Fast Reverse Proxy (FRP) is a legitimate open-source reverse-proxy and tunneling tool widely abused to maintain remote access and relay command-and-control traffic during intrusions. Its client establishes an outbound connection to a relay server, exposing local services behind NAT or firewalls without requiring direct inbound access. Attackers commonly use it to tunnel Remote Desktop Protocol traffic, bypass inbound network restrictions, and conceal their originating addresses. FRP supports TLS-protected connections, connections through an upstream proxy, and configuration-driven operation. Both standard clients and customized builds with embedded configuration or hardcoded callbacks have been deployed on Windows and Linux.
FRP is typically introduced after an initial compromise rather than functioning as an initial-access payload. Observed deployments follow exploitation of public-facing applications and web-shell access, with scheduled tasks used to maintain persistent execution. Its use spans espionage and financially motivated operations, including activity associated with Volt Typhoon, APT35, COBALT MIRAGE, ChamelGang, Hydrochasma, Webworm, z0Miner, and TeamPCP. COBALT MIRAGE uses both unmodified clients and a modified variant known as TunnelFish. FRP has appeared in intrusions affecting critical infrastructure, government, energy, aviation, shipping, medical laboratories, and cloud environments. These associations reflect broad abuse of a general-purpose networking utility, not exclusive attribution to any actor or inherent maliciousness.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
It is worth noting that some of the more recent methods that were observed in attacks attributed to the Phosphorus group included open-source tools such as the famous DiskCryptor library and also BitLocker, along with the Fast Reverse Proxy which is used for RDP proxying.
Trend™ Research observed that CVE-2025-55182, as of this writing, is being exploited in-the-wild, and in several malware campaigns such as the emerald and nuts campaigns. ... CVE-2025-55182, which is a critical (CVSS 10.0) pre-authentication remote code execution vulnerability affecting React Server Components (RSC) used in React.js, Next.js, and related frameworks.
13 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The attackers ... [used] known malicious programs such as FRP, Cobalt Strike Beacon, and Tiny Shell.
The actor has used Earthworm and a custom Fast Reverse Proxy (FRP) client with hardcoded C2 callbacks to ports 8080, 8443, 8043, 8000, and 10443.
The z0Miner threat actor used both the default Frpc and the customized version.
It is worth noting that some of the more recent methods that were observed in attacks attributed to the Phosphorus group included open-source tools such as the famous DiskCryptor library and also BitLocker, along with the Fast Reverse Proxy which is used for RDP proxying.
Following initial access on one machine, the attackers were seen dropping Fast Reverse Proxy (FRP), a tool that can expose a local server that is sitting behind an NAT or firewall to the internet.
COBALT MIRAGE's preferred form of remote access uses the Fast Reverse Proxy (FRPC) tool. While COBALT MIRAGE Cluster A uses a modified version of this tool known as TunnelFish, Cluster B favors the unaltered version.
25 distinct techniques documented for this family, organized by ATT&CK tactic.
Persistence was established for the FRP via scheduled tasks on the domain controller.
Persistence was established for the FRP via scheduled tasks on the domain controller.
For persistence, the threat actor registers their reverse proxies as scheduled tasks, causing the reverse proxy to execute approximately every 20 minutes to communicate with the attacker’s C2 servers.
Volexity detected a system running frp, otherwise known as fast reverse proxy, and subsequently detected internal port scanning shortly afterward.
Shared IOCs with Memento Ransomware: One of the IP addresses serves a domain which is being used as command and control (C2) for the recently discovered Memento Ransomware.
The actor has used Earthworm and a custom Fast Reverse Proxy (FRP) client with hardcoded C2 callbacks [T1090].
Figure 15 displays the reverse SOCKS proxy activity on the infected device using the open-source tool FRP.
The FRP client can be configured to connect to the server through a proxy. The server component of SystemBC has used SOCKS5 for C2 communication. Keydnap uses a copy of tor2web proxy for HTTPS communications.
MITRE ATT&CK Techniques Command and Control T1090.003 Proxy: Multi-hop Proxy
MITRE ATT&CK Techniques Command and Control T1105 Ingress Tool Transfer
27 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
51 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A fast reverse proxy utility used by Webworm and also serving as the inspiration/base for the custom WormFrp tool.
FRP is used by the toolkit as an embedded reverse proxy component to create tunnels for RDP and a raw TCP shell back to the operator-controlled server. In this case it is wrapped in a .NET loader, decrypted with AES-256-CBC, and loaded in memory via manual PE mapping.
Reverse proxy utility used to provide persistent remote access/tunneling into victim environments.
Reverse proxy/tunneling utility used to establish covert connectivity (including C2-style access) and bypass network controls; observed here in modified builds.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.