Activity timeline
T1090.003 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 28 reports, and 68 of the 68 threats were reported in the twelve months to 2026-09.
How adversaries use it
T1090.003 Multi-hop Proxy is catalogued by MITRE ATT&CK under the Command and Control tactic in the Enterprise matrix, as a sub-technique of T1090 Proxy. Threadlinqs maps 68 of 2623 tracked threats (2.6%) to it; by severity that is 17 critical, 38 high, 13 medium.
Threats that use T1090.003 most often also use T1071.001 Web Protocols (43 threats), T1190 Exploit Public-Facing Application (34 threats), T1005 Data from Local System (32 threats), T1082 System Information Discovery (32 threats), T1027 Obfuscated Files or Information (28 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
44 tracked threat actors appear in the threats that use T1090.003; the most frequent are 1VPNS (2), APT28 (2), APT38 (2), Mustang Panda (2), SNOWLIGHT (2).
Mitigations
MITRE ATT&CK lists 1 mitigation for T1090.003.
Data sources
Telemetry that can reveal T1090.003, per MITRE ATT&CK.
- Network Traffic — Network Connection Creation, Network Traffic Content, Network Traffic Flow
Threat actors using it
Tracked threats
The 30 most recent of 68 tracked threats that use T1090.003.
- CSuite Phishing Operation Steals Microsoft 365 Sessions via Device-Code Phishing and Deploys…high
- Check Point Security Gateway VPN Pre-Auth RCE (CVE-2026-85102) and Management Path Traversal Zero-Day…critical
- Vexy Ransomware Claims Data-Extortion Attack on Majani Insurance Brokers (Kenya)medium
- Nation-State Intrusions into Telecom Infrastructure via SS7, BGP Hijacking, and Router Compromise (Salt…high
- Team Cymru Infrastructure Analysis: Seven Active Ransomware Gangs (Akira, DragonForce, Clop, MedusaLocker…high
- China-Based AI Companies Conducting Industrial-Scale Distillation Campaigns Against U.S. Frontier AI Modelscritical
- Aurora Ransomware Actors Abuse Cursor Agent AI Coding Tool for Post-Compromise Exploitation Against ESXi and…high
- Emperador ransomware group claims breach of Uniguaçu (Brazilian education sector)medium
- PaperCut NG/MF Application Server Zero-Day: Unauthenticated RCE Under Active Exploitation, No CVE Assignedcritical
- PaperCut NG/MF Print Management Software Under Active Exploitation of Unpatched Vulnerabilityhigh
- Aurora Ransomware Affiliate Uses Cursor AI Coding Assistant for Attack Planning, ADCS Abuse Across 20+ Victimshigh
- Edge Infrastructure Under Siege: Tenable and SentinelOne Datasets Reveal Convergent Nation-State and…high
- Microsoft August 2026 Patch Tuesday: 400 Flaws Fixed, Including Lazarus-Exploited Zero-Day CVE-2026-68820…critical
- Cyble H1 2026 Threat Actor Landscape: 261 Tracked Groups, Five Most Active Actors Profiledhigh
- Fake Corepack.org Site Distributes OpenShield Infostealer/Proxyware to Developers; Secondary Malvertising…high
- Everest Ransomware Gang Breaches Stadler Rail Supplier Data Exchange Platform, Demands $12.3M (CHF 10M) Ransommedium
- Autonomous AI Agent (GPT-5.6 Sol) Chains Zero-Day and Stolen Credentials to Breach Hugging Face Production…critical
- Russian Bulletproof Hosting Operators Indicted: Media Land / ML.Cloud Facilitated $62M+ in Ransomware…high
- ChainVeil and ViteVenom Malware Linked to DPRK PolinRider Supply-Chain Campaignhigh
- HOLLOWGRAPH: .NET NativeAOT Malware Abusing Microsoft Graph API and M365 Calendar Events for C2, Linked to…high
- Infostealer-Enabled ClickFix Campaign Compromises Artlist via EtherHiding C2 and DLL Side-Loaded RAThigh
- Atomic Arch: Supply Chain Attack on 1,619 Arch Linux AUR Packages Deploys Rust Infostealer and eBPF Rootkithigh
- Passive DNS Pivoting Uncovers 122 New ACTINIUM (Gamaredon) Infrastructure Domainsmedium
- Starland RAT Campaign (UAT-11795) — Trojanized WebEx, Zoom, MobaXterm, DBeaver & FACEIT Installers Deliver…high
- LegacyHive: Windows User Profile Service (ProfSvc) Local Privilege Escalation Zero-Day PoC (Unpatched, No CVE)high
- Daxin Kernel Rootkit Resurfaces in Taiwan Alongside New Stupig Pre-Auth SYSTEM Backdoorcritical
- ClickLock Stealer: ClickFix-Delivered macOS Infostealer with GSocket Reverse-Shell Backdoorhigh
- Jscrambler npm Package Compromised: IronWorm Cross-Platform Infostealer (Shai-Hulud Lineage) via Rust Native…high
- Pro-Iran Hacktivist Ecosystem Uses Telegram to Coordinate DDoS, Hack-and-Leak, and Credential-Theft…medium
- US Treasury Sanctions VPN Provider 1VPNS and Crypter Seller for Enabling Ransomware Operationsmedium
Detection coverage
Threadlinqs maintains 218 detection rules mapped to T1090.003 (SPL 79, KQL 66, Sigma 73). Rule content is available to Blue tier accounts and above; this page shows counts only.
Parent technique
T1090 Proxy — 367 tracked threats at the technique level.