
New Njrat Samples Detected Using Microsoft Dev Tunnels for C2 Connections
CybersecurityMalwareNjratMicrosoftDevTunnelsC2Serversngrok
New samples of Njrat have been detected using the Microsoft dev tunnels service to connect to their command and control (C2) servers. This service allows developers to securely expose local services to the Internet for testing, debugging, and collaboration, providing temporary, public, or private URLs. Dev tunnels create a secure temporary URL that maps to a local service running on the machine, work through firewalls and NAT, and their access can be restricted. This service is similar to ngrok.