T1090Proxy
T1090 — Proxy is a MITRE ATT&CK technique in the Command and Control tactic. Clankerusecase tracks 18 detection use cases covering it and 11 threat-intel articles citing it.
Command and Control
18Use cases
11Articles
4Sub-techniques
1Tactic
Sub-techniques (4)
Use cases covering this technique (18)
Cisco IOS XE Tunnel Interface Configuration Okta Non-Standard VPN Usage Linux Ngrok Reverse Proxy Usage Linux Proxy Socks Curl Windows Devtunnels Execution Windows Devtunnels Image Loaded Windows Ngrok Reverse Proxy Usage Ngrok Reverse Proxy on Network [LLM] Velvet Ant air-gap bridge — fcgiwrap/uptime spawning SSH from HTTP-driven FastCGI [LLM] SOCKS5 proxy masquerading as 'smbd -D' from non-Samba install path [LLM] VerdantBamboo BRICKSTORM / PLENET / AGENTPSD file-hash IOCs [LLM] Egress to BTMOB hosted C2 cluster (LATAM/Hetzner IPs, Google CDN excluded) [LLM] BadIIS traffic-hijacking: IIS 503 surge + anomalous external redirect ratio per site/hour [LLM] zrok ProxyShare SSRF — request path begins with absolute URL (CVE-2026-45568) [LLM] IIS worker (w3wp.exe) initiating outbound connection to public IP [LLM] Outbound C2 callback to xygeni-action backdoor IP 91.214.78.178 from CI runner [LLM] DRILLAPP C2: msedge.exe egress to known DRILLAPP IPs or WebSocket to localhost:8000 [LLM] Sandworm SOCKS5 C2 egress to 31.172.71[.]5 (Fornex) or progamevl.ruArticles citing this technique (11)
crit From PDB strings to MaaS: Tracking a commodity BadIIS ecosystem used by Chinese-speaking threat art-265