Plink, also known as PuTTY Link, is a legitimate command-line connection utility in the PuTTY suite that threat actors abuse for encrypted SSH tunneling and remote access. It supports local and remote port forwarding, allowing attackers to expose internal services through attacker-controlled infrastructure. Observed malicious uses include tunneling RDP and HTTP traffic, accessing internal servers, transferring tools, and supporting lateral movement. Outbound reverse tunnels can bypass inbound firewall restrictions, while encryption obscures the traffic carried within them.
Plink is commonly deployed after compromise rather than serving as an initial infection mechanism. It has been downloaded and executed through web shells and other post-exploitation components on compromised Windows systems, including Microsoft Exchange and ManageEngine servers. Attackers sometimes rename the utility to conceal its identity. Modified versions have added Windows service execution and removal functionality or embedded SSH credentials and server configurations to automate reverse tunnels and maintain access.
Documented users include Agrius, Chafer, PHOSPHORUS, POLONIUM, TunnelVision, TEMP.Veles, actors associated with xHunt, and Stonefly. Its abuse spans espionage, ransomware, and extortion operations. Plink is a dual-use administrative tool, not inherently a malware family; malicious behavior depends on its configuration, modifications, and operational use.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The threat actor is known to exploit Fortinet CVE-2018-13379, Exchange ProxyShell, and the log4j vulnerabilities. Thanks to Deep Instinct’s prevention capabilities the threat actor was unsuccessful in executing the payloads in a customer environment despite successful exploitation of the Exchange server.
"The most commonly deployed tunneling tools used by the group are Fast Reverse Proxy Client (FRPC) and Plink."
"The most commonly deployed tunneling tools used by the group are Fast Reverse Proxy Client (FRPC) and Plink."
8 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
A slightly modified version of PLINK, part of the PuTTY suite, was also revealed by Bitdefender telemetry in late September 2018.
we were able to retrieve the “pl” file; it is a Plink executable... The file is used to create a SSH tunnel to the attacker’s machine while exposing RDP port
POLONIUM’s tunnels module uses the Plink utility to create SSH tunnels.
The most commonly deployed tunneling tools used by the group are Fast Reverse Proxy Client (FRPC) and Plink.
Agrius used the Plink tool to tunnel RDP connections for remote access and lateral movement in victim environments.
...deploying tunneling utilities such as Chisel, plink, and rsockstun to established dedicated conduits into affected network segments.
19 distinct techniques documented for this family, organized by ATT&CK tactic.
TunnelVision activities are characterized by wide-exploitation of 1-day vulnerabilities in target regions. During the time we’ve been tracking this actor, we have observed wide exploitation of Fortinet FortiOS (CVE-2018-13379), Microsoft Exchange (ProxyShell) and recently Log4Shell.
This allows the attacker to log in to the compromised system via RDP, even if the RDP is not exposed directly to the internet.
The adversary also used various methods to steal high-level credentials and moved freely across the network using Remote Desktop Protocol (RDP)
“The main purpose of this tool is to give the attacker access to the internal network of the victim.”
Plink (msssh.exe), was used to configure port-forwarding rules allowing for RDP access from a remote host... This effectively sets up a tunnel that allows the attackers to access a remote service such as RDP through the SSH connection.
Plink is then used to open reverse SSH sessions from the attacker's server to the RDP port on the victim computer.
The downloaded files were hosted on attacker-controlled sub-domain google.onedriver-srv[.]ml.
T1105 Ingress Tool Transfer : Powershell cmdlet Invoke-WebRequest(IWR) used to download additional remote access tools
CrowdStrike said the OWASSRF exploit was used to drop remote access tools such as Plink and AnyDesk on Rackspace-compromised servers. BleepingComputer also found that Play ransomware tooling found online by researchers also contains the ConnectWise remote administration software, which will likely be deployed in attacks.
28 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
18 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Command-line network connection tool often used for tunneling and remote access.
A legitimate SSH tool explicitly abused in the observed intrusion. The attacker downloaded a renamed executable and used SSH remote port forwarding to expose the compromised system's RDP service for persistent access. It is included for this malicious use, not characterized as an inherently malicious family.
SSH/tunneling utility used to create access conduits into compromised network segments.
Command-line SSH client (PuTTY suite) used for scripted remote connections and tunneling.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.