Activity timeline
T1090.002 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 31 reports, and 86 of the 86 threats were reported in the twelve months to 2026-10.
How adversaries use it
T1090.002 External Proxy is catalogued by MITRE ATT&CK under the Command and Control tactic in the Enterprise matrix, as a sub-technique of T1090 Proxy. Threadlinqs maps 86 of 2623 tracked threats (3.3%) to it; by severity that is 14 critical, 62 high, 9 medium, 1 low.
Threats that use T1090.002 most often also use T1071.001 Web Protocols (39 threats), T1027 Obfuscated Files or Information (38 threats), T1685 Disable or Modify Tools (36 threats), T1036.005 Match Legitimate Resource Name or Location (35 threats), T1082 System Information Discovery (34 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
49 tracked threat actors appear in the threats that use T1090.002; the most frequent are APT38 (3), DragonForce (3), 1VPNS (2), Andariel (2), Cavern Manticore (2).
Mitigations
MITRE ATT&CK lists 1 mitigation for T1090.002.
Data sources
Telemetry that can reveal T1090.002, per MITRE ATT&CK.
- Network Traffic — Network Connection Creation, Network Traffic Content, Network Traffic Flow
Threat actors using it
Tracked threats
The 30 most recent of 86 tracked threats that use T1090.002.
- Milk Dragon (NaiLong) AiTM Phishing-as-a-Service Kit Uses Real-Time OTP Relay and WebSocket Keylogging to…high
- DragonForce backdoors abuse Microsoft Teams TURN servers and MQTT for resilient C2high
- x47.c Windows Botnet-as-a-Service Weaponizes xAI Grok for AI-Assisted Persistence and AI API Credit Draininghigh
- Bitget Exchange Loses ~$351.6M (On-Chain: ~$356.9M) in Suspected North Korean (TraderTraitor) Backend…critical
- Autonomous AI Agent Operation (Strix, Cairn, Hermes) Steals 600K+ Payment Cards and Injects Skimmers into…critical
- eBPF Rootkit Detection: VoidLink, LinkPro, and Atomic Arch Evade Kernel-Level Monitoringmedium
- TeamFiltration Returns: UNK_CondorFiltration Credential-Spraying Campaign Targets Dormant M365 Service…high
- Iranian State Actors Deploy CHOSEN BRICK Windows Malware to Spy on Dissidents, Activists, and Journalistshigh
- N0va Phishkit Uses Device Code Phishing to Bypass MFA and Hijack SSO Sessions Across US and EUhigh
- Chosen Brick: Iranian State-Sponsored Windows Surveillance Malware Exposed by US, UK, and Dutch Agencieshigh
- Iranian MOIS-Linked Actor Uses Telegram-Controlled HEAVYGRAM/CHOSEN BRICK Malware Against Dissidents and…high
- BambooToken Malware Uses MQTT Protocol for Cross-Platform Windows/Linux C2high
- OAuth Client ID Spoofing Enables Stealthy Enumeration of Microsoft Entra ID Accounts (UNK_pyreq2323 /…high
- Bad Sushi: China-Nexus Phishing Operation Shifts to Residential Proxy Networkshigh
- Browser-in-the-Browser Phishing Campaign Abuses ScreenConnect RMM to Gain Remote Accesshigh
- BigBear 2.0 Evilginx2 Phishing-as-a-Service Campaign Targeting Microsoft 365 with MFA Bypasscritical
- StyleSmuggler — Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Storescritical
- Coordinated GitHub API Enumeration and Access Token Abuse Campaignhigh
- Attacks in Korea Deploy Radmin and UltraVNC for Remote Control, Followed by Proxy/VPN Tools for…high
- ORB Networks and Nation-State CNI Targeting: Destructive Wiper Attack on Polish Energy Infrastructure via…high
- Sality P2P Botnet Disrupted by Law Enforcement and CrowdStrike via Peer-List Sinkholinghigh
- Password Spraying Campaign Targets AWS Root User Accounts Across 150+ Organizationsmedium
- Auto-Color Linux Backdoor Reverse-Engineered: Root-Level LD_PRELOAD Persistence and Encrypted C2high
- Russian Cyber Espionage Infrastructure Uses Evilginx and OAuth Phishing to Steal Accountshigh
- Khmer Shadow: Amber Saolao cluster targets Cambodian government with NIGHTFORGE loader and Havoc Demonhigh
- JarService/Zhima Multi-Stage Android Malware Targets DoFun Automotive Head Units, Linked to BADBOX Botnethigh
- Android Car Malware Spreads Through Built-In Updaters for Ad Fraud, Proxy Botnethigh
- Jewelbug APT Runs Espionage and Crypto Fraud Operations Side by Sidehigh
- Payroll Pirates (Storm-2755) Abuse Microsoft Graph for HR/Finance Staff Recon After AiTM Account Compromisehigh
- Microsoft 365 AitM Phishing Campaign Hijacks Sessions via Residential Proxies to Harvest Payroll and Finance…high
Detection coverage
Threadlinqs maintains 218 detection rules mapped to T1090.002 (SPL 79, KQL 71, Sigma 68). Rule content is available to Blue tier accounts and above; this page shows counts only.
Parent technique
T1090 Proxy — 367 tracked threats at the technique level.