SSF is a tunneling and proxying tool observed in intrusion activity to establish SOCKS proxy connections and support operator access into victim environments. In the provided content, it is described as one of the tunneling tools used by MuddyWater alongside Chisel and Ligolo, where such tooling was used to create layered reverse tunnels and SOCKS5 access inside victim networks. The content also states that Blue Mockingbird used FRP, ssf, and Venom to establish SOCKS proxy connections. Based on the available information, SSF is associated with proxying/tunneling behavior that enables traffic relaying, internal network access, and operational pivoting. Associated threat actors directly mentioned in the content are MuddyWater, an Iranian state-sponsored actor linked by U.S. Cyber Command to Iran’s MOIS, and Blue Mockingbird. No specific infection vector, platform-specific malware behavior, or standalone indicators of compromise for SSF are provided in the content.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Among the tunneling tools MuddyWater attackers were observed using are Chisel, SSF and Ligolo.
Blue Mockingbird has used frp, ssf, and Venom to establish SOCKS proxy connections.
2 distinct techniques documented for this family, organized by ATT&CK tactic.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A tunneling tool observed in MuddyWater operations, used to facilitate network pivoting and protocol tunneling.
Proxy/tunneling tool used to set up SOCKS proxying for internal access and pivoting.
Tool used to establish SOCKS proxy connections for tunneling/pivoting.
Tool used to establish SOCKS proxy connections.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.