netsh is the Windows network shell utility. In the provided content, it is described as being usable to set up a proxy tunnel that allows remote host access to an infected host. The content also notes its use in conjunction with the command "cmd.exe /c netsh firewall add portopening TCP 443 "adp"" to make a victim machine function as a proxy server. These behaviors indicate use for proxying, tunneling, and enabling remote access/pivoting through compromised Windows systems. No specific threat actor, industry targeting, or additional indicators of compromise beyond the cited command are directly attributed to netsh in the provided content.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 distinct techniques documented for this family, organized by ATT&CK tactic.
"APT41 used a tool called CLASSFON to covertly proxy network communications." / "BADCALL functions as a proxy server between the victim and C2 server." / "Sandworm Team's BCS-server tool can create an internal proxy server to redirect traffic..."
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Windows command-line utility that can be abused to configure networking to enable proxy tunneling/remote access.
Windows command-line utility that can be abused to configure networking to enable proxy tunneling/remote access.
Windows command-line utility that can be abused to configure proxy tunneling/port forwarding.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.