FRP, short for Fast Reverse Proxy, is a legitimate open-source reverse proxy and tunneling utility that adversaries frequently repurpose to provide covert remote access to compromised systems. It is designed to expose internal services located behind NAT or firewall boundaries to externally reachable infrastructure, and supports encrypted transport including TLS as well as multiple transport protocols such as TCP, UDP, QUIC, KCP, and stream multiplexing. In intrusion operations, FRP is commonly deployed after initial compromise to establish persistent command-and-control paths, tunnel RDP or other internal services, bypass network segmentation and perimeter controls, and support operator hands-on-keyboard activity.
Threat actors have used both unmodified and custom-compiled FRP clients and servers across Windows and Linux environments. Observed modifications include hardcoded callback settings, embedded or manually mapped FRP components, altered authentication or proxy naming conventions, and wrapper binaries intended to evade detection or simplify deployment. FRP has been associated with a wide range of espionage and intrusion clusters, including Iranian, Chinese, and other state-linked or unattributed actors such as APT35, Volt Typhoon, COBALT MIRAGE, Webworm, Hydrochasma, CL-UNK-1068, and TeamPCP. It has also appeared in campaigns targeting critical infrastructure, government, telecommunications, healthcare, shipping, medical laboratories, cloud environments, and cryptocurrency organizations.
Operationally, FRP is most often used as post-compromise infrastructure rather than as a self-contained malware family. Adversaries deploy it to maintain persistence, proxy command-and-control traffic, relay RDP sessions, and enable lateral movement or follow-on tooling while blending in with legitimate administrative traffic. Because it is a benign dual-use tool with broad legitimate adoption, malicious use is typically distinguished by context such as unauthorized tunneling, suspicious persistence mechanisms, or coupling with other malware and credential theft activity.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Trend™ Research observed that CVE-2025-55182, as of this writing, is being exploited in-the-wild, and in several malware campaigns such as the emerald and nuts campaigns. ... CVE-2025-55182, which is a critical (CVSS 10.0) pre-authentication remote code execution vulnerability affecting React Server Components (RSC) used in React.js, Next.js, and related frameworks.
10 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Following initial access on one machine, the attackers were seen dropping Fast Reverse Proxy (FRP), a tool that can expose a local server that is sitting behind an NAT or firewall to the internet.
COBALT MIRAGE's preferred form of remote access uses the Fast Reverse Proxy (FRPC) tool. While COBALT MIRAGE Cluster A uses a modified version of this tool known as TunnelFish, Cluster B favors the unaltered version.
We found the FRP tool being used on a Linux host, which is similar to Avast’s findings in a report that they published on the Iron Tiger threat actor. The FRP tool that we analyzed was a modified version, which was possibly copied off of Github.
While the group continued to use existing proxy solutions, specifically the Go-written iox (port forwarding and intranet proxy tool) and frp (fast reverse proxy)
FRP (Fast Reverse Proxy) is used to create reverse proxy tunnels, providing persistent remote access to compromised systems...
...using a mix of custom and public tools such as Microsocks, FRP, FScan, and Responder...
25 distinct techniques documented for this family, organized by ATT&CK tactic.
Finally, the loader creates a scheduled task for FRP, of course while being dependent on the OS type.
The FRP client is deployed with a self-installing persistence mechanism via the start.sh launcher... installs itself into crontab... The FRP client is restarted by cron every minute if the process dies.
For persistence, the threat actor registers their reverse proxies as scheduled tasks, causing the reverse proxy to execute approximately every 20 minutes to communicate with the attacker’s C2 servers.
Finally, the loader creates a scheduled task for FRP, of course while being dependent on the OS type.
The FRP client is deployed with a self-installing persistence mechanism via the start.sh launcher... installs itself into crontab... The FRP client is restarted by cron every minute if the process dies.
For persistence, the threat actor registers their reverse proxies as scheduled tasks, causing the reverse proxy to execute approximately every 20 minutes to communicate with the attacker’s C2 servers.
Finally, the loader creates a scheduled task for FRP, of course while being dependent on the OS type.
The FRP client is deployed with a self-installing persistence mechanism via the start.sh launcher... installs itself into crontab... The FRP client is restarted by cron every minute if the process dies.
The content repeatedly describes threat actors and malware using HTTP and HTTPS for command and control, such as: "Sandworm Team used BlackEnergy to communicate between compromised hosts and their command-and-control servers via HTTP post requests."
Following initial access on one machine, the attackers were seen dropping Fast Reverse Proxy (FRP), a tool that can expose a local server that is sitting behind an NAT or firewall to the internet.
The attacker used various tools for different purposes: collecting information for infiltration, port forwarding for establishing an external connection...
The FRP client can be configured to connect to the server through a proxy. The server component of SystemBC has used SOCKS5 for C2 communication. Keydnap uses a copy of tor2web proxy for HTTPS communications.
MITRE ATT&CK Techniques Command and Control T1090.003 Proxy: Multi-hop Proxy
20 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
45 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A fast reverse proxy utility used by Webworm and also serving as the inspiration/base for the custom WormFrp tool.
FRP is used by the toolkit as an embedded reverse proxy component to create tunnels for RDP and a raw TCP shell back to the operator-controlled server. In this case it is wrapped in a .NET loader, decrypted with AES-256-CBC, and loaded in memory via manual PE mapping.
Reverse proxy utility used to provide persistent remote access/tunneling into victim environments.
Reverse proxy/tunneling utility used to establish covert connectivity (including C2-style access) and bypass network controls; observed here in modified builds.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.