ngrok (316ecd9d-ac0b-58c7-8083-5d9214c770f6)
ngrok is a legitimate reverse proxy tool that can create a secure tunnel to servers located behind firewalls or on local machines that do not have a public IP. ngrok has been leveraged by threat actors in several campaigns including use for lateral movement and data exfiltration.[Zdnet Ngrok September 2018][FireEye Maze May 2020][Cyware Ngrok May 2019][MalwareBytes LazyScripter Feb 2021]