ssf
SSF is a tunneling and proxying tool observed in intrusion activity to establish SOCKS proxy connections and enable access into victim networks. The provided content identifies SSF as one of the tunneling tools used by MuddyWater, alongside Chisel and Ligolo, and separately notes Blue Mockingbird using frp, ssf, and Venom to establish SOCKS proxy connections. Based on the content, SSF is used as dual-use infrastructure tooling rather than as a custom malware family. Its documented role is network tunneling/proxying to support operator access, pivoting, and internal network reachability after compromise. The content does not provide specific infection vectors, persistence mechanisms, payload delivery behavior, or indicators of compromise unique to SSF itself.
Hunt this family in your stack
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
Groups observed using it
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Among the tunneling tools MuddyWater attackers were observed using are Chisel, SSF and Ligolo.
Blue Mockingbird has used frp, ssf, and Venom to establish SOCKS proxy connections.
Techniques & procedures
2 distinct techniques documented for this family, organized by ATT&CK tactic.
Command and Control
2 techniques"APT41 used a tool called CLASSFON to covertly proxy network communications." / "BADCALL functions as a proxy server between the victim and C2 server." / "Sandworm Team's BCS-server tool can create an internal proxy server to redirect traffic..."
The operators behind MuddyWater activities are very fond of tunneling tools... Among the tunneling tools MuddyWater attackers were observed using are Chisel, SSF and Ligolo... By setting up both a server and a client instance of Chisel on the machine, the operators enable themselves to tunnel a variety of protocols which are supported over SOCKS5.
Recent activity
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A tunneling tool observed in MuddyWater operations for network pivoting and protocol tunneling.
Proxy/tunneling tool used to set up SOCKS proxying for internal access and pivoting.
Tool used to establish SOCKS proxy connections for tunneling/pivoting.
Tool used to establish SOCKS proxy connections.
The version that knows your environment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.