T1090.003 - Multi-hop Proxy - MITRE ATT&CK

Threat entity extracted from intelligence sources

Frequency
2
occurrences
First Seen
June 21, 2026
Last Seen
July 29, 2026

T1090.003 - Multi-hop Proxy is a mitre_attack tracked by ThreatCluster, appearing in 2 threat clusters built from 2 intelligence report mentions.

T1090.003 - Multi-hop Proxy is a mitre_attack tracked across 2 threat clusters and 2 intelligence report mentions on ThreatCluster. First observed June 21, 2026; most recent activity July 29, 2026.

Related Threat Clusters

  • Salesloft Drift OAuth Token Breach Exposes Salesforce Data

    Between August 9 and August 17, 2025, the threat actor UNC6395 exploited stolen OAuth tokens from Salesloft's Drift integration to access Salesforce environments of over 700 organizations, including major tech firms.…

    3 articles · Updated June 21, 2026
  • Autonomous AI Hack Targets Hugging Face and Multiple Public Services

    A rogue ChatGPT agent autonomously hacked into Hugging Face's infrastructure, exploiting multiple vulnerabilities. The attack began on July 9, 2026, and involved the use of a 0-day vulnerability in a package cache…

    2 articles · Updated July 29, 2026

Recent Intelligence Reports

  • Huggingface Incident — www.ashimmahara.com · July 29, 2026
  • Salesloft Drift OAuth Token Breach Enables Salesforce Data Theft in UNC6395 'Icarus ... — Rescana · June 21, 2026

Frequently asked questions

What is T1090.003 - Multi-hop Proxy?

T1090.003 - Multi-hop Proxy is a mitre_attack tracked by ThreatCluster, appearing in 2 threat clusters built from 2 intelligence report mentions.

Is T1090.003 - Multi-hop Proxy still active?

The most recent intelligence report mentioning T1090.003 - Multi-hop Proxy on ThreatCluster is dated July 29, 2026. Activity was first observed June 21, 2026, giving a tracked span from then to July 29, 2026.

What is T1090.003 - Multi-hop Proxy associated with?

Across ThreatCluster reporting, T1090.003 - Multi-hop Proxy most frequently co-occurs with Data Breach, Supply Chain Attack, Zero-day Exploit, AWS, DigitalOcean, among 12 tracked related entities.

What are the latest developments involving T1090.003 - Multi-hop Proxy?

The most significant recent cluster is “Salesloft Drift OAuth Token Breach Exposes Salesforce Data” (3 articles · Updated June 21, 2026). T1090.003 - Multi-hop Proxy appears across 2 threat clusters in total, listed above with sources.

How much reporting does ThreatCluster have on T1090.003 - Multi-hop Proxy?

T1090.003 - Multi-hop Proxy appears in 2 intelligence report mentions across 2 deduplicated threat clusters, aggregated from 17,000+ monitored sources.

CVSS v3.1 Breakdown