ngrok
MITRE ATT&CK: S0508 View on attack.mitre.org
Aliases: ngrok
- Operating systems
- windows
- Last IoC activity
- 2026-07-10 19:39:39
- Profile updated
- 2026-07-07 13:21:18
Context
ngrok is a legitimate reverse proxy tool that can create a secure tunnel to servers located behind firewalls or on local machines that do not have a public IP. ngrok has been leveraged by threat actors in several campaigns including use for lateral movement and data exfiltration.
Detection coverage
- 70 Sigma rules
Malware & tools used
- Proxy (attack-pattern)
- Exfiltration Over Web Service (attack-pattern)
- Domain Generation Algorithms (attack-pattern)
- Web Service (attack-pattern)
- Protocol Tunneling (attack-pattern)
Used by threat actors
- SharePoint ToolShell Exploitation (campaign)
- Iranian APT Credential Harvesting & Cryptomining Activity (campaign)
- Ember Bear (threat-actor)
- Scattered Spider (threat-actor)
- Fox Kitten (threat-actor)
- LazyScripter (threat-actor)
- OilRig (threat-actor)
Related threat objects
- Ngrok (malware)
Reports & references
- web.archive.org — Lazyscripter (report)
- Mandiant — Tactics Techniques Procedures Associated With Maze Ransomware Incidents (report)
- MITRE ATT&CK — S0508 (report)
- cyware.com — Cyber Attackers Leverage Tunneling Service To Drop Lokibot Onto Victims Systems 6F610E44 (report)
- zdnet.com — Sly Malware Author Hides Cryptomining Botnet Behind Ever Shifting Proxy Service (report)