Ngrok Misused By Hackers For New Phishing Wave
ID: 4fe5cf4f-3aaf-5a4f-aa76-7099dcf3cef8
STIX ID: report--4fe5cf4f-3aaf-5a4f-aa76-7099dcf3cef8
Feed Name: Cyble Blog
Threat Score
Cyble observed an uptick in phishing campaigns abusing the ngrok tunnelling service to expose locally hosted phishing pages on random ngrok subdomains, enabling attackers to bypass NAT/firewall protections and capture credentials, OTPs, and financial data; the report includes attack steps, example ngrok IOCs, evidence of tool-sharing in cybercrime forums, and mitigation recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
