# T1090 Proxy

> As of 2026-10-05, T1090 (Proxy) appears in 367 tracked threats, first reported 2026-01-25 and most recently 2026-10-04, with linked actors including The Gentlemen, TeamPCP, APT28; it most often appears alongside T1027 (Obfuscated Files or Information).

- **Tracked threats:** 367 (115 critical, 219 high, 31 medium)
- **First seen:** 2026-01-25
- **Last seen:** 2026-10-04
- **Threat actors:** 133
- **Detection rules:** 339 (counts only; Blue tier and above)

## Key facts

- **ID:** T1090
- **Framework:** MITRE ATT&CK
- **Tactics:** Command and Control
- **Matrix:** Enterprise
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1090/

## Activity timeline

T1090 first appeared in tracked threats on 2026-01-25 and was most recently reported on 2026-10-04. The busiest month was 2026-07 with 154 reports, and 367 of the 367 threats were reported in the twelve months to 2026-10.

## How adversaries use it

T1090 Proxy is catalogued by MITRE ATT&CK under the Command and Control tactic in the Enterprise matrix. Threadlinqs maps 367 of 2623 tracked threats (14%) to it; by severity that is 115 critical, 219 high, 31 medium.

Threats that use T1090 most often also use [T1027 Obfuscated Files or Information](https://intel.threadlinqs.com/technique/T1027) (227 threats), [T1059 Command and Scripting Interpreter](https://intel.threadlinqs.com/technique/T1059) (221 threats), [T1071 Application Layer Protocol](https://intel.threadlinqs.com/technique/T1071) (209 threats), [T1005 Data from Local System](https://intel.threadlinqs.com/technique/T1005) (200 threats), [T1082 System Information Discovery](https://intel.threadlinqs.com/technique/T1082) (200 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

133 tracked threat actors appear in the threats that use T1090; the most frequent are [The Gentlemen](https://intel.threadlinqs.com/actor/The%20Gentlemen) (7), [TeamPCP](https://intel.threadlinqs.com/actor/TeamPCP) (6), [APT28](https://intel.threadlinqs.com/actor/APT28) (5), [APT38](https://intel.threadlinqs.com/actor/APT38) (5), [APT43](https://intel.threadlinqs.com/actor/APT43) (5).

## Mitigations

MITRE ATT&CK lists 3 mitigations for T1090.

- [M1020 SSL/TLS Inspection](https://attack.mitre.org/mitigations/M1020/)
- [M1031 Network Intrusion Prevention](https://attack.mitre.org/mitigations/M1031/)
- [M1037 Filter Network Traffic](https://attack.mitre.org/mitigations/M1037/)

## Data sources

Telemetry that can reveal T1090, per MITRE ATT&CK.

- Network Traffic — Network Connection Creation, Network Traffic Content, Network Traffic Flow

## Threat actors using it

- [The Gentlemen](https://intel.threadlinqs.com/actor/The%20Gentlemen) — 7
- [TeamPCP](https://intel.threadlinqs.com/actor/TeamPCP) — 6
- [APT28](https://intel.threadlinqs.com/actor/APT28) — 5
- [APT38](https://intel.threadlinqs.com/actor/APT38) — 5
- [APT43](https://intel.threadlinqs.com/actor/APT43) — 5
- [Kimsuky](https://intel.threadlinqs.com/actor/Kimsuky) — 5
- [MuddyWater](https://intel.threadlinqs.com/actor/MuddyWater) — 5
- [Mustang Panda](https://intel.threadlinqs.com/actor/Mustang%20Panda) — 5
- [Turla](https://intel.threadlinqs.com/actor/Turla) — 5
- [Lazarus Group](https://intel.threadlinqs.com/actor/Lazarus%20Group) — 4
- [Scattered Spider](https://intel.threadlinqs.com/actor/Scattered%20Spider) — 4
- [Static Tundra](https://intel.threadlinqs.com/actor/Static%20Tundra) — 4

## Tracked threats

The 30 most recent of 367 tracked threats that use T1090.

