T1572 Protocol Tunneling — ATT&CK Technique
Adversaries may tunnel network communications to and from a victim system within a separate protocol to avoid detection/network filtering and/or enable access to otherwise unreachable systems. Tunneling involves explicitly encapsulating a protocol within another. This behavior may conceal malicious traffic by blending in with existing traffic and/or provide an outer layer of encryption (similar to a VPN). Tunneling could also enable routing of network packets that would otherwise not reach their intended destination, such as SMB, RDP, or other traffic that would be filtered by network appliances or not routed over the Internet. There are various means to encapsulate a protocol within another protocol. For example, adversaries may perform SSH tunneling (also known as SSH port forwarding), which involves forwarding arbitrary data over an encrypted SSH tunnel. Protocol Tunneling may also be abused by adversaries during Dynamic Resolution. Known as DNS over HTTPS (DoH), queries to resolve C2 infrastructure may be encapsulated within encrypted HTTPS packets. Adversaries may also leverage Protocol Tunneling in conjunction with Proxy and/or Protocol or Service Impersonation to further conceal C2 communications and infrastructure.
Detection coverage (34)
- Tunneling Tool Execution medium
- PUA - 3Proxy Execution high
- Communication To Ngrok Tunneling Service - Linux high
- PUA - Ngrok Execution high
- Potentially Suspicious Usage Of Qemu medium
- Communication To LocaltoNet Tunneling Service Initiated - Linux high
- DNS Query To Devtunnels Domain medium
- Cloudflared Tunnels Related DNS Requests medium
- Network Connection Initiated To DevTunnels Domain medium
- Network Connection Initiated To Cloudflared Tunnels Domains medium
- Network Connection Initiated To BTunnels Domains medium
- Process Initiated Network Connection To Ngrok Domain high
- Communication To LocaltoNet Tunneling Service Initiated high
- Network Connection Initiated To Visual Studio Code Tunnels Domain medium
- Communication To Ngrok Tunneling Service Initiated high
- RDP to HTTP or HTTPS Target Ports high
- RDP Over Reverse SSH Tunnel high
- Silence.EDA Detection critical
- Cloudflared Tunnel Execution medium
- Cloudflared Tunnel Connections Cleanup medium
- Potential RDP Tunneling Via Plink high
- Suspicious Plink Port Forwarding high
- Port Forwarding Activity Via SSH.EXE medium
- Potential RDP Tunneling Via SSH high
- Cisco IOS XE Tunnel Interface Configuration
- Okta Non-Standard VPN Usage
- Linux Ngrok Reverse Proxy Usage
- Windows Ngrok Reverse Proxy Usage
- Windows Potential Cloudflared Network Connection
- Windows Potential Cloudflared Tunnel Execution
- Windows Protocol Tunneling with Plink
- Windows SoftEther VPN Masquerading as Legitimate Binary
- Windows SSH Proxy Command
- Ngrok Reverse Proxy on Network
Malware using this technique
- Neo-reGeorg
- Heyoka Backdoor
- reGeorg
- LunarWeb
- Duqu
- SPAWNCHIMERA
- FunnyDream
- Kevin
- BRICKSTORM
- Industroyer
- FRP
- Brute Ratel C4
- Uroburos
- Milan
- Cobalt Strike
- ngrok
- Mythic
- FLIPSIDE
- HiddenFace
- QakBot
- Cyclops Blink