# T1090.001 Internal Proxy

> As of 2026-10-05, T1090.001 (Internal Proxy) appears in 41 tracked threats, first reported 2025-10-13 and most recently 2026-09-27, with linked actors including Cavern Manticore, UTA0533, APT43; it most often appears alongside T1071.001 (Web Protocols).

- **Tracked threats:** 41 (16 critical, 23 high, 2 medium)
- **First seen:** 2025-10-13
- **Last seen:** 2026-09-27
- **Threat actors:** 7
- **Detection rules:** 93 (counts only; Blue tier and above)

## Key facts

- **ID:** T1090.001
- **Framework:** MITRE ATT&CK
- **Tactics:** Command and Control
- **Matrix:** Enterprise
- **Parent:** T1090
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1090/001/

## Activity timeline

T1090.001 first appeared in tracked threats on 2025-10-13 and was most recently reported on 2026-09-27. The busiest month was 2026-07 with 17 reports, and 41 of the 41 threats were reported in the twelve months to 2026-09.

## How adversaries use it

T1090.001 Internal Proxy is catalogued by MITRE ATT&CK under the Command and Control tactic in the Enterprise matrix, as a sub-technique of [T1090 Proxy](https://intel.threadlinqs.com/technique/T1090). Threadlinqs maps 41 of 2623 tracked threats (1.6%) to it; by severity that is 16 critical, 23 high, 2 medium.

Threats that use T1090.001 most often also use [T1071.001 Web Protocols](https://intel.threadlinqs.com/technique/T1071.001) (29 threats), [T1005 Data from Local System](https://intel.threadlinqs.com/technique/T1005) (25 threats), [T1036.005 Match Legitimate Resource Name or Location](https://intel.threadlinqs.com/technique/T1036.005) (25 threats), [T1027 Obfuscated Files or Information](https://intel.threadlinqs.com/technique/T1027) (24 threats), [T1190 Exploit Public-Facing Application](https://intel.threadlinqs.com/technique/T1190) (23 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

7 tracked threat actors appear in the threats that use T1090.001; the most frequent are [Cavern Manticore](https://intel.threadlinqs.com/actor/Cavern%20Manticore) (3), [UTA0533](https://intel.threadlinqs.com/actor/UTA0533) (2), [APT43](https://intel.threadlinqs.com/actor/APT43) (1), [Armored Likho](https://intel.threadlinqs.com/actor/Armored%20Likho) (1), [Kimsuky](https://intel.threadlinqs.com/actor/Kimsuky) (1).

## Mitigations

MITRE ATT&CK lists 1 mitigation for T1090.001.

- [M1031 Network Intrusion Prevention](https://attack.mitre.org/mitigations/M1031/)

## Data sources

Telemetry that can reveal T1090.001, per MITRE ATT&CK.

- Network Traffic — Network Connection Creation, Network Traffic Content, Network Traffic Flow

## Threat actors using it

- [Cavern Manticore](https://intel.threadlinqs.com/actor/Cavern%20Manticore) — 3
- [UTA0533](https://intel.threadlinqs.com/actor/UTA0533) — 2
- [APT43](https://intel.threadlinqs.com/actor/APT43) — 1
- [Armored Likho](https://intel.threadlinqs.com/actor/Armored%20Likho) — 1
- [Kimsuky](https://intel.threadlinqs.com/actor/Kimsuky) — 1
- [MuddyWater](https://intel.threadlinqs.com/actor/MuddyWater) — 1
- [Velvet Ant](https://intel.threadlinqs.com/actor/Velvet%20Ant) — 1

## Tracked threats

The 30 most recent of 41 tracked threats that use T1090.001.

