# T1090.003 Multi-hop Proxy

> As of 2026-10-05, T1090.003 (Multi-hop Proxy) appears in 68 tracked threats, first reported 2026-01-29 and most recently 2026-09-30, with linked actors including 1VPNS, APT28, APT38; it most often appears alongside T1071.001 (Web Protocols).

- **Tracked threats:** 68 (17 critical, 38 high, 13 medium)
- **First seen:** 2026-01-29
- **Last seen:** 2026-09-30
- **Threat actors:** 44
- **Detection rules:** 218 (counts only; Blue tier and above)

## Key facts

- **ID:** T1090.003
- **Framework:** MITRE ATT&CK
- **Tactics:** Command and Control
- **Matrix:** Enterprise
- **Parent:** T1090
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1090/003/

## Activity timeline

T1090.003 first appeared in tracked threats on 2026-01-29 and was most recently reported on 2026-09-30. The busiest month was 2026-07 with 28 reports, and 68 of the 68 threats were reported in the twelve months to 2026-09.

## How adversaries use it

T1090.003 Multi-hop Proxy is catalogued by MITRE ATT&CK under the Command and Control tactic in the Enterprise matrix, as a sub-technique of [T1090 Proxy](https://intel.threadlinqs.com/technique/T1090). Threadlinqs maps 68 of 2623 tracked threats (2.6%) to it; by severity that is 17 critical, 38 high, 13 medium.

Threats that use T1090.003 most often also use [T1071.001 Web Protocols](https://intel.threadlinqs.com/technique/T1071.001) (43 threats), [T1190 Exploit Public-Facing Application](https://intel.threadlinqs.com/technique/T1190) (34 threats), [T1005 Data from Local System](https://intel.threadlinqs.com/technique/T1005) (32 threats), [T1082 System Information Discovery](https://intel.threadlinqs.com/technique/T1082) (32 threats), [T1027 Obfuscated Files or Information](https://intel.threadlinqs.com/technique/T1027) (28 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

44 tracked threat actors appear in the threats that use T1090.003; the most frequent are [1VPNS](https://intel.threadlinqs.com/actor/1VPNS) (2), [APT28](https://intel.threadlinqs.com/actor/APT28) (2), [APT38](https://intel.threadlinqs.com/actor/APT38) (2), [Mustang Panda](https://intel.threadlinqs.com/actor/Mustang%20Panda) (2), [SNOWLIGHT](https://intel.threadlinqs.com/actor/SNOWLIGHT) (2).

## Mitigations

MITRE ATT&CK lists 1 mitigation for T1090.003.

- [M1037 Filter Network Traffic](https://attack.mitre.org/mitigations/M1037/)

## Data sources

Telemetry that can reveal T1090.003, per MITRE ATT&CK.

- Network Traffic — Network Connection Creation, Network Traffic Content, Network Traffic Flow

## Threat actors using it

- [1VPNS](https://intel.threadlinqs.com/actor/1VPNS) — 2
- [APT28](https://intel.threadlinqs.com/actor/APT28) — 2
- [APT38](https://intel.threadlinqs.com/actor/APT38) — 2
- [Mustang Panda](https://intel.threadlinqs.com/actor/Mustang%20Panda) — 2
- [SNOWLIGHT](https://intel.threadlinqs.com/actor/SNOWLIGHT) — 2
- [Sapphire Sleet](https://intel.threadlinqs.com/actor/Sapphire%20Sleet) — 2
- [Stardust Chollima](https://intel.threadlinqs.com/actor/Stardust%20Chollima) — 2
- [UNC6508](https://intel.threadlinqs.com/actor/UNC6508) — 2
- [APT36](https://intel.threadlinqs.com/actor/APT36) — 1
- [Andariel](https://intel.threadlinqs.com/actor/Andariel) — 1
- [Cavern Manticore](https://intel.threadlinqs.com/actor/Cavern%20Manticore) — 1
- [Cleaver](https://intel.threadlinqs.com/actor/Cleaver) — 1

## Tracked threats

The 30 most recent of 68 tracked threats that use T1090.003.

