ngrok — Malware Profile
ngrok is a legitimate reverse proxy tool that can create a secure tunnel to servers located behind firewalls or on local machines that do not have a public IP. ngrok has been leveraged by threat actors in several campaigns including use for lateral movement and data exfiltration.
MITRE ATT&CK techniques (5)
- T1090 Proxy
- T1102 Web Service
- T1567 Exfiltration Over Web Service
- T1568.002 Domain Generation Algorithms
- T1572 Protocol Tunneling
IntelFusions coverage
- Microsoft Reveals Andariel's New Dora RAT and Decade-Long Malware Arsenal Targeting Aerospace and Defence 2026-02-16
- Scattered Spider Q2 2025: vCenter Unmanaged VM ntds.dit Dumping, Chisel/Teleport/Pinggy Tunneling, S3 Browser Exfiltration, and Email Transport Rule Hijacking 2026-02-16
- Kimsuky Adds Chrome Remote Desktop to Remote Control Arsenal Alongside AppleSeed, RDP Patcher, and Ngrok 2026-02-16
- Scattered Spider (UNC3944) 2025: Teleport as Novel C2 Persistence on AWS EC2, STONESTOP/POORTRY BYOVD EDR Termination, and DragonForce Ransomware Partnerships 2026-02-16
- Microsoft Exposes Onyx Sleet's Expanding Malware Arsenal Targeting Aerospace and Defense Organizations 2026-02-16
- Korean firms hit by backdoor tied to North Korean hackers 2026-08-06
- Claude Code sessions exposed a Mac app to the internet 2026-08-07
Attributed threat actors
- OilRig
- Ember Bear
- Scattered Spider
- LazyScripter
- Fox Kitten
- DarkSide machine-inferred link
- Akira machine-inferred link
- ALPHV/BlackCat machine-inferred link
- BianLian machine-inferred link
- Karakurt machine-inferred link
- Head Mare machine-inferred link