Activity timeline
T1090.001 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 17 reports, and 41 of the 41 threats were reported in the twelve months to 2026-09.
How adversaries use it
T1090.001 Internal Proxy is catalogued by MITRE ATT&CK under the Command and Control tactic in the Enterprise matrix, as a sub-technique of T1090 Proxy. Threadlinqs maps 41 of 2623 tracked threats (1.6%) to it; by severity that is 16 critical, 23 high, 2 medium.
Threats that use T1090.001 most often also use T1071.001 Web Protocols (29 threats), T1005 Data from Local System (25 threats), T1036.005 Match Legitimate Resource Name or Location (25 threats), T1027 Obfuscated Files or Information (24 threats), T1190 Exploit Public-Facing Application (23 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
7 tracked threat actors appear in the threats that use T1090.001; the most frequent are Cavern Manticore (3), UTA0533 (2), APT43 (1), Armored Likho (1), Kimsuky (1).
Mitigations
MITRE ATT&CK lists 1 mitigation for T1090.001.
Data sources
Telemetry that can reveal T1090.001, per MITRE ATT&CK.
- Network Traffic — Network Connection Creation, Network Traffic Content, Network Traffic Flow
Threat actors using it
Tracked threats
The 30 most recent of 41 tracked threats that use T1090.001.
- CISA Adds Two Citrix NetScaler Vulnerabilities (CVE-2026-88771, CVE-2026-88772) to KEV Catalogcritical
- NightEagle (APT-Q-95) Deploys GhostContainer Backdoor on Exchange, Exploits BlueKeep (CVE-2019-0708) and…critical
- Red Heron Weaponizes Gitea RCE (CVE-2026-60004) with JITTERLY Implant and SIXZUT Rootkitcritical
- Spamhaus H1 2026 Botnet Threat Update: Sliver Overtakes Cobalt Strike as Leading C2 Framework, .cn C&C…medium
- TerminalFix Campaign Deploys Custom Reverse-Tunnel Implant via Fake Cloudflare CAPTCHA and Multistage…critical
- Fake Cloudflare CAPTCHA Delivers TerminalFix Reverse Tunnel via ClickFix-Style DLL Sideloadinghigh
- SynkLoader: Modular Multi-Language Loader Deployed via Microsoft Teams Phishing, Likely Ransomware Precursorhigh
- 14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2critical
- Unpatched GeoServer Zero-Day SQL Injection (jsonArrayContains, GHSA-mqjf-5f49-2fjh) Under Active Exploitationcritical
- BlackTech Deploys BlueShell Linux Backdoor Against Japanese Organizationshigh
- OpenAI Models Chain Eight JFrog Artifactory Zero-Days to Escape Sandbox and Breach Hugging Facecritical
- JadeProx: China-Nexus Campaign Deploys TriBack Loader Against Government, Healthcare, and Education Targets…high
- Kimsuky (APT43) Supply-Chain Espionage Campaign Compromises South Korean Groupware Vendors, Deploys New…high
- Royal Ransomware Uses Qbot and Cobalt Strike to Rapidly Compromise Windows Domainshigh
- HollowGraph Malware Abuses Microsoft 365 Calendar as Covert C2 Channel (Cavern Framework, Suspected Cavern…high
- HOLLOWGRAPH: .NET NativeAOT Malware Abusing Microsoft Graph API and M365 Calendar Events for C2, Linked to…high
- Actively Exploited SonicWall SMA1000 Zero-Days (CVE-2026-15409, CVE-2026-15410) Chained for Full Appliance…critical
- macOS Infostealer Hijacks Telegram Desktop Sessions via tdata Theft to Bypass 2FA, Harvests Keychain…high
- SonicWall SMA1000 SSRF (CVE-2026-15409, CVSS 10.0) Chained With Appliance Management Console Command…critical
- SonicWall SMA1000 Zero-Days CVE-2026-15409 (Unauthenticated SSRF, CVSS 10.0) and CVE-2026-15410 (Post-Auth…critical
- SonicWall SMA1000 Zero-Day Vulnerabilities (CVE-2026-15409, CVE-2026-15410) Actively Exploited in Tandemcritical
- China-Linked Threat Actor Integrates Claude Code and DeepSeek-v4-pro into Active Espionage Operations…high
- LabubaRAT: Rust-Based RAT Masquerades as NVIDIA Container Runtime to Backdoor Windows Hostshigh
- The Gentlemen Ransomware: Worm-Like Self-Propagation and Network-Wide Encryption via Storm-2697's RaaS…critical
- Cavern Manticore: Iran-Linked Modular .NET C2 Framework Targeting Israeli Government and IT Sectors via…high
- Armored Likho APT Targets Government and Power Sector with New BusySnake Stealer via CVE-2025-9491 LNK Abusehigh
- Velvet Ant (China-Nexus) 'Operation Highland' — Backdoored pam_unix.so PAM Module and Trojanized OpenSSH for…high
- Targeted Espionage Campaign Against a Global Stock Exchange Executive via Incremental Outlook OST Mailbox…high
- Claude Code MCP Traffic Hijack via Malicious npm postinstall — ~/.claude.json Tampering Proxies MCP…high
- Multi-Stage Linux Intrusion via End-of-Life F5 BIG-IP and Unpatched Confluence — SSH Foothold to NTLM Relay…high
Detection coverage
Threadlinqs maintains 93 detection rules mapped to T1090.001 (SPL 37, KQL 30, Sigma 26). Rule content is available to Blue tier accounts and above; this page shows counts only.
Parent technique
T1090 Proxy — 367 tracked threats at the technique level.