ATT&CKReferencesZdnet Ngrok September 2018

Zdnet Ngrok September 2018

Cimpanu, C. (2018, September 13). Sly malware author hides cryptomining botnet behind ever-shifting proxy service. Retrieved September 15, 2020.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples3

TechniqueUsed byProcedure example
T1090
Proxy
Toolngrok

ngrok can be used to proxy connections to machines located behind NAT or firewalls.

T1102
Web Service
Toolngrok

ngrok has been used by threat actors to proxy C2 connections to ngrok service subdomains.

T1568.002
Domain Generation Algorithms
Toolngrok

ngrok can provide DGA for C2 servers through the use of random URL strings that change every 12 hours.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.