Plink (PuTTY Link) is a legitimate PuTTY command-line SSH client that threat actors have used as a tunneling utility rather than as malware developed specifically for malicious use. In the provided reporting, it was used to tunnel Remote Desktop Protocol (RDP) connections over SSH and to create tunnels into internal services. xHunt used Plink to establish SSH tunnels to interact with BumbleBee webshells on internal IIS servers across three Kuwaiti organizations, including tunnels to TCP 3389 and TCP 80, as part of long-running cyber-espionage campaigns targeting shipping, transportation, and government entities in Kuwait. In a separate intrusion investigated by NCC Group, an actor associated with the NoEscape ransomware-as-a-service operation used PuTTY Link shortly after exploiting Microsoft Exchange ProxyShell vulnerabilities (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207) to maintain access by tunneling RDP over SSH in case the initial webshell foothold was removed. That command referenced remote endpoint 172.93.181[.]238. The content also notes that IOC listings included hashes for PuTTY Link (Plink).
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct techniques documented for this family, organized by ATT&CK tactic.
5 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
SSH tunneling utility used to create port forwards/tunnels to internal services (e.g., RDP 3389, HTTP 80), supporting lateral movement and access to internal webshell endpoints.
Legitimate SSH tunneling utility abused to create RDP-over-SSH tunnels for persistent remote access (protocol tunneling) as a backup access method.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.