- [China-Aligned TA419 Targets U.S. AI Policy Experts With Microsoft AitM Phishing (Frameless BitB)](https://intel.threadlinqs.com/threat/TL-2026-2884) — high — 2026-10-04
- [BPFDoor, Rekoobe and AVERAT Linux Implants Impersonate SpamSniper and ShareTech Mail Security Appliances…](https://intel.threadlinqs.com/threat/TL-2026-2875) — high — 2026-10-03
- [Rejetto HTTP File Server (HFS) 3.x session forgery via predictable Math.random() signing key leads to…](https://intel.threadlinqs.com/threat/TL-2026-2865) — critical — 2026-10-03
- [Cling IoT botnet masquerades as Google STUN traffic for C2, exploiting Realtek Jungle SDK CVE-2021-35394](https://intel.threadlinqs.com/threat/TL-2026-2857) — high — 2026-10-03
- [ScreenConnect Client Abused by Attackers via Mejuri-Themed Payment Receipt Phishing](https://intel.threadlinqs.com/threat/TL-2026-2826) — medium — 2026-10-01
- [Multi-Platform Data Exfiltration Across AWS and GitHub via Stolen GitHub Token and Hardcoded AWS Credentials…](https://intel.threadlinqs.com/threat/TL-2026-2772) — critical — 2026-09-29
- [Infostealers Target Corporate AI Accounts, Sessions and API Keys (LLMjacking Risk)](https://intel.threadlinqs.com/threat/TL-2026-2752) — high — 2026-09-28
- [Citrix Patches Two Actively Exploited NetScaler Zero-Days (CVE-2026-88771, CVE-2026-88772)](https://intel.threadlinqs.com/threat/TL-2026-2703) — critical — 2026-09-27
- [Two Unpatched Citrix NetScaler Zero-Day RCE Vulnerabilities Under Active Exploitation](https://intel.threadlinqs.com/threat/TL-2026-2693) — critical — 2026-09-27
- [CISA Adds Four Actively Exploited KEVs: Check Point Gateway/Management RCE Flaws, Arista VeloCloud…](https://intel.threadlinqs.com/threat/TL-2026-2678) — critical — 2026-09-26
- [CISA Adds Two Actively Exploited KEVs: SharePoint Code Injection (CVE-2026-65660) and Mikrotik RouterOS Auth…](https://intel.threadlinqs.com/threat/TL-2026-2669) — critical — 2026-09-26
- [Eclypsium InfraTrust Report: Mass Active Exploitation of Network Management Systems (Cisco FMC/ISE…](https://intel.threadlinqs.com/threat/TL-2026-2630) — critical — 2026-09-23
- [Vexy Ransomware Claims Quy Nhon University (Vietnam) — New Group, 50GB Exfiltrated](https://intel.threadlinqs.com/threat/TL-2026-2598) — high — 2026-09-21
- [AI-Driven Exploit Chain Against OpenAI Community Forum via libheif Flaw (CVE-2026-32882)](https://intel.threadlinqs.com/threat/TL-2026-2558) — high — 2026-09-18
- [Team Cymru Infrastructure Analysis: Seven Active Ransomware Gangs (Akira, DragonForce, Clop, MedusaLocker…](https://intel.threadlinqs.com/threat/TL-2026-2517) — high — 2026-09-15
- [ScreenConnect Backdoor Delivered via SSA-Impersonation Phishing Lure](https://intel.threadlinqs.com/threat/TL-2026-2594) — medium — 2026-09-14
- [CISA Adds Actively Exploited Cisco Secure Email Gateway SQL Injection (CVE-2026-76461) to KEV Catalog](https://intel.threadlinqs.com/threat/TL-2026-2508) — critical — 2026-09-14
- [Blockchain-Based C2 Evolution: Nation-State Actors Adopt Smart-Contract C2 (EtherHiding…](https://intel.threadlinqs.com/threat/TL-2026-2484) — high — 2026-09-13
- [Dutch NCSC Warns of Critical Check Point VPN Flaws (CVE-2026-85102, CVE-2026-85103) — Exploitation Expected…](https://intel.threadlinqs.com/threat/TL-2026-2463) — critical — 2026-09-12
- [SloppyRAT: New Remote Access Trojan Deployed via ClickFix in Ransomware-Linked Attacks](https://intel.threadlinqs.com/threat/TL-2026-2439) — high — 2026-09-10
- [CVE-2025-25249: Fortinet Heap-Based Buffer Overflow Exploited to Deploy PivotC2 RAT on FortiGate Devices](https://intel.threadlinqs.com/threat/TL-2026-2431) — critical — 2026-09-10
- [BloodAlchemy RAT Traced to Deed RAT/ShadowPad Lineage via VPN Account Compromise and DLL Side-Loading](https://intel.threadlinqs.com/threat/TL-2026-2426) — high — 2026-09-10
- [Ivanti September 2026 Patch Batch: 10 CVEs Across EPMM, Neurons for ITSM, and Sentry (CVE-2026-12744/12745…](https://intel.threadlinqs.com/threat/TL-2026-2396) — critical — 2026-09-08
- [REVSTEALER (REF2859): Emerging Windows infostealer with App-Bound encryption bypass, Polygon blockchain C2…](https://intel.threadlinqs.com/threat/TL-2026-2370) — high — 2026-09-07
- [Vexy Ransomware hits Mega Velocity — 46.68 GB exfiltrated, double extortion](https://intel.threadlinqs.com/threat/TL-2026-2363) — high — 2026-09-06
- [Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication (MikroTrick)](https://intel.threadlinqs.com/threat/TL-2026-2345) — critical — 2026-09-06
- [Chinese-Speaking Operator "Nie" Uses SecFlow AI Orchestration Framework (Claude, Qwen, DeepSeek) and GLUTTON…](https://intel.threadlinqs.com/threat/TL-2026-2325) — high — 2026-09-04
- [Attacks in Korea Deploy Radmin and UltraVNC for Remote Control, Followed by Proxy/VPN Tools for…](https://intel.threadlinqs.com/threat/TL-2026-2323) — high — 2026-09-03
- ["Phantom Deal": Fake M&A Business Email/WhatsApp Compromise Scam Targets Large Enterprises with Forged NDAs](https://intel.threadlinqs.com/threat/TL-2026-2322) — high — 2026-09-03
- [REVSTEALER Infostealer Campaign: Four C2-Delivered Modules Disable Windows Update & Defender to Deploy XMRig…](https://intel.threadlinqs.com/threat/TL-2026-2353) — high — 2026-09-02

