Chisel is an open-source tunneling utility developed by Jamie Pillora that implements client-server TCP tunneling over HTTP, typically secured through SSH, and is widely abused by threat actors as a covert post-compromise access mechanism. It is commonly used to establish reverse tunnels and SOCKS5 proxies from victim environments back to attacker-controlled infrastructure, enabling command-and-control, remote administration, lateral movement support, and traffic relay into otherwise inaccessible internal network segments.
Across intrusion reporting, Chisel is repeatedly observed after initial compromise rather than as a primary payload. Operators deploy it on compromised Windows and Linux systems, on internet-facing servers, and in some cases on security appliances or adjacent infrastructure to maintain resilient connectivity. Adversaries frequently rename the binary to blend with legitimate software and use it alongside web shells, remote management tools, reverse shells, Cloudflare Tunnel, FRP, Ligolo, SSF, Sliver, or GRE tunnels to create layered persistence and redundant access paths. In SOCKS mode, Chisel provides a full proxy capability that supports hands-on-keyboard operations, credential theft workflows, reconnaissance, and lateral movement through tools such as WMIExec, SMBExec, PsExec, RDP, and other administrative channels.
Chisel has been documented in financially motivated intrusions, ransomware operations, espionage campaigns, and state-linked activity. Reported users include MuddyWater, Stonefly, Pioneer Kitten/UNC757, Seashell Blizzard-linked operations, UAT-9686, and multiple criminal or hybrid clusters targeting government, critical infrastructure, telecommunications, financial organizations, healthcare entities, and enterprise environments. It has also appeared in campaigns exploiting perimeter devices and web applications, where attackers paired Chisel with web shells or appliance compromises to tunnel traffic over HTTP and evade host-based visibility.
Because Chisel is a legitimate dual-use tool rather than a purpose-built malware family, its malicious significance lies in its operational role as a tunneling backdoor and proxy channel within broader intrusions. Its recurring use reflects its effectiveness for defense evasion, persistence, and post-exploitation network access.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The threat actor primarily gained initial access by compromising a Citrix NetScaler remote access server using a publicly available exploit for CVE-2019-19781.
Cisco revealed that a newly identified China-linked advanced persistent threat (APT), "UAT-9686," had been exploiting a zero-day vulnerability in Cisco email security appliances that run on its AsyncOS software. The vulnerability, tracked as CVE-2025-20393, has since been assigned a "critical" 10 out of 10 severity rating in the Common Vulnerability Scoring System (CVSS), and it has not yet been patched.
15 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Tooling including proprietary reconnaissance engine Kimera; a "curated exploit armory" targeting popular perimeter devices such as those from Fortinet, Ivanti, and Cisco; portable lateral movement toolkits; and "layered command-and-control infrastructure using Neo-reGeorg webshells, Chisel reverse tunnels, and compromised Cisco routers with persistent GRE tunnels," researchers said.
Tooling including proprietary reconnaissance engine Kimera; a "curated exploit armory" targeting popular perimeter devices such as those from Fortinet, Ivanti, and Cisco; portable lateral movement toolkits; and "layered command-and-control infrastructure using Neo-reGeorg webshells, Chisel reverse tunnels, and compromised Cisco routers with persistent GRE tunnels," researchers said.
The tools frequently used by the group include Cobalt Strike, mimikatz, chisel, BloodHound, PowerView, adPEAS, CrackMapExec, Advanced IP Scanner and PsExec.
Among the tunneling tools MuddyWater attackers were observed using are Chisel, SSF and Ligolo... In this case, the “SharpChisel.exe” client runs on the victim machine, connects back to the Chisel server over port 8080...
...deploying tunneling utilities such as Chisel, plink, and rsockstun to established dedicated conduits into affected network segments.
Для побудови прихованих тунелей можуть використовуватися програмні засоби LIGOLO-NG та CHISEL.
23 distinct techniques documented for this family, organized by ATT&CK tactic.
On compromised servers, the binary drops as a hidden dot-prefixed file and persists at /var/tmp/.xs , using either a cron job or a systemd service to survive reboots.
Base64-encoded payloads including chisel.b64 , pwnkit_b64 , neo.jspx.b64 and payload.b64 ; chunked ELF binary delivery; AES-encrypted Neo-reGeorg webshell channel; custom Base64 alphabet.
a renamed copy of the Chisel tunneling tool disguised as chrome.exe... The payload was named bitsadmin.exe, likely to masquerade as the legitimate Windows utility
A separate diagnostic script rounds out the toolkit. It selects five active beacons at random and runs a shell command on each to verify the presence of Chisel binaries at known drop paths, confirm a Chisel process is running, check available disk space, test reachability of port 9000 on the C2, and confirm persistence artifacts are still in place.
A separate diagnostic script rounds out the toolkit. It selects five active beacons at random and runs a shell command on each to verify the presence of Chisel binaries at known drop paths, confirm a Chisel process is running, check available disk space, test reachability of port 9000 on the C2, and confirm persistence artifacts are still in place.
The attacker used Sliver, an open-source command-and-control framework, combined with Chisel tunneling binaries compiled for most Linux CPU architectures: AMD64, ARM64, and x86.
CMDEmber sends and receives data from the C2 server by issuing HTTP POST and GET requests, respectively.
Within minutes, they deployed three separate tunneling tools, including Chisel (disguised as chrome.exe) and a Cloudflare tunnel client establishing redundant, covert communication channels.
SOCKS5 pivot through 165.22.184.26:5571 to internal 10.39.x.x systems; Chisel reverse tunnel creating SOCKS proxies on 127.0.0.1:1080–1081; internal relay node at 10.39.1.204.
they set up a reverse SOCKS proxy, a renamed copy of the Chisel tunneling tool disguised as chrome.exe, and a Cloudflare Tunnel client
Three separate network-tunneling utilities were deployed to the host in the first 10 minutes of activity.
Payloads and tools were delivered from the same external IP and from two external staging domains, in some cases, using .jpg extensions to disguise the files.
CloudSEK’s findings, as summarized by Infosecurity Magazine, describe Neo-reGeorg webshells, Chisel reverse tunnels, and even a compromised Cisco router configured with a GRE tunnel to maintain access. These methods helped the attackers stay connected while blending into normal traffic...
19 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
55 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A tunneling utility used by the attackers, renamed to masquerade as Chrome and provide redundant access channels in the compromised environment.
A tunneling utility used for reverse tunnels to maintain attacker connectivity and evade detection by blending with normal traffic.
A reverse tunneling tool used to carry attacker traffic over HTTP and maintain covert connectivity into victim environments.
A reverse tunneling utility used in the campaign's command-and-control stack to maintain access and route traffic through compromised infrastructure.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.