FRPC (Fast Reverse Proxy Client) is the Go-based client component of the open-source Fast Reverse Proxy (FRP) project. It is a legitimate, dual-use tunneling utility frequently deployed by threat actors, including in modified forms, to establish connections between compromised systems and attacker-controlled relay servers. It exposes services behind network address translation or firewalls, enabling remote access and pivoting into internal networks. Observed implementations support TCP, UDP, HTTP, HTTPS, SOCKS5 proxying, encryption, compression, and token-based authentication. Windows executables and Linux ELF variants have been used in malicious activity.
Attackers use FRPC to tunnel Remote Desktop Protocol over TLS, maintain remote access, and support lateral movement. Persistence is commonly established by separate installation tooling that schedules FRPC execution. Malicious deployments have masqueraded as legitimate system components, and some modified variants contact both legitimate services and attacker-controlled destinations to blend malicious communications into normal traffic. FRPC is typically installed after an initial compromise, including through exploited remote-access infrastructure, Microsoft Exchange, Apache ActiveMQ, and Log4j-vulnerable services; it is not itself the vulnerability-exploitation component.
FRPC has been used by Fox Kitten/Pioneer Kitten, PHOSPHORUS, TunnelVision, Earth Kurma, and Volt Typhoon. These deployments span espionage, persistent-access, and ransomware-associated operations affecting government, critical infrastructure, telecommunications, healthcare, financial services, and other enterprise environments. Its broad availability and use by unrelated actors make FRPC presence alone insufficient for attribution.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
공격자는 ActiveMQ 취약점을 악용하여 실행된 파워쉘 명령으로 Frpc 및 설정 파일을 설치하였다.
The threat actor is known to exploit Fortinet CVE-2018-13379, Exchange ProxyShell, and the log4j vulnerabilities. Thanks to Deep Instinct’s prevention capabilities the threat actor was unsuccessful in executing the payloads in a customer environment despite successful exploitation of the Exchange server. | task_update.exe is responsible for downloading FRPC from an attacker-controlled server, followed by a creation of a scheduled task to run the downloaded FRPC. FRPC stands for Fast Reverse Proxy Client; the downloaded FRPC is configured to connect to yet another attacker-controlled server, creating a tunnel between the attacker and the compromised system.
In addition to the windows FRPC variants, ELF variants were identified that were also used with log4j exploitation. ... The threat actor is known to exploit Fortinet CVE-2018-13379, Exchange ProxyShell, and the log4j vulnerabilities.
task_update.exe is responsible for downloading FRPC from an attacker-controlled server, followed by a creation of a scheduled task to run the downloaded FRPC. FRPC stands for Fast Reverse Proxy Client; the downloaded FRPC is configured to connect to yet another attacker-controlled server, creating a tunnel between the attacker and the compromised system.
5 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
“FRPC is a modified version of the open-source FRP tool.” The advisory states that it tunneled RDP over TLS, providing the actor with primary persistence.
Earth Kurma conducted lateral movement using several tools: NBTSCAN, LADON, FRPC, WMIHACKER and ICMPinger.
task_update.exe is responsible for downloading FRPC from an attacker-controlled server, followed by a creation of a scheduled task to run the downloaded FRPC. FRPC stands for Fast Reverse Proxy Client; the downloaded FRPC is configured to connect to yet another attacker-controlled server, creating a tunnel between the attacker and the compromised system.
The most commonly deployed tunneling tools used by the group are Fast Reverse Proxy Client (FRPC) and Plink.
"This packed file contains a compiled version of an open-source tool published on GitHub called \"FRPC\". The \"FRPC\" is a command-line tool written in Golang that is designed to open a reverse proxy between the compromised system and the TA's C2 server."
22 distinct techniques documented for this family, organized by ATT&CK tactic.
task_update.exe... is responsible for downloading FRPC from an attacker-controlled server, followed by a creation of a scheduled task to run the downloaded FRPC.
task_update.exe... is responsible for downloading FRPC from an attacker-controlled server, followed by a creation of a scheduled task to run the downloaded FRPC.
"packed using Ultimate Packer for Executables (UPX)"; "UPX compressed"; PE sections include "UPX0/UPX1/UPX2"
The hash of this root certificate file is b06c9d01cd4b89baa595f48736e6e31f2559381f1487f16304dde98ebd5e9d90 and it is impersonating Microsoft.
The central component of the infrastructure is an HTTPS-accessible Command-and-Control (C2) server... Communication between the operator and the malicious application is carried out using standard web interfaces or APIs
“frpc ... establishes a secure, persistent reverse tunnel, giving attackers access to the ADB daemon for command execution.”
"APT41 used a tool called CLASSFON to covertly proxy network communications." / "BADCALL functions as a proxy server between the victim and C2 server." / "Sandworm Team's BCS-server tool can create an internal proxy server to redirect traffic..."
Symantec's published indicators point to a wider intrusion kit... FRPC for tunneling traffic out...
The threat actors exploited the ProxyShell and Log4j vulnerabilities to deploy TunnelFish, a custom Fast Reverse Proxy client (FRPC) variant and enable remote access to vulnerable systems.
The binary generates many connections to domains and subdomains of legitimate companies along with connection to visually similar subdomains that are attacker controlled.
One of the key elements is the launch of an FRP client (frpc — Fast Reverse Proxy Client), which establishes an outbound reverse-tunnel connection to an intermediary FRP server
The downloaded files were hosted on attacker-controlled sub-domain google.onedriver-srv[.]ml.
task_update.exe... is responsible for downloading FRPC from an attacker-controlled server...
54 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A named tool listed in the IoCs, commonly used for proxying or tunneling network traffic to support covert access or exfiltration.
A named tool listed in the IOCs. FRPC commonly refers to the Fast Reverse Proxy client, suggesting possible tunneling or remote connectivity use, though the content does not describe its role in this intrusion.
Legitimate Go-based reverse-proxy client explicitly weaponized in this intrusion. The attacker installed it through commands executed by vulnerable ActiveMQ to expose the victim's RDP service on port 3389 through an external relay. Researchers assessed that the relay was another compromised South Korean system running the Frps server component. It enabled access using attacker-created backdoor accounts; no modification of the proxy software itself was reported.
A port-forwarding tool explicitly abused in the first attack as part of the remote-access infrastructure.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.