# T1090.004 Domain Fronting

> As of 2026-10-05, T1090.004 (Domain Fronting) appears in 12 tracked threats, first reported 2026-02-26 and most recently 2026-09-12, with linked actors including Cavern Manticore, Grandoreiro operators; it most often appears alongside T1027 (Obfuscated Files or Information).

- **Tracked threats:** 12 (2 critical, 8 high, 2 medium)
- **First seen:** 2026-02-26
- **Last seen:** 2026-09-12
- **Threat actors:** 2
- **Detection rules:** 34 (counts only; Blue tier and above)

## Key facts

- **ID:** T1090.004
- **Framework:** MITRE ATT&CK
- **Tactics:** Command and Control
- **Matrix:** Enterprise
- **Parent:** T1090
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1090/004/

## Activity timeline

T1090.004 first appeared in tracked threats on 2026-02-26 and was most recently reported on 2026-09-12. The busiest month was 2026-07 with 5 reports, and 12 of the 12 threats were reported in the twelve months to 2026-09.

## How adversaries use it

T1090.004 Domain Fronting is catalogued by MITRE ATT&CK under the Command and Control tactic in the Enterprise matrix, as a sub-technique of [T1090 Proxy](https://intel.threadlinqs.com/technique/T1090). Threadlinqs maps 12 of 2623 tracked threats (0.5%) to it; by severity that is 2 critical, 8 high, 2 medium.

Threats that use T1090.004 most often also use [T1027 Obfuscated Files or Information](https://intel.threadlinqs.com/technique/T1027) (10 threats), [T1071.001 Web Protocols](https://intel.threadlinqs.com/technique/T1071.001) (10 threats), [T1041 Exfiltration Over C2 Channel](https://intel.threadlinqs.com/technique/T1041) (8 threats), [T1005 Data from Local System](https://intel.threadlinqs.com/technique/T1005) (7 threats), [T1036.005 Match Legitimate Resource Name or Location](https://intel.threadlinqs.com/technique/T1036.005) (7 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

2 tracked threat actors appear in the threats that use T1090.004; the most frequent are [Cavern Manticore](https://intel.threadlinqs.com/actor/Cavern%20Manticore) (1), [Grandoreiro operators](https://intel.threadlinqs.com/actor/Grandoreiro%20operators) (1).

## Mitigations

MITRE ATT&CK lists 1 mitigation for T1090.004.

- [M1020 SSL/TLS Inspection](https://attack.mitre.org/mitigations/M1020/)

## Data sources

Telemetry that can reveal T1090.004, per MITRE ATT&CK.

- Network Traffic — Network Traffic Content

## Threat actors using it

- [Cavern Manticore](https://intel.threadlinqs.com/actor/Cavern%20Manticore) — 1
- [Grandoreiro operators](https://intel.threadlinqs.com/actor/Grandoreiro%20operators) — 1

## Tracked threats

12 tracked threats use T1090.004.

- [Spamhaus H1 2026 Botnet Threat Update: Sliver Overtakes Cobalt Strike as Leading C2 Framework, .cn C&C…](https://intel.threadlinqs.com/threat/TL-2026-2469) — medium — 2026-09-12
- [HOLLOWGRAPH: .NET NativeAOT Malware Abusing Microsoft Graph API and M365 Calendar Events for C2, Linked to…](https://intel.threadlinqs.com/threat/TL-2026-1553) — high — 2026-07-20
- [LabubaRAT: Rust-Based Windows Implant Masquerading as NVIDIA Container Runtime](https://intel.threadlinqs.com/threat/TL-2026-1367) — high — 2026-07-15
- [Braintree.Net NuGet Typosquat Uses XOR-Obfuscated WebSocket/HTTPS C2 to Exfiltrate Live Payment Card Data…](https://intel.threadlinqs.com/threat/TL-2026-1165) — high — 2026-07-10
- [PamStealer: Rust-Based macOS Infostealer Masquerades as Maccy Clipboard Manager, Validates Stolen Passwords…](https://intel.threadlinqs.com/threat/TL-2026-1104) — high — 2026-07-05
- [ChocoPoC Campaign: Trojanised PoC Exploits and PyPI Packages Deliver Python RAT Using Mapbox Datasets API as…](https://intel.threadlinqs.com/threat/TL-2026-1088) — high — 2026-07-02
- [Grandoreiro Banking Trojan Resurgence (May 2026) — Dual-Vector DLL Side-Loading & VBS Geofenced Campaign…](https://intel.threadlinqs.com/threat/TL-2026-0609) — high — 2026-05-27
- [2026 FIFA World Cup Phishing Campaign — 222 Typosquatting Domains, 203 IPs, 4 Operator Clusters (Flare)](https://intel.threadlinqs.com/threat/TL-2026-0569) — high — 2026-05-22
- [PAN-OS User-ID Authentication Portal RCE Zero-Day (CVE-2026-0300) — Active Exploitation on PA-Series &…](https://intel.threadlinqs.com/threat/TL-2026-0465) — critical — 2026-05-06
- [Winter Olympics 2026 Domain Impersonation and Phishing Infrastructure Campaign](https://intel.threadlinqs.com/threat/TL-2026-1523) — medium — 2026-03-31
- [BMC FootPrints ITSM Pre-Auth RCE Chain via Auth Bypass + Java Deserialization…](https://intel.threadlinqs.com/threat/TL-2026-1516) — critical — 2026-03-18
- [Dohdoor Backdoor — UAT-10027 DNS-over-HTTPS C2 Campaign Targeting US Education & Healthcare via Cloudflare…](https://intel.threadlinqs.com/threat/TL-2026-0149) — high — 2026-02-26

## Related CVEs

CVEs referenced by the tracked threats that use T1090.004, most frequent first.

- [CVE-2025-55182](https://intel.threadlinqs.com/cve/CVE-2025-55182)
- [CVE-2025-64446](https://intel.threadlinqs.com/cve/CVE-2025-64446)
- [CVE-2026-0257](https://intel.threadlinqs.com/cve/CVE-2026-0257)
- [CVE-2026-0300](https://intel.threadlinqs.com/cve/CVE-2026-0300)
- [CVE-2026-10520](https://intel.threadlinqs.com/cve/CVE-2026-10520)

## Detection coverage

Threadlinqs maintains 34 detection rules mapped to T1090.004 (SPL 12, KQL 12, Sigma 10). Rule content is available to Blue tier accounts and above; this page shows counts only.

34 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Parent technique

[T1090 Proxy](https://intel.threadlinqs.com/technique/T1090) — 367 tracked threats at the technique level.

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1090.004
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