## Related CVEs

CVEs referenced by the tracked threats that use T1090, most frequent first.

- [CVE-2026-15409](https://intel.threadlinqs.com/cve/CVE-2026-15409)
- [CVE-2026-15410](https://intel.threadlinqs.com/cve/CVE-2026-15410)
- [CVE-2018-0171](https://intel.threadlinqs.com/cve/CVE-2018-0171)
- [CVE-2024-55591](https://intel.threadlinqs.com/cve/CVE-2024-55591)
- [CVE-2025-55182](https://intel.threadlinqs.com/cve/CVE-2025-55182)
- [CVE-2014-8361](https://intel.threadlinqs.com/cve/CVE-2014-8361)
- [CVE-2025-5777](https://intel.threadlinqs.com/cve/CVE-2025-5777)
- [CVE-2008-4128](https://intel.threadlinqs.com/cve/CVE-2008-4128)
- [CVE-2017-17215](https://intel.threadlinqs.com/cve/CVE-2017-17215)
- [CVE-2018-10561](https://intel.threadlinqs.com/cve/CVE-2018-10561)
- [CVE-2021-26855](https://intel.threadlinqs.com/cve/CVE-2021-26855)
- [CVE-2021-4034](https://intel.threadlinqs.com/cve/CVE-2021-4034)
- [CVE-2023-27997](https://intel.threadlinqs.com/cve/CVE-2023-27997)
- [CVE-2025-49113](https://intel.threadlinqs.com/cve/CVE-2025-49113)
- [CVE-2025-8088](https://intel.threadlinqs.com/cve/CVE-2025-8088)
- [CVE-2026-85102](https://intel.threadlinqs.com/cve/CVE-2026-85102)
- [CVE-2018-10562](https://intel.threadlinqs.com/cve/CVE-2018-10562)
- [CVE-2019-19781](https://intel.threadlinqs.com/cve/CVE-2019-19781)
- [CVE-2020-12641](https://intel.threadlinqs.com/cve/CVE-2020-12641)
- [CVE-2020-35730](https://intel.threadlinqs.com/cve/CVE-2020-35730)
- [CVE-2021-22681](https://intel.threadlinqs.com/cve/CVE-2021-22681)
- [CVE-2021-26857](https://intel.threadlinqs.com/cve/CVE-2021-26857)
- [CVE-2021-26858](https://intel.threadlinqs.com/cve/CVE-2021-26858)
- [CVE-2021-27065](https://intel.threadlinqs.com/cve/CVE-2021-27065)
- [CVE-2021-31207](https://intel.threadlinqs.com/cve/CVE-2021-31207)
- [CVE-2021-34473](https://intel.threadlinqs.com/cve/CVE-2021-34473)
- [CVE-2021-34523](https://intel.threadlinqs.com/cve/CVE-2021-34523)
- [CVE-2021-34527](https://intel.threadlinqs.com/cve/CVE-2021-34527)
- [CVE-2021-44026](https://intel.threadlinqs.com/cve/CVE-2021-44026)
- [CVE-2021-44228](https://intel.threadlinqs.com/cve/CVE-2021-44228)

## Detection coverage

Threadlinqs maintains 339 detection rules mapped to T1090 (SPL 117, KQL 99, Sigma 122, other 1). Rule content is available to Blue tier accounts and above; this page shows counts only.

339 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Sub-techniques

- [T1090.001 Internal Proxy](https://intel.threadlinqs.com/technique/T1090.001) — 41 tracked threats
- [T1090.002 External Proxy](https://intel.threadlinqs.com/technique/T1090.002) — 86 tracked threats
- [T1090.003 Multi-hop Proxy](https://intel.threadlinqs.com/technique/T1090.003) — 68 tracked threats
- [T1090.004 Domain Fronting](https://intel.threadlinqs.com/technique/T1090.004) — 12 tracked threats

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1090
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
