It's a bit more pernicious than ngrok just because it's more difficult to isolate and block only malicious usage of the feature. But yeah I agree it's not breaking news that implants will find ways to tunnel out of your infrastructure when exfiltrating data...
Doesn't ngrok require a local config? This technique allows attackers to maintain a nonfunctional tunnel and enable functionality only when they want to engage with the victim machine, similar to TA569's SocGholish campaigns across news sites last year.