Threadlinqs IntelligenceStart free

ATT&CK techniqueCommand and Control

T1090 Proxy

Command and ControlEnterprise

As of 2026-10-05, T1090 (Proxy) appears in 367 tracked threats, first reported 2026-01-25 and most recently 2026-10-04, with linked actors including The Gentlemen, TeamPCP, APT28; it most often appears alongside T1027 (Obfuscated Files or Information).

Tracked threats
367115 critical, 219 high, 31 medium
First seen
2026-01-25
Last seen
2026-10-04
Threat actors
133In the threats using it
Detection rules
339Blue tier and above

Data as of:

Activity timeline

T1090 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 154 reports, and 367 of the 367 threats were reported in the twelve months to 2026-10.

How adversaries use it

T1090 Proxy is catalogued by MITRE ATT&CK under the Command and Control tactic in the Enterprise matrix. Threadlinqs maps 367 of 2623 tracked threats (14%) to it; by severity that is 115 critical, 219 high, 31 medium.

Threats that use T1090 most often also use T1027 Obfuscated Files or Information (227 threats), T1059 Command and Scripting Interpreter (221 threats), T1071 Application Layer Protocol (209 threats), T1005 Data from Local System (200 threats), T1082 System Information Discovery (200 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

133 tracked threat actors appear in the threats that use T1090; the most frequent are The Gentlemen (7), TeamPCP (6), APT28 (5), APT38 (5), APT43 (5).

Mitigations

MITRE ATT&CK lists 3 mitigations for T1090.

Data sources

Telemetry that can reveal T1090, per MITRE ATT&CK.

  • Network Traffic — Network Connection Creation, Network Traffic Content, Network Traffic Flow

Threat actors using it

Tracked threats

The 30 most recent of 367 tracked threats that use T1090.

Detection coverage

Threadlinqs maintains 339 detection rules mapped to T1090 (SPL 117, KQL 99, Sigma 122, other 1). Rule content is available to Blue tier accounts and above; this page shows counts only.

339 detection rules (SPL/KQL/Sigma) · Blue and above. Compare plans

Sub-techniques