Techniques › T1090 › T1090.003
T1090.003 Multi-hop Proxy
command and control — ESXi, Linux, macOS, Network Devices, Windows · attack.mitre.org · JSON
1
MITRE detection strategy
5
analytics
3
Sigma rules tagged attack.t1090.003
0
KEV CVEs mapped here
<p>Adversaries may chain together multiple proxies to disguise the source of malicious traffic. Typically, a defender will be able to identify the last proxy traffic traversed before it enters their network; the defender may or may not be able to identify any previous proxies before the last-hop proxy. This technique makes identifying the original source of the malicious traffic even more difficult by requiring the defender to trace malicious traffic through several proxies to identify its source.</p><p>For example, adversaries may construct or use onion routing networks – such as the publicly available Tor network – to transport encrypted C2 traffic through a compromised population, allowing communication with any device within the network. Adversaries may also use operational relay box (ORB) networks composed of virtual private servers (VPS), Internet of Things (IoT) devices, smart devices, and end-of-life routers to obfuscate their operations.</p><p>In the case of network infrastructure, it is possible for an adversary to leverage multiple compromised devices to create a multi-hop proxy chain (i.e., Network Devices). By leveraging Patch System Image on routers, adversaries can add custom code to the affected network devices that will implement onion routing between those nodes. This method is dependent upon the Network Boundary Bridging method allowing the adversaries to cross the protected network boundary of the Internet perimeter and into the organization’s Wide-Area Network (WAN). Protocols such as ICMP may be used as a transport.</p><p>Similarly, adversaries may abuse peer-to-peer (P2P) and blockchain-oriented infrastructure to implement routing between a decentralized network of peers.</p>
KEV CVEs mapped to this technique · CTID Mappings Explorer
None. No KEV entry in the public mapping names this technique. Given that 74.7% of KEV has no mapping at all, this says more about the mapping than about the technique.
Detection strategy · ATT&CK Enterprise v19.2
- DET0359 Multi-hop Proxy Behavior via Relay Node Chaining, Onion Routing, and Network Tunneling v1.0
AN1020 WindowsSuspicious processes (e.g., Tor clients, relays, unknown binaries) launch with sustained encrypted outbound traffic to known anonymity infrastructure (e.g., Tor, I2P), and may relay to additional internal systems via reverse proxying, ICMP tunneling, or socket forwarding.dns:query
Outbound resolution to hidden service domains (e.g., `.onion`)→ DC0078 Network Traffic FlowTunable:DomainCategoryProcessParentConnectionDurationAN1021 LinuxTools such astor,nglite,proxychains,chisel, or custom daemons repeatedly initiate outbound sessions to multiple nodes before final destination. This behavior is abnormal for Linux services outside of VPN, monitoring, or CDN relay contexts.Tunable:ExecutablePathRelayCountProtocolTypeAN1022 macOSLaunchAgents or LaunchDaemons initiate persistent Tor or relay processes that make encrypted outbound connections. May be paired with sandbox bypasses or unsigned executables communicating over SOCKS proxies.Tunable:LaunchdLabelUnsignedBinarySOCKSPortUsageAN1023 ESXiOutbound encrypted traffic initiated from hypervisor shell or via VM backdoor mechanisms to relays in VPS infrastructure, especially if traversing multiple nodes before reaching Internet destination. Packet captures or firewall logs show non-VM communication paths.esxi:esxupdate/var/log/esxupdate.log or /var/log/vmksummary.log→ DC0082 Network Connection CreationTunable:HopCountShellAccessVPSIPRangeAN1024 Network DevicesEncrypted traffic or ICMP tunneling from border routers to internal routers or unknown external IPs. Forwarded traffic shows consistent hop-to-hop relaying without matching configured VPN or expected network topology.Tunable:VPNConfigWhitelistICMPPayloadEntropyRelayChainSignature
Sigma rules · SigmaHQ da9bb07d64, tag attack.t1090.003
Author: frack113
· 2022-02-20 (modified 2025-10-27) · logsource: product=windows category=process_creation · 62f7c9bf-9135-49b2-8aeb-1e54a6ecc13c
Detects the use of Tor or Tor-Browser to connect to onion routing networks
Author: Nasreddine Bencherchali (Nextron Systems)
· 2022-02-20 (modified 2025-09-12) · logsource: product=windows service=dns-client · 8384bd26-bde6-4da9-8e5d-4174a7a47ca2
Detects DNS resolution of an .onion address related to Tor routing networks
Author: frack113
· 2022-02-20 (modified 2025-09-12) · logsource: product=windows category=dns_query · b55ca2a3-7cff-4dda-8bdd-c7bfa63bf544
Detects DNS queries to an ".onion" address related to Tor routing networks
Rules tagged at the parent level (attack.t1090) 22
These target the parent technique, not this sub-technique specifically. Listed for completeness, not counted as coverage.
