Plink is the command-line connection utility from the PuTTY suite and is frequently repurposed by threat actors as a dual-use SSH tunneling tool rather than as bespoke malware. In intrusion operations it is commonly used to establish encrypted SSH tunnels, including reverse tunnels, that expose internal services such as Remote Desktop Protocol to attacker-controlled infrastructure. This enables covert remote access, lateral movement, tool transfer, and post-compromise persistence or access maintenance inside victim environments.
Multiple state-linked and espionage-oriented clusters have used Plink in post-exploitation workflows, including Iranian-aligned activity such as PHOSPHORUS, POLONIUM, Agrius, TunnelVision, and Homeland Justice; the xHunt campaign; DPRK-linked Andariel and Stonefly activity; and TEMP.Veles. Reported use cases include tunneling RDP to compromised Windows hosts, bridging access to internal IIS and other segmented systems, and supporting movement across enterprise networks after exploitation of internet-facing services or deployment of web shells and backdoors. Actors have also renamed or modified Plink binaries and embedded credentials or tunnel parameters to reduce scrutiny and automate access.
Because Plink is a legitimate administration utility, its malicious significance depends on operational context. When abused by adversaries, it most directly functions as a tunneling and remote-access enabler in the post-exploitation phase, especially on Windows systems, and is often paired with credential theft, web shells, reverse proxies, or remote desktop access to sustain intrusion activity.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The threat actor is known to exploit Fortinet CVE-2018-13379, Exchange ProxyShell, and the log4j vulnerabilities. Thanks to Deep Instinct’s prevention capabilities the threat actor was unsuccessful in executing the payloads in a customer environment despite successful exploitation of the Exchange server.
"The most commonly deployed tunneling tools used by the group are Fast Reverse Proxy Client (FRPC) and Plink."
"The most commonly deployed tunneling tools used by the group are Fast Reverse Proxy Client (FRPC) and Plink."
7 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
we were able to retrieve the “pl” file; it is a Plink executable... The file is used to create a SSH tunnel to the attacker’s machine while exposing RDP port
POLONIUM’s tunnels module uses the Plink utility to create SSH tunnels.
The most commonly deployed tunneling tools used by the group are Fast Reverse Proxy Client (FRPC) and Plink.
Agrius used the Plink tool to tunnel RDP connections for remote access and lateral movement in victim environments.
...deploying tunneling utilities such as Chisel, plink, and rsockstun to established dedicated conduits into affected network segments.
The commands executed on the servers via BumbleBee suggest that the actor used the PuTTY Link (Plink) tool to create SSH tunnels to access services internal to the compromised network.
20 distinct techniques documented for this family, organized by ATT&CK tactic.
TunnelVision activities are characterized by wide-exploitation of 1-day vulnerabilities in target regions. During the time we’ve been tracking this actor, we have observed wide exploitation of Fortinet FortiOS (CVE-2018-13379), Microsoft Exchange (ProxyShell) and recently Log4Shell.
This allows the attacker to log in to the compromised system via RDP, even if the RDP is not exposed directly to the internet.
The adversary also used various methods to steal high-level credentials and moved freely across the network using Remote Desktop Protocol (RDP)
The PowerShell scripts executes the Plink tool for establishing a reverse proxy connection to the C2 to enable interaction with the PowerShell web server
Plink (msssh.exe), was used to configure port-forwarding rules allowing for RDP access from a remote host... This effectively sets up a tunnel that allows the attackers to access a remote service such as RDP through the SSH connection.
Plink is then used to open reverse SSH sessions from the attacker's server to the RDP port on the victim computer.
FIN8 has used the Plink utility to tunnel RDP back to C2 infrastructure. REPTILE can use TLS over raw TCP for secure C2.
The downloaded files were hosted on attacker-controlled sub-domain google.onedriver-srv[.]ml.
task_update.exe... is responsible for downloading FRPC from an attacker-controlled server...
CrowdStrike said the OWASSRF exploit was used to drop remote access tools such as Plink and AnyDesk on Rackspace-compromised servers. BleepingComputer also found that Play ransomware tooling found online by researchers also contains the ConnectWise remote administration software, which will likely be deployed in attacks.
T1572 – Protocol Tunneling The adversary employed Ngrok, plink, and SSH to tunnel various protocols (primarily RDP, SMB, and SSH) within web traffic to various VPS infrastructure. | The adversary then began chaining proxy access via plink and Ngrok to traverse the victim’s network segmentation.
28 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
15 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Command-line network connection tool often used for tunneling and remote access.
SSH/tunneling utility used to create access conduits into compromised network segments.
Command-line SSH client (PuTTY suite) used for scripted remote connections and tunneling.
Publicly available network communication utility used by the attackers as part of the intrusion toolset.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.