Chisel is an open-source TCP and UDP tunneling tool written in Go and developed by Jamie Pillora. It uses a client-server architecture to establish forward or reverse tunnels; its SOCKS5 mode provides a network proxy through the tunneled connection. Although legitimate in administrative and security-testing contexts, it is frequently repurposed in post-compromise operations to create covert remote-access channels, pivot into internal networks, and maintain connectivity that can bypass network segmentation. Threat actors have deployed Chisel in intrusions involving ransomware, espionage, financially motivated access operations, and compromise of perimeter appliances and web servers. Reported users include PYSA ransomware operators, MuddyWater, UAT-9686, and actors associated with Operation Escaneo. Chisel has been observed on Windows and Linux systems, commonly renamed or embedded in deployment chains to reduce analyst visibility.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Wave 3: Chisel SOCKS5 tunnel deployed (bash history confirms).
On December 17th, 2025, Cisco published an advisory regarding a zero-day Remote Code Execution (RCE) vulnerability impacting Cisco AsyncOS Software for Cisco Secure Email Gateway and Cisco Secure Email and Web Manager, tracked as CVE-2025-20393 (CVSS: 10). | Reported attacks also resulted in the deployment of the reverse SSH tunneling tools AquaTunnel and Chisel, which can enable unauthorized remote access...
Some of the tools we saw used in post-compromise activity in those impacted since March 2 include: ... Chisel
Some of the tools we saw used in post-compromise activity in those impacted since March 2 include: ... Chisel
The threat actor primarily gained initial access by compromising a Citrix NetScaler remote access server using a publicly available exploit for CVE-2019-19781.
17 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Reported attacks also resulted in the deployment of the reverse SSH tunneling tools AquaTunnel and Chisel, which can enable unauthorized remote access...
Reported attacks also resulted in the deployment of the reverse SSH tunneling tools AquaTunnel and Chisel, which can enable unauthorized remote access...
Tooling including proprietary reconnaissance engine Kimera; a "curated exploit armory" targeting popular perimeter devices such as those from Fortinet, Ivanti, and Cisco; portable lateral movement toolkits; and "layered command-and-control infrastructure using Neo-reGeorg webshells, Chisel reverse tunnels, and compromised Cisco routers with persistent GRE tunnels," researchers said.
Tooling including proprietary reconnaissance engine Kimera; a "curated exploit armory" targeting popular perimeter devices such as those from Fortinet, Ivanti, and Cisco; portable lateral movement toolkits; and "layered command-and-control infrastructure using Neo-reGeorg webshells, Chisel reverse tunnels, and compromised Cisco routers with persistent GRE tunnels," researchers said.
The tools frequently used by the group include Cobalt Strike, mimikatz, chisel, BloodHound, PowerView, adPEAS, CrackMapExec, Advanced IP Scanner and PsExec.
21 distinct techniques documented for this family, organized by ATT&CK tactic.
In order to execute remote command, threat actors also relied on valid credentials collected in previous stages used wmic tool to execute commands on remote hosts.
The use of Cobalt Strike and related beacons were also observed for C2. An interesting observation of a tool used for maintaining access was the use of Chisel, a TCP/UDP tunneling tool written in Golang.
Command and Control T1071.001 Application Layer Protocol: Web Protocols ... using POST request /api/v2/ajax
The first operator deployed "proxy agents." The cryptomining operator also deployed a proxy agent and a "Chisel SOCKS5 tunnel."
« Pivot réseau : SOCKS via VPS loués en Allemagne et aux États-Unis ».
they set up a reverse SOCKS proxy, a renamed copy of the Chisel tunneling tool disguised as chrome.exe, and a Cloudflare Tunnel client
Some of the tools we saw used in post-compromise activity in those impacted since March 2 include: ... Stowaway multi-hop proxy tool
Lorenz set up a SOCKS proxy via Chisel on the Mitel device.
Over two weeks, the first attacker "dropped a Python credential harvester, proxy agents, and a SimpleHelp RAT installation." The second deployed a proxy agent, Chisel, pearl-miner, and .sysd.
35 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
64 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
SOCKS5 tunneling tool deployed by the cryptomining operator to proxy communications and facilitate access through the compromised Langflow host.
An open-source TCP tunneling tool used by the attacker during post-exploitation.
Reverse tunneling utility used to establish SOCKS-based remote network access during the intrusion.
Legitimate tunneling tool that the content says was customized by attackers to support malicious operations.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.