Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
MalwareRansomwareUsed by 2 actorsExploits 1 CVE

ligolo-ng

Ligolo-ng is an open-source tunneling and pivoting tool written in Go that provides encrypted reverse TCP/TLS connections to a remote host. It is a legitimate red-team/offensive security utility, but the provided reporting shows it being repeatedly repurposed for malicious post-exploitation activity to establish covert remote access, persistence, and internal network pivoting. Observed use cases include deployment by Akira ransomware operators via an NSSM-created malicious service named "Sysmon" to launch Ligolo-ng or Ngrok for remote access; post-exploitation on compromised Citrix NetScaler ADC/Gateway appliances following exploitation of CVE-2023-3519, where actors installed a persistent Ligolo-ng-derived tunneler and in some cases also used NPS and web shells such as SECRETSAUCE and REGEORG.NEO; use by operators targeting Ukrainian municipal and healthcare entities, where CERT-UA observed LIGOLO-NG and CHISEL used to build covert tunnels during UAC-0247 intrusions; and use in broader intrusion infrastructure including exposed C2 environments where a Ligolo-ng agent or proxy was staged or active. Multiple reports specifically note Ligolo-ng proxy activity on port 11601, including self-signed TLS certificates with subject or organization fields indicating Ligolo. Additional contexts tie Ligolo-ng to APT28-aligned Roundcube exploitation infrastructure, Silent Lynx activity, and Russian-hosted malicious infrastructure where it appeared alongside Sliver, Cobalt Strike, Tactical RMM, and other offensive frameworks repurposed for malicious use. High-confidence indicators directly mentioned in the content include filenames such as agent.exe and /var/tmp/the in Ligolo-ng-related deployments, execution from /tmp in one NetScaler case, and recurring network exposure on TCP port 11601 with self-signed TLS certificates associated with Ligolo.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

EXPLOITED CVES

Vulnerabilities exploited

1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.

1 CVES
CVE-2023-3519Unauthenticated RCE in Citrix NetScaler ADC and GatewayExploited in the wild

CISA is releasing this Cybersecurity Advisory to warn network defenders about exploitation of CVE-2023-3519, an unauthenticated remote code execution (RCE) vulnerability affecting NetScaler (formerly Citrix) Application Delivery Controller (ADC) and NetScaler Gateway. In June 2023, threat actors exploited this vulnerability as a zero-day to drop a webshell...

via cisacisa.gov
THREAT ACTORS

Groups observed using it

2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
UAC-0247

Для побудови прихованих тунелей можуть використовуватися програмні засоби LIGOLO-NG та CHISEL.

via cert uacert.gov.ua
APT28

Notably, port 11601 ran Ligolo-ng, a tunneling and pivoting tool popular in red team operations... used the C2 server as a pivot point for tunneling into compromised networks.

via huntio bloghunt.io
MITRE ATT&CK

Techniques & procedures

12 distinct techniques documented for this family, organized by ATT&CK tactic.

Resource Development

2 techniques
T1588.002ToolEvidence2

According to trusted third party reporting, threat actors leveraged open source webshells and other publicly available tools [T1588.002].

T1608.001Upload MalwareEvidence1

MITRE ATT&CK Mapping ... Stage Capabilities: Upload Malware T1608.001 Open directory on :8000 with 9 tools

Persistence

1 technique
T1543.003Windows ServiceEvidence1

Sophos XDR detected the threat actors using the service manager tool nssm.exe... to create the malicious service ‘sysmon,’ which executed sysmon.exe and launched tunneling tools such as Ngrok or Ligolo-ng

Privilege Escalation

1 technique
T1543.003Windows ServiceEvidence1

Sophos XDR detected the threat actors using the service manager tool nssm.exe... to create the malicious service ‘sysmon,’ which executed sysmon.exe and launched tunneling tools such as Ngrok or Ligolo-ng

Lateral Movement

1 technique
T1570Lateral Tool TransferEvidence1

tries to move laterally on the network, and uses publicly available utilities, like the RustScan port scanner, the Ligolo-ng and Chisel tunneling tools

Command and Control

8 techniques
T1071Application Layer ProtocolEvidence1

Over a three-month window from January 1 to April 1, 2026, more than 1,250 active command-and-control (C2) servers were detected across 165 Russian infrastructure providers.

T1090ProxyEvidence3

In some cases, the LIGOLO-NG and CHISEL tools were deployed to build hidden network tunnels

T1090.002External ProxyEvidence3

launched tunneling tools such as Ngrok or Ligolo-ng to establish remote access to the compromised machines

T1090.003Multi-hop ProxyEvidence1

MITRE ATT&CK Mapping ... Proxy: Multi-hop Proxy T1090.003 Ligolo-ng tunnel proxy

T1105Ingress Tool TransferEvidence4

As part of their initial exploit chain [T1190], the threat actors uploaded a TGZ file [T1105] containing a generic webshell [T1505.003], discovery script [TA0007], and setuid binary [T1548.001] on the ADC appliance.

T1571Non-Standard PortEvidence1

MITRE ATT&CK Mapping ... Non-Standard Port T1571 Ports 4040, 2083, 8181, 11601

T1572Protocol TunnelingEvidence2

VPN или jump host с доступом в OT Protocol Tunneling T1572 ... Когда файрвол на границе IT/OT пропускает только специфические порты (502, 443), Protocol Tunneling (T1572, Command and Control) - основной способ получить полноценный доступ в OT.

T1573.002Asymmetric CryptographyEvidence1

LIGOLO-NG is a tunneller [T1572] written in Go that provides encrypted reverse TCP/TLS connections [T1573.002] to a remote host.

INDICATORS OF COMPROMISE

IOCs tracked for this family

14 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.

View more in app
Network
6 tracked

IPs, domains, and DNS infrastructure linked to this family.

Hashes
4 tracked

File hashes (MD5, SHA-1, SHA-256) from samples and reports.

Other
4 tracked

Other indicator types observed in public reporting.

TypeValueLatest sighting
domain●●●●●●●●●●●●View more in app2 months ago
domain●●●●●●●●●●●●View more in app2 months ago
hash.md5●●●●●●●●●●●●View more in app2 months ago
hash.md5●●●●●●●●●●●●View more in app2 months ago
hash.sha256●●●●●●●●●●●●View more in app2 months ago
hash.sha256●●●●●●●●●●●●View more in app2 months ago
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching14

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution2

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities1

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping12

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.