# T1090.002 External Proxy

> As of 2026-10-05, T1090.002 (External Proxy) appears in 86 tracked threats, first reported 2026-02-02 and most recently 2026-10-04, with linked actors including APT38, DragonForce, 1VPNS; it most often appears alongside T1071.001 (Web Protocols).

- **Tracked threats:** 86 (14 critical, 62 high, 9 medium, 1 low)
- **First seen:** 2026-02-02
- **Last seen:** 2026-10-04
- **Threat actors:** 49
- **Detection rules:** 218 (counts only; Blue tier and above)

## Key facts

- **ID:** T1090.002
- **Framework:** MITRE ATT&CK
- **Tactics:** Command and Control
- **Matrix:** Enterprise
- **Parent:** T1090
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1090/002/

## Activity timeline

T1090.002 first appeared in tracked threats on 2026-02-02 and was most recently reported on 2026-10-04. The busiest month was 2026-07 with 31 reports, and 86 of the 86 threats were reported in the twelve months to 2026-10.

## How adversaries use it

T1090.002 External Proxy is catalogued by MITRE ATT&CK under the Command and Control tactic in the Enterprise matrix, as a sub-technique of [T1090 Proxy](https://intel.threadlinqs.com/technique/T1090). Threadlinqs maps 86 of 2623 tracked threats (3.3%) to it; by severity that is 14 critical, 62 high, 9 medium, 1 low.

Threats that use T1090.002 most often also use [T1071.001 Web Protocols](https://intel.threadlinqs.com/technique/T1071.001) (39 threats), [T1027 Obfuscated Files or Information](https://intel.threadlinqs.com/technique/T1027) (38 threats), [T1685 Disable or Modify Tools](https://intel.threadlinqs.com/technique/T1685) (36 threats), [T1036.005 Match Legitimate Resource Name or Location](https://intel.threadlinqs.com/technique/T1036.005) (35 threats), [T1082 System Information Discovery](https://intel.threadlinqs.com/technique/T1082) (34 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

49 tracked threat actors appear in the threats that use T1090.002; the most frequent are [APT38](https://intel.threadlinqs.com/actor/APT38) (3), [DragonForce](https://intel.threadlinqs.com/actor/DragonForce) (3), [1VPNS](https://intel.threadlinqs.com/actor/1VPNS) (2), [Andariel](https://intel.threadlinqs.com/actor/Andariel) (2), [Cavern Manticore](https://intel.threadlinqs.com/actor/Cavern%20Manticore) (2).

## Mitigations

MITRE ATT&CK lists 1 mitigation for T1090.002.

- [M1031 Network Intrusion Prevention](https://attack.mitre.org/mitigations/M1031/)

## Data sources

Telemetry that can reveal T1090.002, per MITRE ATT&CK.

- Network Traffic — Network Connection Creation, Network Traffic Content, Network Traffic Flow

## Threat actors using it

- [APT38](https://intel.threadlinqs.com/actor/APT38) — 3
- [DragonForce](https://intel.threadlinqs.com/actor/DragonForce) — 3
- [1VPNS](https://intel.threadlinqs.com/actor/1VPNS) — 2
- [Andariel](https://intel.threadlinqs.com/actor/Andariel) — 2
- [Cavern Manticore](https://intel.threadlinqs.com/actor/Cavern%20Manticore) — 2
- [FSB Center 16](https://intel.threadlinqs.com/actor/FSB%20Center%2016) — 2
- [Iran Ministry of Intelligence](https://intel.threadlinqs.com/actor/Iran%20Ministry%20of%20Intelligence) — 2
- [Lazarus Group](https://intel.threadlinqs.com/actor/Lazarus%20Group) — 2
- [MoYu Group](https://intel.threadlinqs.com/actor/MoYu%20Group) — 2
- [Sapphire Sleet](https://intel.threadlinqs.com/actor/Sapphire%20Sleet) — 2
- [Security](https://intel.threadlinqs.com/actor/Security) — 2
- [Stardust Chollima](https://intel.threadlinqs.com/actor/Stardust%20Chollima) — 2

## Tracked threats

The 30 most recent of 86 tracked threats that use T1090.002.

