ngrok

MITRE ATT&CK: S0508 View on attack.mitre.org

Aliases: ngrok

Operating systems
windows
Last IoC activity
2026-07-10 19:39:39
Profile updated
2026-07-07 13:21:18

Context

ngrok is a legitimate reverse proxy tool that can create a secure tunnel to servers located behind firewalls or on local machines that do not have a public IP. ngrok has been leveraged by threat actors in several campaigns including use for lateral movement and data exfiltration.

Detection coverage

  • 70 Sigma rules

Malware & tools used

  • Proxy (attack-pattern)
  • Exfiltration Over Web Service (attack-pattern)
  • Domain Generation Algorithms (attack-pattern)
  • Web Service (attack-pattern)
  • Protocol Tunneling (attack-pattern)

Used by threat actors

Related threat objects

Reports & references

  • web.archive.org — Lazyscripter (report)
  • Mandiant — Tactics Techniques Procedures Associated With Maze Ransomware Incidents (report)
  • MITRE ATT&CK — S0508 (report)
  • cyware.com — Cyber Attackers Leverage Tunneling Service To Drop Lokibot Onto Victims Systems 6F610E44 (report)
  • zdnet.com — Sly Malware Author Hides Cryptomining Botnet Behind Ever Shifting Proxy Service (report)

External references