Cimpanu, C. (2018, September 13). Sly malware author hides cryptomining botnet behind ever-shifting proxy service. Retrieved September 15, 2020.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1090 Proxy |
Toolngrok | ngrok can be used to proxy connections to machines located behind NAT or firewalls. |
| T1102 Web Service |
Toolngrok | ngrok has been used by threat actors to proxy C2 connections to ngrok service subdomains. |
| T1568.002 Domain Generation Algorithms |
Toolngrok | ngrok can provide DGA for C2 servers through the use of random URL strings that change every 12 hours. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.