- [Milk Dragon (NaiLong) AiTM Phishing-as-a-Service Kit Uses Real-Time OTP Relay and WebSocket Keylogging to…](https://intel.threadlinqs.com/threat/TL-2026-2901) — high — 2026-10-04
- [DragonForce backdoors abuse Microsoft Teams TURN servers and MQTT for resilient C2](https://intel.threadlinqs.com/threat/TL-2026-2836) — high — 2026-10-01
- [x47.c Windows Botnet-as-a-Service Weaponizes xAI Grok for AI-Assisted Persistence and AI API Credit Draining](https://intel.threadlinqs.com/threat/TL-2026-2686) — high — 2026-09-27
- [Bitget Exchange Loses ~$351.6M (On-Chain: ~$356.9M) in Suspected North Korean (TraderTraitor) Backend…](https://intel.threadlinqs.com/threat/TL-2026-2650) — critical — 2026-09-25
- [Autonomous AI Agent Operation (Strix, Cairn, Hermes) Steals 600K+ Payment Cards and Injects Skimmers into…](https://intel.threadlinqs.com/threat/TL-2026-2633) — critical — 2026-09-23
- [eBPF Rootkit Detection: VoidLink, LinkPro, and Atomic Arch Evade Kernel-Level Monitoring](https://intel.threadlinqs.com/threat/TL-2026-2624) — medium — 2026-09-22
- [TeamFiltration Returns: UNK_CondorFiltration Credential-Spraying Campaign Targets Dormant M365 Service…](https://intel.threadlinqs.com/threat/TL-2026-2616) — high — 2026-09-22
- [Iranian State Actors Deploy CHOSEN BRICK Windows Malware to Spy on Dissidents, Activists, and Journalists](https://intel.threadlinqs.com/threat/TL-2026-2543) — high — 2026-09-16
- [N0va Phishkit Uses Device Code Phishing to Bypass MFA and Hijack SSO Sessions Across US and EU](https://intel.threadlinqs.com/threat/TL-2026-2537) — high — 2026-09-16
- [Chosen Brick: Iranian State-Sponsored Windows Surveillance Malware Exposed by US, UK, and Dutch Agencies](https://intel.threadlinqs.com/threat/TL-2026-2534) — high — 2026-09-16
- [Iranian MOIS-Linked Actor Uses Telegram-Controlled HEAVYGRAM/CHOSEN BRICK Malware Against Dissidents and…](https://intel.threadlinqs.com/threat/TL-2026-2526) — high — 2026-09-15
- [BambooToken Malware Uses MQTT Protocol for Cross-Platform Windows/Linux C2](https://intel.threadlinqs.com/threat/TL-2026-2520) — high — 2026-09-15
- [OAuth Client ID Spoofing Enables Stealthy Enumeration of Microsoft Entra ID Accounts (UNK_pyreq2323 /…](https://intel.threadlinqs.com/threat/TL-2026-2476) — high — 2026-09-13
- [Bad Sushi: China-Nexus Phishing Operation Shifts to Residential Proxy Networks](https://intel.threadlinqs.com/threat/TL-2026-2471) — high — 2026-09-12
- [Browser-in-the-Browser Phishing Campaign Abuses ScreenConnect RMM to Gain Remote Access](https://intel.threadlinqs.com/threat/TL-2026-2453) — high — 2026-09-09
- [BigBear 2.0 Evilginx2 Phishing-as-a-Service Campaign Targeting Microsoft 365 with MFA Bypass](https://intel.threadlinqs.com/threat/TL-2026-2374) — critical — 2026-09-07
- [StyleSmuggler — Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores](https://intel.threadlinqs.com/threat/TL-2026-2358) — critical — 2026-09-06
- [Coordinated GitHub API Enumeration and Access Token Abuse Campaign](https://intel.threadlinqs.com/threat/TL-2026-2339) — high — 2026-09-05
- [Attacks in Korea Deploy Radmin and UltraVNC for Remote Control, Followed by Proxy/VPN Tools for…](https://intel.threadlinqs.com/threat/TL-2026-2323) — high — 2026-09-03
- [ORB Networks and Nation-State CNI Targeting: Destructive Wiper Attack on Polish Energy Infrastructure via…](https://intel.threadlinqs.com/threat/TL-2026-2317) — high — 2026-09-03
- [Sality P2P Botnet Disrupted by Law Enforcement and CrowdStrike via Peer-List Sinkholing](https://intel.threadlinqs.com/threat/TL-2026-2284) — high — 2026-09-01
- [Password Spraying Campaign Targets AWS Root User Accounts Across 150+ Organizations](https://intel.threadlinqs.com/threat/TL-2026-2263) — medium — 2026-08-31
- [Auto-Color Linux Backdoor Reverse-Engineered: Root-Level LD_PRELOAD Persistence and Encrypted C2](https://intel.threadlinqs.com/threat/TL-2026-2264) — high — 2026-08-30
- [Russian Cyber Espionage Infrastructure Uses Evilginx and OAuth Phishing to Steal Accounts](https://intel.threadlinqs.com/threat/TL-2026-2167) — high — 2026-08-27
- [Khmer Shadow: Amber Saolao cluster targets Cambodian government with NIGHTFORGE loader and Havoc Demon](https://intel.threadlinqs.com/threat/TL-2026-2148) — high — 2026-08-26
- [JarService/Zhima Multi-Stage Android Malware Targets DoFun Automotive Head Units, Linked to BADBOX Botnet](https://intel.threadlinqs.com/threat/TL-2026-2111) — high — 2026-08-22
- [Android Car Malware Spreads Through Built-In Updaters for Ad Fraud, Proxy Botnet](https://intel.threadlinqs.com/threat/TL-2026-2100) — high — 2026-08-21
- [Jewelbug APT Runs Espionage and Crypto Fraud Operations Side by Side](https://intel.threadlinqs.com/threat/TL-2026-2002) — high — 2026-08-13
- [Payroll Pirates (Storm-2755) Abuse Microsoft Graph for HR/Finance Staff Recon After AiTM Account Compromise](https://intel.threadlinqs.com/threat/TL-2026-1970) — high — 2026-08-10
- [Microsoft 365 AitM Phishing Campaign Hijacks Sessions via Residential Proxies to Harvest Payroll and Finance…](https://intel.threadlinqs.com/threat/TL-2026-1930) — high — 2026-08-07

