ATT&CKReferencesMalwareBytes Ngrok February 2020

MalwareBytes Ngrok February 2020

Segura, J. (2020, February 26). Fraudsters cloak credit card skimmer with fake content delivery network, ngrok server. Retrieved September 15, 2020.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples3

TechniqueUsed byProcedure example
T1090
Proxy
Toolngrok

ngrok can be used to proxy connections to machines located behind NAT or firewalls.

T1567
Exfiltration Over Web Service
Toolngrok

ngrok has been used by threat actors to configure servers for data exfiltration.

T1572
Protocol Tunneling
Toolngrok

ngrok can tunnel RDP and other services securely over internet connections.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.