ngrok is a legitimate tunneling and reverse-proxy utility frequently abused by threat actors; it is not inherently malware. It exposes local services through public endpoints that relay traffic through ngrok infrastructure, allowing access to systems behind NAT or inbound firewall restrictions. Attackers use its encrypted tunnels to proxy command-and-control communications, expose RDP and VNC services, bypass network controls, and support data exfiltration. Remote command execution and graphical control are provided by the services or malware carried through the tunnels, rather than by ngrok itself.
In Windows intrusions, attackers commonly deploy ngrok after gaining access, configure it to tunnel RDP through outbound HTTPS connections, and register it through services to maintain access. Deployment across multiple hosts provides redundant access when individual systems reboot or become unavailable. Observed use includes Scattered Spider, Twelve, Akira operators, Kimsuky, TunnelVision, and Iranian government-sponsored activity against a U.S. federal civilian agency following exploitation of Log4Shell in VMware Horizon. These deployments span government and commercial environments and are not specific to one industry or threat actor. ngrok has also been used alongside the Loki backdoor to reach private network segments and with AlphaVNC in the Android banking malware Vultur to enable remote access to infected devices.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
In this example, the threat actor attempted to download ngrok to a compromised VMware Horizon server.
5 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The notorious cybercrime group “Scattered Spider” has used ngrok to establish persistent access in many intrusions, including an incident observed by ReliaQuest in November 2023.
This file is a version of Ngrok software that was hidden in the victim’s computer since the attacker hacked it.
The adversary used ngrok to tunnel traffic. They installed that utility immediately after connecting to the system, and set port 3389 (standard RDP port) in the configuration file.
In this example, the threat actor attempted to download ngrok to a compromised VMware Horizon server.
The threat actor uses the additionally installed malware strains and proxy tools, such as Ngrok, to establish a proxy network environment.
17 distinct techniques documented for this family, organized by ATT&CK tactic.
The third backdoor is by using a webshell of tmate[.]io... TeamTNT is utilizing this tool as a backdoor. The fourth backdoor is by utilizing a socket connected over HTTP service with Ngrok product.
The actors used Ngrok to proxy RDP connections and to perform command and control.
ngrok and Cloudflared.exe expose RDP services or establish persistent outbound tunnels.
the threat actor also installed a tunneling program called Ngrok to expose systems located within a NAT environment, allowing external access.
11 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
24 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Legitimate tunneling utility abused to proxy RDP traffic into compromised systems and support covert remote access.
A legitimate tunneling utility abused by the threat actor to expose internal systems through encrypted tunnels, enable covert inbound RDP access, support persistence, and mask the true source of lateral movement.
Legitimate tunneling service often abused by threat actors to create outbound tunnels for remote access and C2.
Tunneling utility used to establish remote access during Akira-related compromises.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.