T1090.004: T1090.004
Essential information
- MITRE technique ID
T1090.004- Confidence
- 100/100
- Revoked
- No
- Published
- 16/12/2025 19:38
- Modified
- 20/04/2026 12:51
- Author / Source
- The MITRE Corporation
Aliases
Domain Fronting
Platforms
windows macos linux ESXi
Description
Kill chain phases
| Kill chain | Phase |
|---|---|
| mitre-attack | command-and-control |
Marking (TLP)
TLP:CLEAR Copyright 2015-2025, The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation.
External references
Related entities
Intrusion sets, malware, reports, vulnerabilities, indicators and other entities linked to this technique.
Intrusion sets (APT) (8)
-
The MITRE Corporation Confidence 100
[APT29](https://attack.mitre.org/groups/G0016) is threat group that has been attributed to Russia's Foreign Intelligence Service (SVR).(Citation: White House Imposing Costs RU Gov April 2021)(Citation: UK Gov Malign RIS Activity April …
First seen 01/01/1970 · Last seen 16/11/5138 Published 16/12/2025 19:39 · Modified 04/05/2026 16:33 -
MRxC0DER usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 05:45 · Modified 21/12/2025 05:45
-
TaxOff usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 08:39 · Modified 21/12/2025 08:39
-
Gamaredon usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 20/12/2025 20:11 · Modified 20/12/2025 20:11
-
The MITRE Corporation Confidence 100
[OilRig](https://attack.mitre.org/groups/G0049) is a suspected Iranian threat group that has targeted Middle Eastern and international victims since at least 2014. The group has targeted a variety of sectors, including …
First seen 01/01/1970 · Last seen 16/11/5138 Published 16/12/2025 19:39 · Modified 27/03/2026 01:13 -
The MITRE Corporation Confidence 100
[Sea Turtle](https://attack.mitre.org/groups/G1041) is a Türkiye-linked threat actor active since at least 2017 performing espionage and service provider compromise operations against victims in Asia, Europe, and North America. [Sea …
First seen 01/01/1970 · Last seen 16/11/5138 Published 16/12/2025 19:39 · Modified 27/03/2026 01:14 -
Earth Longzhi usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 20/12/2025 22:53 · Modified 20/12/2025 22:53
-
The MITRE Corporation Confidence 100
[APT41](https://attack.mitre.org/groups/G0096) is a threat group that researchers have assessed as Chinese state-sponsored espionage group that also conducts financially-motivated operations. Active since at least 2012, [APT41](https://attack.mitre.org/groups/G0096) has been observed …
First seen 01/01/1970 · Last seen 16/11/5138 Published 16/12/2025 19:39 · Modified 27/03/2026 01:14
Malware (18)
-
GammaSteel usesFamilyPublished 08/06/2026 10:30 · Modified 08/06/2026 10:30
-
Veaty usesFamilyPublished 12/09/2024 08:21 · Modified 12/09/2024 08:21
-
GammaWorm usesFamilyPublished 04/06/2026 13:57 · Modified 04/06/2026 13:57
- ScrambleCross
-
Caffeine usesFamilyPublished 02/07/2024 15:45 · Modified 02/07/2024 15:45
-
StealthVector usesFamilyPublished 09/08/2024 20:15 · Modified 09/08/2024 20:15
-
GammaWipe usesFamilyPublished 04/06/2026 13:57 · Modified 04/06/2026 13:57
- StealthMutant
-
Trinper usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 08:39 · Modified 21/12/2025 08:39
-
Cobalt Strike usesFamilyPublished 16/12/2024 14:25 · Modified 16/12/2024 14:25
- procburner
-
GammaPhish usesFamilyPublished 04/06/2026 13:57 · Modified 04/06/2026 13:57
- avburner
-
GammaLoad usesFamilyPublished 04/06/2026 13:57 · Modified 04/06/2026 13:57
- SMOKEDHAM
-
Spearal usesFamilyPublished 12/09/2024 08:21 · Modified 12/09/2024 08:21
-
CacheHttp usesFamilyPublished 12/09/2024 08:21 · Modified 12/09/2024 08:21
-
AlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 20/12/2025 19:39 · Modified 27/05/2026 21:40
Reports (7)
-
19 MITREs 5 Malwares 1 Observable 1 APTPublished 03/06/2026 13:18 · Modified 04/06/2026 08:40
-
Threat landscape — Belgium relatedConfidence 100 18 CVEs 200 MITREs 200 Malwares 20 APTs 26 ToolsPublished 29/05/2026 11:51 · threat-report
-
4 MITREsPublished 20/04/2026 13:20 · Modified 20/04/2026 13:53
-
19 MITREs 4 ObservablesPublished 18/04/2026 13:40 · Modified 20/04/2026 10:51
-
TaxOff: You've Got a Backdoor... related14 MITREs 1 Malware 11 Observables 1 APTPublished 03/12/2024 16:26 · Modified 03/12/2024 16:50
-
11 MITREs 3 Malwares 16 Observables 1 APTPublished 12/09/2024 08:21 · Modified 12/09/2024 08:24
-
9 MITREs 1 Malware 25 Observables 1 APTPublished 02/07/2024 15:45 · Modified 02/07/2024 15:51
Vulnerabilities (CVE) (2)
The driver in Micro-Star MSI Afterburner 4.6.2.15658 (aka RTCore64.sys and RTCore32.sys) allows any authenticated user to read and write to arbitrary memory, …
- Attack vector
- LOCAL
- Published
- 11/09/2019
- Modified
- 20/12/2025
Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution. This vulnerability is part of the ProxyLogon exploit chain.
- Published
- 03/11/2021
- Modified
- 20/12/2025
Attack patterns (MITRE) (1)
-
T1090 subtechnique-ofProxy
Tool (2)
-
Mythic usesThe MITRE Corporation Confidence 100
[Mythic](https://attack.mitre.org/software/S0699) is an open source, cross-platform post-exploitation/command and control platform. [Mythic](https://attack.mitre.org/software/S0699) is designed to "plug-n-play" with various agents and communication channels.(Citation: Mythic Github)(Citation: Mythic SpecterOps)(Citation: Mythc Documentation) Deployed …
Published 26/03/2022 02:38 · Modified 27/03/2026 01:07 -
meek usesThe MITRE Corporation Confidence 100
[meek](https://attack.mitre.org/software/S0175) is an open-source Tor plugin that tunnels Tor traffic through HTTPS connections.
Published 16/01/2018 17:13 · Modified 27/03/2026 01:07
Course Of Action (1)
- SSL/TLS Inspection mitigates