Ligolo is an open-source reverse-tunneling utility used to create covert network pivots and remote access paths from compromised systems back to operator-controlled infrastructure. In intrusion reporting it is typically observed as a post-compromise tool rather than a bespoke malware family, enabling attackers to tunnel traffic, proxy connections, and extend control deeper into victim environments after initial access. It has been used to support lateral movement, remote administration, and broader post-exploitation operations by providing a bridge into internal networks.
Ligolo has been repeatedly associated with Iranian state-linked intrusion activity, especially operations attributed to MuddyWater, also tracked by some vendors as MERCURY or Mango Sandstorm. Reporting has described its deployment after foothold establishment by other implants such as SloughRAT, as well as its use alongside tools including Chisel, SSF, eHorus, ScreenConnect, RemoteUtilities, Mimikatz, CrackMapExec, and Exchange web shells. In some campaigns, operators downloaded Ligolo with native Windows utilities or PowerShell and used it to pivot from initially compromised hosts toward additional internal systems and external targets.
Observed victimology linked to Ligolo-enabled operations includes telecommunications providers, government entities, IT services organizations, utilities, and other high-value organizations across the Middle East and Asia, with additional reporting tying its use to campaigns affecting Turkey, Pakistan, Armenia, Jordan, Israel, and states in the Arabian Peninsula. Customized variants have also been reported masquerading as legitimate VPN software to reduce suspicion and blend with enterprise remote-access tooling.
Because Ligolo is a legitimate open-source tunneling project, its presence alone does not inherently indicate maliciousness. In threat operations, however, it functions as an offensive post-exploitation utility that facilitates persistence of access, internal pivoting, and operator control within compromised Windows environments.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The attackers utilized SloughRAT to deploy Ligolo, an open-source reverse-tunneling tool to gain a greater degree of control over the infected endpoints.
16 distinct techniques documented for this family, organized by ATT&CK tactic.
Step 2: Pivot : Moved laterally from the compromised Exchange server into the internal network. The actor used a Metasploit reverse shell and ran Ligolo as a background process on an internal host for tunneling.
The attackers utilized SloughRAT to deploy Ligolo, an open-source reverse-tunneling tool to gain a greater degree of control over the infected endpoints.
the Ligolo reverse tunneling tool which was used against Middle Eastern countries in March 2021
The attackers utilized SloughRAT to deploy Ligolo, an open-source reverse-tunneling tool
4 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A tunneling/pivoting tool observed in MuddyWater activity to enable operator access into internal target environments.
Open-source reverse tunneling tool; observed in customized variants to emulate Cisco/Palo Alto VPN artifacts for evasion.
Open-source reverse tunneling tool used for command-and-control communications and pivoting within victim environments.
An open-source reverse-tunneling tool deployed post-compromise to provide greater control over infected endpoints.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.