logo

Abusing Ngrok: Hackers at the End of the Tunnel

ID: 9ff51bed-c77d-5a57-8dd3-d9efc6951aa0

STIX ID: report--9ff51bed-c77d-5a57-8dd3-d9efc6951aa0

Feed Name: Huntress Blog

Threat Score
70/100

Date Published: 2024-04-12

Date Updated: 2026-04-28

...
...

Huntress reports an incident in which attackers installed a renamed ngrok client (masquerading as conhost.exe) and used a persistent VBScript to launch it with an ngrok configuration exposing RDP (3389), UltraVNC (configured on port 6300), and a proxy (3128) to the public Internet. Artifacts recovered include the ngrok.yml, an UltraVNC configuration and winvnc.exe in a user AppData folder plus registry Run keys, indicating post-exploitation persistence and remote access capabilities that could enable full desktop control, lateral movement, and data exfiltration.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.