Skip to main content
Mallory
MalwareUsed by 2 actors

ssf

SSF is a tunneling and proxying tool observed in intrusion activity to establish SOCKS proxy connections and enable access into victim networks. The provided content identifies SSF as one of the tunneling tools used by MuddyWater, alongside Chisel and Ligolo, and separately notes Blue Mockingbird using frp, ssf, and Venom to establish SOCKS proxy connections. Based on the content, SSF is used as dual-use infrastructure tooling rather than as a custom malware family. Its documented role is network tunneling/proxying to support operator access, pivoting, and internal network reachability after compromise. The content does not provide specific infection vectors, persistence mechanisms, payload delivery behavior, or indicators of compromise unique to SSF itself.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

THREAT ACTORS

Groups observed using it

2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
MuddyWater

Among the tunneling tools MuddyWater attackers were observed using are Chisel, SSF and Ligolo.

via sentinelone labssentinelone.com
Blue Mockingbird

Blue Mockingbird has used frp, ssf, and Venom to establish SOCKS proxy connections.

via mitre attackattack.mitre.org
MITRE ATT&CK

Techniques & procedures

2 distinct techniques documented for this family, organized by ATT&CK tactic.

T1090.001Internal ProxyEvidence2

"APT41 used a tool called CLASSFON to covertly proxy network communications." / "BADCALL functions as a proxy server between the victim and C2 server." / "Sandworm Team's BCS-server tool can create an internal proxy server to redirect traffic..."

T1572Protocol TunnelingEvidence1

The operators behind MuddyWater activities are very fond of tunneling tools... Among the tunneling tools MuddyWater attackers were observed using are Chisel, SSF and Ligolo... By setting up both a server and a client instance of Chisel on the machine, the operators enable themselves to tunnel a variety of protocols which are supported over SOCKS5.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution2

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping2

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.