Ngrok is a tool tracked across 7 threat clusters and 17 intelligence report mentions on ThreatCluster. First observed November 13, 2025; most recent activity July 24, 2026.
Ngrok is a tunneling/reverse-proxy service that exposes local services to the internet, facilitating quick remote access and testing. In threat contexts, adversaries can use Ngrok to establish external C2 channels, bypass NAT/firewalls, and facilitate post-exploitation and lateral movement due to its ease of use and broad accessibility.
The Akira ransomware group has been identified as a significant threat to critical infrastructure, with the U.S. Cybersecurity and Infrastructure Security Agency (CISA) and the FBI warning of its active ransomware…
In early 2026, the Iranian APT group MuddyWater launched cyberattacks against U.S. banking, a major airport, and Israeli operations of a U.S.-based software company. The attacks intensified in March, coinciding with…
Researchers found an exposed server on a Russian bulletproof hosting provider containing a complete ransomware toolkit linked to TheGentlemen affiliate. The toolkit includes various utilities for credential dumping,…
The Com, a decentralized criminal ecosystem, has emerged as a significant threat, combining cybercrime, exploitation of minors, and real-world violence. This group primarily targets cloud and SaaS platforms, with…
A US court filing has disclosed that Microsoft's Global Device Identifier (GDID) tracks user behavior across Windows installations. This persistent key, tied to every Windows OS since Vista, is generated on Microsoft's…
Peter Stokes, a 19-year-old hacker, was arrested in Finland on April 10, 2026, for allegedly being part of the Scattered Spider hacking group. The FBI linked him to a US$8 million ransom demand against a luxury retailer…
Between February and September 2025, BlueDelta, a Russian state-sponsored group, conducted multiple credential-harvesting campaigns. These operations targeted users of UKR.NET, a popular Ukrainian webmail and news…