Author: Florian Roth (Nextron Systems)
· 2022-11-03 · logsource: product=linux category=network_connection · 19bf6fdb-7721-4f3d-867f-53467f6a5db6
Detects an executable accessing an ngrok tunneling endpoint, which could be a sign of forbidden exfiltration of data exfiltration by malicious actors
Author: Florian Roth (Nextron Systems)
· 2022-11-03 (modified 2024-02-02) · logsource: product=windows category=network_connection · 1d08ac94-400d-4469-a82f-daee9a908849
Detects an executable initiating a network connection to "ngrok" tunneling domains.
Attackers were seen using this "ngrok" in order to store their second stage payloads and malware.
While communication with such domains can be legitimate, often times is a sign of either data exfiltration by malicious actors or additional download.
Author: Florian Roth (Nextron Systems), omkar72, oscd.community, Swachchhanda Shrawan Poudel
· 2019-01-29 (modified 2023-09-01) · logsource: product=windows category=process_creation · 322ed9ec-fcab-4f67-9a34-e7c6aef43614
Detects the execution of netsh commands that configure a new port forwarding (PortProxy) rule
Author: frack113, Florian Roth
· 2022-09-02 (modified 2024-11-23) · logsource: product=windows category=process_creation · 32410e29-5f94-4568-b6a3-d91a8adad863
Detects the use of Fast Reverse Proxy. frp is a fast reverse proxy to help you expose a local server behind a NAT or firewall to the Internet.
Author: Mark Morowczynski '@markmorow', Gloria Lee, '@gleeiamglo'
· 2023-09-07 · logsource: product=azure service=riskdetection · 36440e1c-5c22-467a-889b-593e66498472
Indicates sign-in from a malicious IP address known to be malicious at time of sign-in.
Author: Andreas Braathen (mnemonic.io)
· 2024-06-17 · logsource: product=windows category=network_connection · 3ab65069-d82a-4d44-a759-466661a082d1
Detects an executable initiating a network connection to "LocaltoNet" tunneling sub-domains.
LocaltoNet is a reverse proxy that enables localhost services to be exposed to the Internet.
Attackers have been seen to use this service for command-and-control activities to bypass MFA and perimeter controls.
Author: Security Onion Solutions
· 2024-03-08 · logsource: product=opencanary category=application · 5498fc09-adc6-4804-b9d9-5cca1f0b8760
Detects instances where an HTTPPROXY service on an OpenCanary node has had an attempt to proxy another page.
Author: Muhammad Faisal (@faisalusuf), Hunter Juhan (@threatHNTR)
· 2024-06-03 · logsource: product=windows category=process_creation · 5fc297ae-25b6-488a-8f25-cc12ac29b744
Detects potentially suspicious execution of the Qemu utility in a Windows environment.
Threat actors have leveraged this utility and this technique for achieving network access as reported by Kaspersky.
