logo

Ngrok-free.app Malware Tunneling Abuse: Prevention Guide

ID: 395ce5a3-eaf9-57ac-b9e0-ce6110aa2373

STIX ID: report--395ce5a3-eaf9-57ac-b9e0-ce6110aa2373

Feed Name: Malware Patrol Blog

Threat Score
65/100

Date Published: 2024-04-22

Date Updated: 2026-06-15

Author: Malware Patrol

...
...

This intelligence blog analyzes the rising misuse of tunneling/ingress-as-a-service platforms (like Ngrok) by attackers to host C2 servers, phishing sites, data exfiltration channels, and malware distribution; it documents example C2 URLs and that njRAT and Nanocore RAT comprise the vast majority of observed Ngrok-hosted C2s (Oct 2023–Apr 2024), describes responsible disclosure to Ngrok, and lists defensive controls and mitigations (network monitoring, EDR, whitelisting, access controls, audits, and intelligence sharing).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.