ngrok is a legitimate tunneling and reverse-proxy utility that exposes local services to the internet, including systems located behind NAT or firewall boundaries, typically over encrypted channels. In intrusion activity, it is frequently abused as a dual-use remote access and traffic-relay tool rather than as malware in its own right. Adversaries have used ngrok to tunnel Remote Desktop Protocol and other command-and-control traffic, establish covert inbound access to compromised hosts, proxy connections to internal systems, and in some cases support data exfiltration over web services. It is commonly deployed after initial compromise as part of post-exploitation tradecraft and may be installed as a service or paired with persistence mechanisms to maintain remote access. Reported use spans ransomware, espionage, and intrusion sets including Iranian-aligned operators, ransomware affiliates, and other threat actors targeting enterprise Windows environments, VMware infrastructure, and occasionally Android malware operations through companion remote-access components. Because ngrok is a legitimate administrative tool with benign uses, malicious context is determined by how it is configured and employed within a compromise rather than by the software itself.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
In this example, the threat actor attempted to download ngrok to a compromised VMware Horizon server.
5 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
This file is a version of Ngrok software that was hidden in the victim’s computer since the attacker hacked it.
The adversary used ngrok to tunnel traffic. They installed that utility immediately after connecting to the system, and set port 3389 (standard RDP port) in the configuration file.
In this example, the threat actor attempted to download ngrok to a compromised VMware Horizon server.
The threat actor uses the additionally installed malware strains and proxy tools, such as Ngrok, to establish a proxy network environment.
...various covert tunneling tools, such as NGROK, RSOCX, and Localtonet.
18 distinct techniques documented for this family, organized by ATT&CK tactic.
The third backdoor is by using a webshell of tmate[.]io... TeamTNT is utilizing this tool as a backdoor. The fourth backdoor is by utilizing a socket connected over HTTP service with Ngrok product.
T1021.001 – Remote Services: Remote Desktop Protocol The adversary utilized Remote Desktop Protocol (RDP) for lateral movement... In many cases, RDP traffic was tunneled using internal proxies. | The adversary also used various methods to steal high-level credentials and moved freely across the network using Remote Desktop Protocol (RDP)
the threat actor also installed a tunneling program called Ngrok to expose systems located within a NAT environment, allowing external access.
T1572 – Protocol Tunneling The adversary employed Ngrok, plink, and SSH to tunnel various protocols (primarily RDP, SMB, and SSH) within web traffic to various VPS infrastructure. | The adversary then began chaining proxy access via plink and Ngrok to traverse the victim’s network segmentation.
11 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
22 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Legitimate tunneling utility abused to proxy RDP traffic into compromised systems and support covert remote access.
A legitimate tunneling utility abused by the threat actor to expose internal systems through encrypted tunnels, enable covert inbound RDP access, support persistence, and mask the true source of lateral movement.
Legitimate tunneling service often abused by threat actors to create outbound tunnels for remote access and C2.
Tunneling utility used to establish remote access during Akira-related compromises.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.