command and Control
12Use cases
6Articles
0Sub-techniques
1Tactic
↑ Parent technique: T1090 · Proxy
Use cases covering this technique (12)
1Password activity from Tor exit node Application user activity from Tor Google Workspace access from Tor exit node Windows TOR Client Execution Cisco SA - Access to Anonymizer Services TOR Traffic [LLM] IronWorm C2 beacon to hardcoded IPs and Tor endpoints from temp-dir process [LLM] UAT-7810 ORB relay C2 — outbound to LONGLEASH/DOGLEASH relay IPs [LLM] Edge device recruited as ORB relay — inbound sessions from UAT-7810 IPs [LLM] Outbound connection to UAT-7810 (LapDogs ORB) SHORTLEASH/DOGLEASH C2 VPS [LLM] Salesforce connected-app OAuth access from first-seen ISP / anonymizing proxy (stolen-token reuse) [LLM] Session/Oxen P2P exfil DNS or TCP to getsession.org from build/CI hostArticles citing this technique (6)
crit Winning 54% of the time art-214