Activity timeline
T1090.004 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 5 reports, and 12 of the 12 threats were reported in the twelve months to 2026-09.
How adversaries use it
T1090.004 Domain Fronting is catalogued by MITRE ATT&CK under the Command and Control tactic in the Enterprise matrix, as a sub-technique of T1090 Proxy. Threadlinqs maps 12 of 2623 tracked threats (0.5%) to it; by severity that is 2 critical, 8 high, 2 medium.
Threats that use T1090.004 most often also use T1027 Obfuscated Files or Information (10 threats), T1071.001 Web Protocols (10 threats), T1041 Exfiltration Over C2 Channel (8 threats), T1005 Data from Local System (7 threats), T1036.005 Match Legitimate Resource Name or Location (7 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
2 tracked threat actors appear in the threats that use T1090.004; the most frequent are Cavern Manticore (1), Grandoreiro operators (1).
Mitigations
MITRE ATT&CK lists 1 mitigation for T1090.004.
Data sources
Telemetry that can reveal T1090.004, per MITRE ATT&CK.
- Network Traffic — Network Traffic Content
Threat actors using it
Tracked threats
12 tracked threats use T1090.004.
- Spamhaus H1 2026 Botnet Threat Update: Sliver Overtakes Cobalt Strike as Leading C2 Framework, .cn C&C…medium
- HOLLOWGRAPH: .NET NativeAOT Malware Abusing Microsoft Graph API and M365 Calendar Events for C2, Linked to…high
- LabubaRAT: Rust-Based Windows Implant Masquerading as NVIDIA Container Runtimehigh
- Braintree.Net NuGet Typosquat Uses XOR-Obfuscated WebSocket/HTTPS C2 to Exfiltrate Live Payment Card Data…high
- PamStealer: Rust-Based macOS Infostealer Masquerades as Maccy Clipboard Manager, Validates Stolen Passwords…high
- ChocoPoC Campaign: Trojanised PoC Exploits and PyPI Packages Deliver Python RAT Using Mapbox Datasets API as…high
- Grandoreiro Banking Trojan Resurgence (May 2026) — Dual-Vector DLL Side-Loading & VBS Geofenced Campaign…high
- 2026 FIFA World Cup Phishing Campaign — 222 Typosquatting Domains, 203 IPs, 4 Operator Clusters (Flare)high
- PAN-OS User-ID Authentication Portal RCE Zero-Day (CVE-2026-0300) — Active Exploitation on PA-Series &…critical
- Winter Olympics 2026 Domain Impersonation and Phishing Infrastructure Campaignmedium
- BMC FootPrints ITSM Pre-Auth RCE Chain via Auth Bypass + Java Deserialization…critical
- Dohdoor Backdoor — UAT-10027 DNS-over-HTTPS C2 Campaign Targeting US Education & Healthcare via Cloudflare…high
Detection coverage
Threadlinqs maintains 34 detection rules mapped to T1090.004 (SPL 12, KQL 12, Sigma 10). Rule content is available to Blue tier accounts and above; this page shows counts only.
Parent technique
T1090 Proxy — 367 tracked threats at the technique level.