Ligolo-ng is an open-source tunneling and pivoting utility written in Go that is widely used in red-team operations and frequently repurposed by threat actors for covert post-exploitation access. It provides encrypted reverse TCP/TLS tunnels between compromised systems and operator-controlled infrastructure, enabling remote access, internal pivoting, and movement across segmented environments. In intrusion reporting it commonly appears alongside broader hands-on-keyboard tradecraft, including credential theft, privilege escalation, lateral movement, and ransomware or espionage operations.
Observed malicious use spans Windows and Linux environments, as well as edge appliances such as Citrix NetScaler. Operators have deployed Ligolo-ng as an agent or persistent tunneler, sometimes installed as a service or maintained through scheduled execution mechanisms such as cron. It has been used to establish remote access from compromised hosts, route traffic into victim networks, and support multi-hop proxying and internal reconnaissance after initial compromise. Reporting also places it in campaigns involving phishing-delivered malware, exploitation of internet-facing appliances, and post-compromise persistence within enterprise networks.
Ligolo-ng has been observed in activity associated with multiple threat clusters and intrusion sets, including ransomware operations such as Akira and The Gentlemen, espionage-linked activity aligned with APT28, and campaigns tracked by CERT-UA. Because it is a legitimate dual-use tool rather than malware purpose-built for a single criminal operation, its presence is most strongly indicative of post-exploitation tunneling, covert access, and lateral enablement rather than standalone payload functionality.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
CISA is releasing this Cybersecurity Advisory to warn network defenders about exploitation of CVE-2023-3519, an unauthenticated remote code execution (RCE) vulnerability affecting NetScaler (formerly Citrix) Application Delivery Controller (ADC) and NetScaler Gateway. In June 2023, threat actors exploited this vulnerability as a zero-day to drop a webshell...
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Для побудови прихованих тунелей можуть використовуватися програмні засоби LIGOLO-NG та CHISEL.
Notably, port 11601 ran Ligolo-ng, a tunneling and pivoting tool popular in red team operations... used the C2 server as a pivot point for tunneling into compromised networks.
14 distinct techniques documented for this family, organized by ATT&CK tactic.
At least two payloads of SystemBC ... communicated with that IP around 2023-10-27 ... Again, we found that this IP address resolved o*.*.claudfront[.]net on 2024-03-15 (see section in the main text dedicated to DecoyDog: DNS tunnelling as C2).
SSH Dynamic Port Forwarding (SOCKS Proxy)... You then configure proxychains... the traffic will be seamlessly tunneled through the SSH connection into the internal network.
launched tunneling tools such as Ngrok or Ligolo-ng to establish remote access to the compromised machines
Durring our CTI research on Karakurt / Conti Servers we are able to identify the use of SOCKS proxy pivoting technique with a open source tool called Ligolo-ng against multiple victims.
As part of their initial exploit chain [T1190], the threat actors uploaded a TGZ file [T1105] containing a generic webshell [T1505.003], discovery script [TA0007], and setuid binary [T1548.001] on the ADC appliance.
MITRE ATT&CK Mapping ... Non-Standard Port T1571 Ports 4040, 2083, 8181, 11601
35 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Tunneling utility staged as part of the operator toolkit to support network pivoting and remote access.
A tunneling/offensive security tool observed on the infrastructure and repurposed for malicious use.
A tunneling/proxy tool used to build covert tunnels within compromised environments.
A tunneling/pivoting utility used to route traffic into compromised environments; in this campaign it was exposed as a service on the operator infrastructure and used for network pivoting.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.