- [CISA Adds Two Citrix NetScaler Vulnerabilities (CVE-2026-88771, CVE-2026-88772) to KEV Catalog](https://intel.threadlinqs.com/threat/TL-2026-2711) — critical — 2026-09-27
- [NightEagle (APT-Q-95) Deploys GhostContainer Backdoor on Exchange, Exploits BlueKeep (CVE-2019-0708) and…](https://intel.threadlinqs.com/threat/TL-2026-2606) — critical — 2026-09-21
- [Red Heron Weaponizes Gitea RCE (CVE-2026-60004) with JITTERLY Implant and SIXZUT Rootkit](https://intel.threadlinqs.com/threat/TL-2026-2516) — critical — 2026-09-14
- [Spamhaus H1 2026 Botnet Threat Update: Sliver Overtakes Cobalt Strike as Leading C2 Framework, .cn C&C…](https://intel.threadlinqs.com/threat/TL-2026-2469) — medium — 2026-09-12
- [TerminalFix Campaign Deploys Custom Reverse-Tunnel Implant via Fake Cloudflare CAPTCHA and Multistage…](https://intel.threadlinqs.com/threat/TL-2026-2265) — critical — 2026-08-31
- [Fake Cloudflare CAPTCHA Delivers TerminalFix Reverse Tunnel via ClickFix-Style DLL Sideloading](https://intel.threadlinqs.com/threat/TL-2026-2203) — high — 2026-08-29
- [SynkLoader: Modular Multi-Language Loader Deployed via Microsoft Teams Phishing, Likely Ransomware Precursor](https://intel.threadlinqs.com/threat/TL-2026-2131) — high — 2026-08-24
- [14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2](https://intel.threadlinqs.com/threat/TL-2026-2099) — critical — 2026-08-21
- [Unpatched GeoServer Zero-Day SQL Injection (jsonArrayContains, GHSA-mqjf-5f49-2fjh) Under Active Exploitation](https://intel.threadlinqs.com/threat/TL-2026-2037) — critical — 2026-08-13
- [BlackTech Deploys BlueShell Linux Backdoor Against Japanese Organizations](https://intel.threadlinqs.com/threat/TL-2026-1803) — high — 2026-07-31
- [OpenAI Models Chain Eight JFrog Artifactory Zero-Days to Escape Sandbox and Breach Hugging Face](https://intel.threadlinqs.com/threat/TL-2026-1750) — critical — 2026-07-28
- [JadeProx: China-Nexus Campaign Deploys TriBack Loader Against Government, Healthcare, and Education Targets…](https://intel.threadlinqs.com/threat/TL-2026-1653) — high — 2026-07-23
- [Kimsuky (APT43) Supply-Chain Espionage Campaign Compromises South Korean Groupware Vendors, Deploys New…](https://intel.threadlinqs.com/threat/TL-2026-1643) — high — 2026-07-22
- [Royal Ransomware Uses Qbot and Cobalt Strike to Rapidly Compromise Windows Domains](https://intel.threadlinqs.com/threat/TL-2026-1626) — high — 2026-07-22
- [HollowGraph Malware Abuses Microsoft 365 Calendar as Covert C2 Channel (Cavern Framework, Suspected Cavern…](https://intel.threadlinqs.com/threat/TL-2026-1601) — high — 2026-07-21
- [HOLLOWGRAPH: .NET NativeAOT Malware Abusing Microsoft Graph API and M365 Calendar Events for C2, Linked to…](https://intel.threadlinqs.com/threat/TL-2026-1553) — high — 2026-07-20
- [Actively Exploited SonicWall SMA1000 Zero-Days (CVE-2026-15409, CVE-2026-15410) Chained for Full Appliance…](https://intel.threadlinqs.com/threat/TL-2026-1451) — critical — 2026-07-17
- [macOS Infostealer Hijacks Telegram Desktop Sessions via tdata Theft to Bypass 2FA, Harvests Keychain…](https://intel.threadlinqs.com/threat/TL-2026-1424) — high — 2026-07-16
- [SonicWall SMA1000 SSRF (CVE-2026-15409, CVSS 10.0) Chained With Appliance Management Console Command…](https://intel.threadlinqs.com/threat/TL-2026-1390) — critical — 2026-07-15
- [SonicWall SMA1000 Zero-Days CVE-2026-15409 (Unauthenticated SSRF, CVSS 10.0) and CVE-2026-15410 (Post-Auth…](https://intel.threadlinqs.com/threat/TL-2026-1382) — critical — 2026-07-15
- [SonicWall SMA1000 Zero-Day Vulnerabilities (CVE-2026-15409, CVE-2026-15410) Actively Exploited in Tandem](https://intel.threadlinqs.com/threat/TL-2026-1357) — critical — 2026-07-15
- [China-Linked Threat Actor Integrates Claude Code and DeepSeek-v4-pro into Active Espionage Operations…](https://intel.threadlinqs.com/threat/TL-2026-1354) — high — 2026-07-15
- [LabubaRAT: Rust-Based RAT Masquerades as NVIDIA Container Runtime to Backdoor Windows Hosts](https://intel.threadlinqs.com/threat/TL-2026-1322) — high — 2026-07-14
- [The Gentlemen Ransomware: Worm-Like Self-Propagation and Network-Wide Encryption via Storm-2697's RaaS…](https://intel.threadlinqs.com/threat/TL-2026-1138) — critical — 2026-07-06
- [Cavern Manticore: Iran-Linked Modular .NET C2 Framework Targeting Israeli Government and IT Sectors via…](https://intel.threadlinqs.com/threat/TL-2026-1137) — high — 2026-07-06
- [Armored Likho APT Targets Government and Power Sector with New BusySnake Stealer via CVE-2025-9491 LNK Abuse](https://intel.threadlinqs.com/threat/TL-2026-1108) — high — 2026-07-03
- [Velvet Ant (China-Nexus) 'Operation Highland' — Backdoored pam_unix.so PAM Module and Trojanized OpenSSH for…](https://intel.threadlinqs.com/threat/TL-2026-0809) — high — 2026-06-15
- [Targeted Espionage Campaign Against a Global Stock Exchange Executive via Incremental Outlook OST Mailbox…](https://intel.threadlinqs.com/threat/TL-2026-0755) — high — 2026-06-10
- [Claude Code MCP Traffic Hijack via Malicious npm postinstall — ~/.claude.json Tampering Proxies MCP…](https://intel.threadlinqs.com/threat/TL-2026-0712) — high — 2026-06-08
- [Multi-Stage Linux Intrusion via End-of-Life F5 BIG-IP and Unpatched Confluence — SSH Foothold to NTLM Relay…](https://intel.threadlinqs.com/threat/TL-2026-0596) — high — 2026-05-26

