Chisel is an open-source, Go-based network tunneling utility used legitimately for remote connectivity and abused by threat actors for post-exploitation access and lateral pivoting. It supports encrypted tunneling, TCP/UDP forwarding, and reverse SOCKS proxies, carrying traffic over HTTP to connect attacker-controlled infrastructure with services inside compromised networks. Its malicious use is not specific to a single malware family or threat actor.
Attackers deploy Chisel after obtaining access through exploited internet-facing applications, compromised security appliances, web shells, or other implants. Reverse SOCKS tunnels enable operators to reach internal systems and support subsequent lateral movement using separate tools. Chisel has been deployed on Windows and Linux hosts and compromised Cisco email-security appliances. Operators have renamed its executables to resemble legitimate applications, and customized DLL builds have concealed configuration strings with runtime decryption.
Chisel has been used in PYSA and Lorenz ransomware intrusions, exploitation of ManageEngine and Microsoft Exchange vulnerabilities, and the Chinese UAT-9686 campaign against Cisco AsyncOS devices. In the Iranian state-aligned CL-STA-1178 campaign targeting Iraqi critical infrastructure, the distinct Blackwood wrapper decrypted and reflectively loaded a Chisel DLL into memory to establish encrypted reverse SOCKS connectivity. These deployments demonstrate Chisel's role as a reusable tunneling component rather than a credential stealer, ransomware payload, or independently attributed implant.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Wave 3: Chisel SOCKS5 tunnel deployed (bash history confirms).
On December 17th, 2025, Cisco published an advisory regarding a zero-day Remote Code Execution (RCE) vulnerability impacting Cisco AsyncOS Software for Cisco Secure Email Gateway and Cisco Secure Email and Web Manager, tracked as CVE-2025-20393 (CVSS: 10). | Reported attacks also resulted in the deployment of the reverse SSH tunneling tools AquaTunnel and Chisel, which can enable unauthorized remote access...
Some of the tools we saw used in post-compromise activity in those impacted since March 2 include: ... Chisel
Some of the tools we saw used in post-compromise activity in those impacted since March 2 include: ... Chisel
The threat actor primarily gained initial access by compromising a Citrix NetScaler remote access server using a publicly available exploit for CVE-2019-19781.
19 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Blackwood, a memory-resident wrapper for Chisel ... could establish encrypted tunnels and a reverse SOCKS proxy.
The threat actor had leveraged the following commands to access the system and consult the local DNS cache, before downloading a TCP tunnelling tool named Chisel onto the system, allowing them to pivot further into the environment.
Reported attacks also resulted in the deployment of the reverse SSH tunneling tools AquaTunnel and Chisel, which can enable unauthorized remote access...
Reported attacks also resulted in the deployment of the reverse SSH tunneling tools AquaTunnel and Chisel, which can enable unauthorized remote access...
Tooling including proprietary reconnaissance engine Kimera; a "curated exploit armory" targeting popular perimeter devices such as those from Fortinet, Ivanti, and Cisco; portable lateral movement toolkits; and "layered command-and-control infrastructure using Neo-reGeorg webshells, Chisel reverse tunnels, and compromised Cisco routers with persistent GRE tunnels," researchers said.
21 distinct techniques documented for this family, organized by ATT&CK tactic.
The use of Cobalt Strike and related beacons were also observed for C2. An interesting observation of a tool used for maintaining access was the use of Chisel, a TCP/UDP tunneling tool written in Golang.
Command and Control T1071.001 Application Layer Protocol: Web Protocols ... using POST request /api/v2/ajax
The attacker uses Chisel (SOCKS5 proxy connection on a secure channel like http/ssh, tunneling traffic through firewall for hidden communication) with Cobalt Strike.
« Pivot réseau : SOCKS via VPS loués en Allemagne et aux États-Unis ».
«Masque используют утилиту Chisel для перенаправления сетевого трафика в обход firewall и NAT.»
«Masque загружают инструменты с помощью программы certutil и команд PowerShell.»
SSH reverse tunnel (-R *:1080)... Cloudflare Tunnel... Chisel tunneling client... SystemBC SOCKS proxy for resilience.
35 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
68 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Tunneling software explicitly weaponized through the Blackwood wrapper in this campaign. Its functionality supports encrypted tunnels and reverse SOCKS proxy access into the compromised network.
Legitimate open-source tunneling utility explicitly weaponized as Blackwood's embedded in-memory payload in this campaign. It provides encrypted TCP tunnels over HTTP and SOCKS5 proxying, allowing attackers to bridge external infrastructure into compromised internal networks.
SOCKS5 tunneling tool deployed by the cryptomining operator to proxy communications and facilitate access through the compromised Langflow host.
An open-source TCP tunneling tool used by the attacker during post-exploitation.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.