Ligolo-ng is an open-source, Go-based tunneling and pivoting tool used in legitimate red-team engagements and repeatedly abused in intrusions. It establishes encrypted reverse TCP/TLS tunnels between an agent on a compromised system and an operator-controlled proxy, enabling covert remote access, traffic relaying, and pivoting into internal networks. Threat actors have deployed it after compromising Windows systems, Linux servers, and Citrix NetScaler appliances, including for persistent remote access through services or scheduled execution. It has been observed in ransomware, espionage, and financially motivated operations, including activity attributed or linked to Medusa, Akira, UAC-0247, and APT28-aligned operations. Ligolo-ng is commonly used alongside credential-access, remote-access, and lateral-movement tooling to reach otherwise inaccessible internal systems.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
CISA is releasing this Cybersecurity Advisory to warn network defenders about exploitation of CVE-2023-3519, an unauthenticated remote code execution (RCE) vulnerability affecting NetScaler (formerly Citrix) Application Delivery Controller (ADC) and NetScaler Gateway. In June 2023, threat actors exploited this vulnerability as a zero-day to drop a webshell...
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Для побудови прихованих тунелей можуть використовуватися програмні засоби LIGOLO-NG та CHISEL.
Notably, port 11601 ran Ligolo-ng, a tunneling and pivoting tool popular in red team operations... used the C2 server as a pivot point for tunneling into compromised networks.
15 distinct techniques documented for this family, organized by ATT&CK tactic.
At least two payloads of SystemBC ... communicated with that IP around 2023-10-27 ... Again, we found that this IP address resolved o*.*.claudfront[.]net on 2024-03-15 (see section in the main text dedicated to DecoyDog: DNS tunnelling as C2).
T1071.001 — Application Layer Protocol: Web Protocols (Command and Control)
“Cloudflare tunnel (cloudflared.exe tunnel run --token). Ngrok or Ligolo-ng tunneling via nssm.exe as fake ‘sysmon’ service.”
SSH Dynamic Port Forwarding (SOCKS Proxy)... You then configure proxychains... the traffic will be seamlessly tunneled through the SSH connection into the internal network.
launched tunneling tools such as Ngrok or Ligolo-ng to establish remote access to the compromised machines
Durring our CTI research on Karakurt / Conti Servers we are able to identify the use of SOCKS proxy pivoting technique with a open source tool called Ligolo-ng against multiple victims.
As part of their initial exploit chain [T1190], the threat actors uploaded a TGZ file [T1105] containing a generic webshell [T1505.003], discovery script [TA0007], and setuid binary [T1548.001] on the ADC appliance.
MITRE ATT&CK Mapping ... Non-Standard Port T1571 Ports 4040, 2083, 8181, 11601
39 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Tunneling/pivoting tool used in Medusa-related command-and-control activity.
Tunneling utility staged as part of the operator toolkit to support network pivoting and remote access.
A tunneling/offensive security tool observed on the infrastructure and repurposed for malicious use.
A tunneling/proxy tool used to build covert tunnels within compromised environments.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.