## Related CVEs

CVEs referenced by the tracked threats that use T1090.001, most frequent first.

- [CVE-2026-15409](https://intel.threadlinqs.com/cve/CVE-2026-15409)
- [CVE-2026-15410](https://intel.threadlinqs.com/cve/CVE-2026-15410)
- [CVE-2025-33073](https://intel.threadlinqs.com/cve/CVE-2025-33073)
- [CVE-2019-0708](https://intel.threadlinqs.com/cve/CVE-2019-0708)
- [CVE-2020-0688](https://intel.threadlinqs.com/cve/CVE-2020-0688)
- [CVE-2022-22948](https://intel.threadlinqs.com/cve/CVE-2022-22948)
- [CVE-2022-41328](https://intel.threadlinqs.com/cve/CVE-2022-41328)
- [CVE-2022-42045](https://intel.threadlinqs.com/cve/CVE-2022-42045)
- [CVE-2022-42475](https://intel.threadlinqs.com/cve/CVE-2022-42475)
- [CVE-2023-20867](https://intel.threadlinqs.com/cve/CVE-2023-20867)
- [CVE-2023-27532](https://intel.threadlinqs.com/cve/CVE-2023-27532)
- [CVE-2023-34048](https://intel.threadlinqs.com/cve/CVE-2023-34048)
- [CVE-2024-55591](https://intel.threadlinqs.com/cve/CVE-2024-55591)
- [CVE-2025-0282](https://intel.threadlinqs.com/cve/CVE-2025-0282)
- [CVE-2025-21590](https://intel.threadlinqs.com/cve/CVE-2025-21590)
- [CVE-2025-26125](https://intel.threadlinqs.com/cve/CVE-2025-26125)
- [CVE-2025-32433](https://intel.threadlinqs.com/cve/CVE-2025-32433)
- [CVE-2025-53521](https://intel.threadlinqs.com/cve/CVE-2025-53521)
- [CVE-2025-55182](https://intel.threadlinqs.com/cve/CVE-2025-55182)
- [CVE-2025-5777](https://intel.threadlinqs.com/cve/CVE-2025-5777)
- [CVE-2025-9491](https://intel.threadlinqs.com/cve/CVE-2025-9491)
- [CVE-2026-50661](https://intel.threadlinqs.com/cve/CVE-2026-50661)
- [CVE-2026-56155](https://intel.threadlinqs.com/cve/CVE-2026-56155)
- [CVE-2026-56164](https://intel.threadlinqs.com/cve/CVE-2026-56164)
- [CVE-2026-60004](https://intel.threadlinqs.com/cve/CVE-2026-60004)
- [CVE-2026-65617](https://intel.threadlinqs.com/cve/CVE-2026-65617)
- [CVE-2026-65921](https://intel.threadlinqs.com/cve/CVE-2026-65921)
- [CVE-2026-65923](https://intel.threadlinqs.com/cve/CVE-2026-65923)
- [CVE-2026-65924](https://intel.threadlinqs.com/cve/CVE-2026-65924)
- [CVE-2026-65925](https://intel.threadlinqs.com/cve/CVE-2026-65925)

## Detection coverage

Threadlinqs maintains 93 detection rules mapped to T1090.001 (SPL 37, KQL 30, Sigma 26). Rule content is available to Blue tier accounts and above; this page shows counts only.

93 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Parent technique

[T1090 Proxy](https://intel.threadlinqs.com/technique/T1090) — 367 tracked threats at the technique level.

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1090.001
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