- [CSuite Phishing Operation Steals Microsoft 365 Sessions via Device-Code Phishing and Deploys…](https://intel.threadlinqs.com/threat/TL-2026-2802) — high — 2026-09-30
- [Check Point Security Gateway VPN Pre-Auth RCE (CVE-2026-85102) and Management Path Traversal Zero-Day…](https://intel.threadlinqs.com/threat/TL-2026-2677) — critical — 2026-09-26
- [Vexy Ransomware Claims Data-Extortion Attack on Majani Insurance Brokers (Kenya)](https://intel.threadlinqs.com/threat/TL-2026-2713) — medium — 2026-09-25
- [Nation-State Intrusions into Telecom Infrastructure via SS7, BGP Hijacking, and Router Compromise (Salt…](https://intel.threadlinqs.com/threat/TL-2026-2649) — high — 2026-09-25
- [Team Cymru Infrastructure Analysis: Seven Active Ransomware Gangs (Akira, DragonForce, Clop, MedusaLocker…](https://intel.threadlinqs.com/threat/TL-2026-2517) — high — 2026-09-15
- [China-Based AI Companies Conducting Industrial-Scale Distillation Campaigns Against U.S. Frontier AI Models](https://intel.threadlinqs.com/threat/TL-2026-2413) — critical — 2026-09-09
- [Aurora Ransomware Actors Abuse Cursor Agent AI Coding Tool for Post-Compromise Exploitation Against ESXi and…](https://intel.threadlinqs.com/threat/TL-2026-2243) — high — 2026-08-30
- [Emperador ransomware group claims breach of Uniguaçu (Brazilian education sector)](https://intel.threadlinqs.com/threat/TL-2026-2207) — medium — 2026-08-29
- [PaperCut NG/MF Application Server Zero-Day: Unauthenticated RCE Under Active Exploitation, No CVE Assigned](https://intel.threadlinqs.com/threat/TL-2026-2179) — critical — 2026-08-28
- [PaperCut NG/MF Print Management Software Under Active Exploitation of Unpatched Vulnerability](https://intel.threadlinqs.com/threat/TL-2026-2171) — high — 2026-08-27
- [Aurora Ransomware Affiliate Uses Cursor AI Coding Assistant for Attack Planning, ADCS Abuse Across 20+ Victims](https://intel.threadlinqs.com/threat/TL-2026-2165) — high — 2026-08-27
- [Edge Infrastructure Under Siege: Tenable and SentinelOne Datasets Reveal Convergent Nation-State and…](https://intel.threadlinqs.com/threat/TL-2026-2153) — high — 2026-08-26
- [Microsoft August 2026 Patch Tuesday: 400 Flaws Fixed, Including Lazarus-Exploited Zero-Day CVE-2026-68820…](https://intel.threadlinqs.com/threat/TL-2026-1987) — critical — 2026-08-11
- [Cyble H1 2026 Threat Actor Landscape: 261 Tracked Groups, Five Most Active Actors Profiled](https://intel.threadlinqs.com/threat/TL-2026-1721) — high — 2026-07-27
- [Fake Corepack.org Site Distributes OpenShield Infostealer/Proxyware to Developers; Secondary Malvertising…](https://intel.threadlinqs.com/threat/TL-2026-1676) — high — 2026-07-24
- [Everest Ransomware Gang Breaches Stadler Rail Supplier Data Exchange Platform, Demands $12.3M (CHF 10M) Ransom](https://intel.threadlinqs.com/threat/TL-2026-1642) — medium — 2026-07-22
- [Autonomous AI Agent (GPT-5.6 Sol) Chains Zero-Day and Stolen Credentials to Breach Hugging Face Production…](https://intel.threadlinqs.com/threat/TL-2026-1632) — critical — 2026-07-22
- [Russian Bulletproof Hosting Operators Indicted: Media Land / ML.Cloud Facilitated $62M+ in Ransomware…](https://intel.threadlinqs.com/threat/TL-2026-1580) — high — 2026-07-20
- [ChainVeil and ViteVenom Malware Linked to DPRK PolinRider Supply-Chain Campaign](https://intel.threadlinqs.com/threat/TL-2026-1570) — high — 2026-07-20
- [HOLLOWGRAPH: .NET NativeAOT Malware Abusing Microsoft Graph API and M365 Calendar Events for C2, Linked to…](https://intel.threadlinqs.com/threat/TL-2026-1553) — high — 2026-07-20
- [Infostealer-Enabled ClickFix Campaign Compromises Artlist via EtherHiding C2 and DLL Side-Loaded RAT](https://intel.threadlinqs.com/threat/TL-2026-1552) — high — 2026-07-19
- [Atomic Arch: Supply Chain Attack on 1,619 Arch Linux AUR Packages Deploys Rust Infostealer and eBPF Rootkit](https://intel.threadlinqs.com/threat/TL-2026-1498) — high — 2026-07-18
- [Passive DNS Pivoting Uncovers 122 New ACTINIUM (Gamaredon) Infrastructure Domains](https://intel.threadlinqs.com/threat/TL-2026-1484) — medium — 2026-07-18
- [Starland RAT Campaign (UAT-11795) — Trojanized WebEx, Zoom, MobaXterm, DBeaver & FACEIT Installers Deliver…](https://intel.threadlinqs.com/threat/TL-2026-1454) — high — 2026-07-17
- [LegacyHive: Windows User Profile Service (ProfSvc) Local Privilege Escalation Zero-Day PoC (Unpatched, No CVE)](https://intel.threadlinqs.com/threat/TL-2026-1414) — high — 2026-07-16
- [Daxin Kernel Rootkit Resurfaces in Taiwan Alongside New Stupig Pre-Auth SYSTEM Backdoor](https://intel.threadlinqs.com/threat/TL-2026-1404) — critical — 2026-07-16
- [ClickLock Stealer: ClickFix-Delivered macOS Infostealer with GSocket Reverse-Shell Backdoor](https://intel.threadlinqs.com/threat/TL-2026-1402) — high — 2026-07-16
- [Jscrambler npm Package Compromised: IronWorm Cross-Platform Infostealer (Shai-Hulud Lineage) via Rust Native…](https://intel.threadlinqs.com/threat/TL-2026-1379) — high — 2026-07-15
- [Pro-Iran Hacktivist Ecosystem Uses Telegram to Coordinate DDoS, Hack-and-Leak, and Credential-Theft…](https://intel.threadlinqs.com/threat/TL-2026-1309) — medium — 2026-07-14
- [US Treasury Sanctions VPN Provider 1VPNS and Crypter Seller for Enabling Ransomware Operations](https://intel.threadlinqs.com/threat/TL-2026-1295) — medium — 2026-07-14

