ngrok

S0508

Tool.View on attack.mitre.org

About this tool

ngrok is a legitimate reverse proxy tool that can create a secure tunnel to servers located behind firewalls or on local machines that do not have a public IP. ngrok has been leveraged by threat actors in several campaigns including use for lateral movement and data exfiltration.

Techniques used5

Procedure examples5

TechniqueProcedure example
T1090
Proxy

ngrok can be used to proxy connections to machines located behind NAT or firewalls.

T1102
Web Service

ngrok has been used by threat actors to proxy C2 connections to ngrok service subdomains.

T1567
Exfiltration Over Web Service

ngrok has been used by threat actors to configure servers for data exfiltration.

T1568.002
Domain Generation Algorithms

ngrok can provide DGA for C2 servers through the use of random URL strings that change every 12 hours.

T1572
Protocol Tunneling

ngrok can tunnel RDP and other services securely over internet connections.

Groups that use it5

Campaigns1

References4

  1. Cyware Ngrok May 2019 Open source
    Cyware. (2019, May 29). Cyber attackers leverage tunneling service to drop Lokibot onto victims’ systems. Retrieved September 15, 2020.
  2. FireEye Maze May 2020 Open source
    Kennelly, J., Goody, K., Shilko, J. (2020, May 7). Navigating the MAZE: Tactics, Techniques and Procedures Associated With MAZE Ransomware Incidents. Retrieved May 18, 2020.
  3. MalwareBytes LazyScripter Feb 2021 Open source
    Jazi, H. (2021, February). LazyScripter: From Empire to double RAT. Retrieved November 17, 2024.
  4. Zdnet Ngrok September 2018 Open source
    Cimpanu, C. (2018, September 13). Sly malware author hides cryptomining botnet behind ever-shifting proxy service. Retrieved September 15, 2020.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.