Ngrok - Tool

Threat entity extracted from intelligence sources

Frequency
17
occurrences
First Seen
November 13, 2025
Last Seen
July 24, 2026

Ngrok is a tool tracked across 7 threat clusters and 17 intelligence report mentions on ThreatCluster. First observed November 13, 2025; most recent activity July 24, 2026.

Overview

Ngrok is a tunneling/reverse-proxy service that exposes local services to the internet, facilitating quick remote access and testing. In threat contexts, adversaries can use Ngrok to establish external C2 channels, bypass NAT/firewalls, and facilitate post-exploitation and lateral movement due to its ease of use and broad accessibility.

Related Threat Clusters

Recent Intelligence Reports

  • Global Device Identifier: How Microsoft tracks your behaviour — Computing · July 24, 2026
  • Earth Simnavaz Cyberattacks — www.trendmicro.com · July 23, 2026
  • T1102 — attack.mitre.org · July 23, 2026
  • APT34 (OilRig): Espionage on Your Infrastructure — Kelacyber · July 22, 2026
  • Windows is watching: Anti — Theregister · July 7, 2026
  • Notorious hacker's arrest sparks backlash over Microsoft's excessive device tracking — Cybernews · July 7, 2026
  • Microsoft Can Track Users Via a Windows Device ID — Rss.Slashdot · July 7, 2026
  • A Hacker's Arrest Reveals Microsoft Can Track Users Via a Windows Device ID — Uk.Pcmag · July 7, 2026

CVSS v3.1 Breakdown