Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Command and Control/ T1090.003

T1090.003Multi-hop Proxy

T1090.003 — Multi-hop Proxy is a MITRE ATT&CK technique in the Command and Control tactic. Clankerusecase tracks 12 detection use cases covering it and 6 threat-intel articles citing it.

Command and Control
View on the matrix → Filter Detection Library MITRE official spec ↗
12Use cases
6Articles
0Sub-techniques
1Tactic

Use cases covering this technique (12)

1Password activity from Tor exit node Internal delivery · alerting DD Application user activity from Tor Internal delivery · alerting DD Google Workspace access from Tor exit node Internal delivery · alerting DD Windows TOR Client Execution ESCU actions · hunting P Cisco SA - Access to Anonymizer Services ESCU actions · hunting P TOR Traffic ESCU actions · alerting P [LLM] IronWorm C2 beacon to hardcoded IPs and Tor endpoints from temp-dir process Bespoke c2 · hunting DSΣPDDCS [LLM] UAT-7810 ORB relay C2 — outbound to LONGLEASH/DOGLEASH relay IPs Bespoke c2 · hunting DSΣPDDCS [LLM] Edge device recruited as ORB relay — inbound sessions from UAT-7810 IPs Bespoke c2 · hunting DSPDDCS [LLM] Outbound connection to UAT-7810 (LapDogs ORB) SHORTLEASH/DOGLEASH C2 VPS Bespoke c2 · hunting DSΣPDDCS [LLM] Salesforce connected-app OAuth access from first-seen ISP / anonymizing proxy (stolen-token reuse) Bespoke exploit · hunting DSP [LLM] Session/Oxen P2P exfil DNS or TCP to getsession.org from build/CI host Bespoke c2 · alerting DSΣPDD

Articles citing this technique (6)