Author: Florian Roth (Nextron Systems)
· 2022-04-29 · logsource: product=windows service=terminalservices-localsessionmanager · 64d51a51-32a6-49f0-9f3d-17e34d640272
Detects cases in which ngrok, a reverse proxy tool, forwards events to the local RDP port, which could be a sign of malicious behaviour
Author: Florian Roth (Nextron Systems)
· 2022-10-08 (modified 2024-11-23) · logsource: product=windows category=process_creation · 68d37776-61db-42f5-bf54-27e87072d17e
Detects the use of NPS, a port forwarding and intranet penetration proxy server
Author: Nasreddine Bencherchali (Nextron Systems)
· 2023-05-17 (modified 2023-12-21) · logsource: product=windows category=process_creation · 7050bba1-1aed-454e-8f73-3f46f09ce56a
Detects execution of the "cloudflared" tool with the tunnel "cleanup" flag in order to cleanup tunnel connections.
Author: Ömer Günal
· 2020-06-17 (modified 2022-10-05) · logsource: product=linux category=process_creation · 72f4ab3f-787d-495d-a55d-68c2ff46cf4c
Detects setting proxy configuration
Author: Florian Roth (Nextron Systems), oscd.community
· 2019-01-29 (modified 2023-02-13) · logsource: product=windows category=process_creation · 782d6f3e-4c5d-4b8c-92a3-1d05fed72e63
Detects the execution of netsh to configure a port forwarding of port 3389 (RDP) rule
Author: Mark Morowczynski '@markmorow', Gloria Lee, '@gleeiamglo'
· 2023-09-03 · logsource: product=azure service=riskdetection · 821b4dc3-1295-41e7-b157-39ab212dd6bd
Indicates sign-ins from IP addresses infected with malware that is known to actively communicate with a bot server.
Author: Janantha Marasinghe, Nasreddine Bencherchali (Nextron Systems)
· 2023-05-17 (modified 2023-12-20) · logsource: product=windows category=process_creation · 9a019ffc-3580-4c9d-8d87-079f7e8d3fd4
Detects execution of the "cloudflared" tool to connect back to a tunnel. This was seen used by threat actors to maintain persistence and remote access to compromised networks.
Author: Mark Morowczynski '@markmorow', Gloria Lee, '@gleeiamglo'
· 2023-09-07 · logsource: product=azure service=riskdetection · a3f55ebd-0c01-4ed6-adc0-8fb76d8cd3cd
Indicates sign-in from a malicious IP address based on high failure rates.
Author: Andreas Hunkeler (@Karneades)
· 2021-06-22 (modified 2024-03-25) · logsource: product=windows category=registry_event · a54f842a-3713-4b45-8c84-5f136fdebd3c
Detects the modification of the PortProxy registry key which is used for port forwarding.
Author: Nasreddine Bencherchali (Nextron Systems)
· 2022-07-08 · logsource: product=windows category=ps_script · bd33d2aa-497e-4651-9893-5c5364646595
Detects powershell scripts that creates sockets/listeners which could be indicative of tunneling activity
Author: Andreas Braathen (mnemonic.io)
· 2024-06-17 · logsource: product=linux category=network_connection · c4568f5d-131f-4e78-83d4-45b2da0ec4f1
Detects an executable initiating a network connection to "LocaltoNet" tunneling sub-domains.
LocaltoNet is a reverse proxy that enables localhost services to be exposed to the Internet.
Attackers have been seen to use this service for command-and-control activities to bypass MFA and perimeter controls.
Author: Florian Roth (Nextron Systems)
· 2022-10-08 (modified 2024-11-23) · logsource: product=windows category=process_creation · d7654f02-e04b-4934-9838-65c46f187ebc
Detects the use of IOX - a tool for port forwarding and intranet proxy purposes
Author: Arda Buyukkaya (EclecticIQ)
· 2025-02-11 · logsource: product=windows category=process_creation · e99375eb-3ee0-407a-9f90-79569cc6a01c
Detects the execution of the "curl.exe" command, referencing "SOCKS" and ".onion" domains, which could be indicative of Kalambur backdoor activity.
Author: Florian Roth (Nextron Systems)
· 2022-12-27 (modified 2023-02-04) · logsource: product=windows category=process_creation · f5e3b62f-e577-4e59-931e-0a15b2b94e1e
Detects executable names or flags used by Htran or Htran-like tools (e.g. NATBypass)