## Related CVEs

CVEs referenced by the tracked threats that use T1090.002, most frequent first.

- [CVE-2023-52271](https://intel.threadlinqs.com/cve/CVE-2023-52271)
- [CVE-2024-55591](https://intel.threadlinqs.com/cve/CVE-2024-55591)
- [CVE-2025-1055](https://intel.threadlinqs.com/cve/CVE-2025-1055)
- [CVE-2008-4128](https://intel.threadlinqs.com/cve/CVE-2008-4128)
- [CVE-2017-16237](https://intel.threadlinqs.com/cve/CVE-2017-16237)
- [CVE-2018-0171](https://intel.threadlinqs.com/cve/CVE-2018-0171)
- [CVE-2018-0802](https://intel.threadlinqs.com/cve/CVE-2018-0802)
- [CVE-2018-13379](https://intel.threadlinqs.com/cve/CVE-2018-13379)
- [CVE-2022-20775](https://intel.threadlinqs.com/cve/CVE-2022-20775)
- [CVE-2022-40684](https://intel.threadlinqs.com/cve/CVE-2022-40684)
- [CVE-2022-41328](https://intel.threadlinqs.com/cve/CVE-2022-41328)
- [CVE-2022-42045](https://intel.threadlinqs.com/cve/CVE-2022-42045)
- [CVE-2022-42475](https://intel.threadlinqs.com/cve/CVE-2022-42475)
- [CVE-2023-27532](https://intel.threadlinqs.com/cve/CVE-2023-27532)
- [CVE-2023-27997](https://intel.threadlinqs.com/cve/CVE-2023-27997)
- [CVE-2023-36025](https://intel.threadlinqs.com/cve/CVE-2023-36025)
- [CVE-2023-48788](https://intel.threadlinqs.com/cve/CVE-2023-48788)
- [CVE-2024-21762](https://intel.threadlinqs.com/cve/CVE-2024-21762)
- [CVE-2024-23897](https://intel.threadlinqs.com/cve/CVE-2024-23897)
- [CVE-2024-2617](https://intel.threadlinqs.com/cve/CVE-2024-2617)
- [CVE-2024-40766](https://intel.threadlinqs.com/cve/CVE-2024-40766)
- [CVE-2024-53704](https://intel.threadlinqs.com/cve/CVE-2024-53704)
- [CVE-2025-26125](https://intel.threadlinqs.com/cve/CVE-2025-26125)
- [CVE-2025-27152](https://intel.threadlinqs.com/cve/CVE-2025-27152)
- [CVE-2025-32433](https://intel.threadlinqs.com/cve/CVE-2025-32433)
- [CVE-2025-33073](https://intel.threadlinqs.com/cve/CVE-2025-33073)
- [CVE-2025-49704](https://intel.threadlinqs.com/cve/CVE-2025-49704)
- [CVE-2025-49706](https://intel.threadlinqs.com/cve/CVE-2025-49706)
- [CVE-2025-53770](https://intel.threadlinqs.com/cve/CVE-2025-53770)
- [CVE-2025-53771](https://intel.threadlinqs.com/cve/CVE-2025-53771)

## Detection coverage

Threadlinqs maintains 218 detection rules mapped to T1090.002 (SPL 79, KQL 71, Sigma 68). Rule content is available to Blue tier accounts and above; this page shows counts only.

218 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Parent technique

[T1090 Proxy](https://intel.threadlinqs.com/technique/T1090) — 367 tracked threats at the technique level.

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1090.002
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
