Names | Ngrok | |
Category | Tools | |
Type | Backdoor, Tunneling | |
Description | ngrok exposes local servers behind NATs and firewalls to the public internet over secure tunnels. | |
Information | <https://ngrok.com/product> <https://cyware.com/news/cyber-attackers-leverage-tunneling-service-to-drop-lokibot-onto-victims-systems-6f610e44> <https://www.fireeye.com/blog/threat-research/2020/05/tactics-techniques-procedures-associated-with-maze-ransomware-incidents.html> <https://www.malwarebytes.com/resources/files/2021/02/lazyscripter.pdf> <https://www.zdnet.com/article/sly-malware-author-hides-cryptomining-botnet-behind-ever-shifting-proxy-service/> | |
MITRE ATT&CK | <https://attack.mitre.org/software/S0508/> |
Last change to this tool card: 30 December 2022
Download this tool card in JSON format
Changed | Name | Country | Observed | ||
APT groups | |||||
↳ Subgroup: Scattered Spider | [Unknown] | 2022-Jul 2024 | |||
OPERA1ER | [Unknown] | 2016-Jul 2023 | |||
Parisite, Fox Kitten, Pioneer Kitten | 2017-Nov 2020 | ||||
ToddyCat | 2020-2021 |
4 groups listed (4 APT, 0 other, 0 unknown)
Digital Service Security Center Follow us on |
Report incidents |
|
+66 (0)2-123-1227 | ||
[email protected] |