## Related CVEs

CVEs referenced by the tracked threats that use T1090.003, most frequent first.

- [CVE-2018-0171](https://intel.threadlinqs.com/cve/CVE-2018-0171)
- [CVE-2024-3400](https://intel.threadlinqs.com/cve/CVE-2024-3400)
- [CVE-2024-40766](https://intel.threadlinqs.com/cve/CVE-2024-40766)
- [CVE-2008-4128](https://intel.threadlinqs.com/cve/CVE-2008-4128)
- [CVE-2017-0144](https://intel.threadlinqs.com/cve/CVE-2017-0144)
- [CVE-2018-0802](https://intel.threadlinqs.com/cve/CVE-2018-0802)
- [CVE-2019-11580](https://intel.threadlinqs.com/cve/CVE-2019-11580)
- [CVE-2020-25213](https://intel.threadlinqs.com/cve/CVE-2020-25213)
- [CVE-2020-36847](https://intel.threadlinqs.com/cve/CVE-2020-36847)
- [CVE-2021-26855](https://intel.threadlinqs.com/cve/CVE-2021-26855)
- [CVE-2021-29441](https://intel.threadlinqs.com/cve/CVE-2021-29441)
- [CVE-2022-20775](https://intel.threadlinqs.com/cve/CVE-2022-20775)
- [CVE-2022-40684](https://intel.threadlinqs.com/cve/CVE-2022-40684)
- [CVE-2022-42045](https://intel.threadlinqs.com/cve/CVE-2022-42045)
- [CVE-2023-20198](https://intel.threadlinqs.com/cve/CVE-2023-20198)
- [CVE-2023-27532](https://intel.threadlinqs.com/cve/CVE-2023-27532)
- [CVE-2023-27997](https://intel.threadlinqs.com/cve/CVE-2023-27997)
- [CVE-2023-38831](https://intel.threadlinqs.com/cve/CVE-2023-38831)
- [CVE-2023-46805](https://intel.threadlinqs.com/cve/CVE-2023-46805)
- [CVE-2024-21887](https://intel.threadlinqs.com/cve/CVE-2024-21887)
- [CVE-2024-47575](https://intel.threadlinqs.com/cve/CVE-2024-47575)
- [CVE-2024-53704](https://intel.threadlinqs.com/cve/CVE-2024-53704)
- [CVE-2024-55591](https://intel.threadlinqs.com/cve/CVE-2024-55591)
- [CVE-2024-8963](https://intel.threadlinqs.com/cve/CVE-2024-8963)
- [CVE-2025-11371](https://intel.threadlinqs.com/cve/CVE-2025-11371)
- [CVE-2025-14611](https://intel.threadlinqs.com/cve/CVE-2025-14611)
- [CVE-2025-20333](https://intel.threadlinqs.com/cve/CVE-2025-20333)
- [CVE-2025-20362](https://intel.threadlinqs.com/cve/CVE-2025-20362)
- [CVE-2025-26125](https://intel.threadlinqs.com/cve/CVE-2025-26125)
- [CVE-2025-30406](https://intel.threadlinqs.com/cve/CVE-2025-30406)

## Detection coverage

Threadlinqs maintains 218 detection rules mapped to T1090.003 (SPL 79, KQL 66, Sigma 73). Rule content is available to Blue tier accounts and above; this page shows counts only.

218 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Parent technique

[T1090 Proxy](https://intel.threadlinqs.com/technique/T1090) — 367 tracked threats at the technique level.

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1090.003
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
