Title:Communication To LocaltoNet Tunneling Service Initiated - Linux Status:test Description:Detects an executable initiating a network connection to "LocaltoNet" tunneling sub-domains.
LocaltoNet is a reverse proxy that enables localhost services to be exposed to the Internet.
Attackers have been seen to use this service for command-and-control activities to bypass MFA and perimeter controls.
References: -https://localtonet.com/documents/supported-tunnels -https://cloud.google.com/blog/topics/threat-intelligence/unc3944-targets-saas-applications Author: Andreas Braathen (mnemonic.io) Date: 2024-06-17 modified:None Tags: