FRPC is the Fast Reverse Proxy Client component of the open-source FRP tunneling framework, a dual-use utility that threat actors frequently repurpose to establish reverse proxies from compromised hosts to attacker-controlled infrastructure. In intrusion operations, it is commonly used to bypass NAT and firewall boundaries, expose internal services to remote operators, and create covert access paths into victim environments. Observed malicious use includes tunneling Remote Desktop Protocol over TLS, exposing SOCKS proxy services, and maintaining durable remote access through scheduled tasks or service-based persistence.
FRPC has been used by multiple threat clusters, including Iranian-aligned actors tracked as PHOSPHORUS, Fox Kitten, Pioneer Kitten/UNC757, and TunnelVision, as well as in activity associated with Volt Typhoon. In these campaigns, FRPC typically appears after initial compromise through exploitation of internet-facing systems such as Microsoft Exchange, VPN appliances, or Log4j-exposed services. Operators then deploy FRPC to pivot into internal networks, enable hands-on-keyboard access, and support follow-on actions such as credential theft, lateral movement, ransomware deployment, or espionage.
Maliciously deployed FRPC samples are often modified, packed, renamed, or wrapped to blend into victim environments. Documented variants have used token-based authentication, TLS, compression, and multiple transport protocols, and some have been configured to contact both legitimate and lookalike destinations as a traffic-blending evasion technique. On Windows, attackers have persisted FRPC through scheduled tasks and masquerading binaries; ELF variants have also been observed, indicating cross-platform use. Although FRPC is not inherently malware and is a legitimate administrative tool, in adversary tradecraft it functions as a post-compromise tunneling backdoor that enables persistence, remote access, and internal network pivoting.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The threat actor is known to exploit Fortinet CVE-2018-13379, Exchange ProxyShell, and the log4j vulnerabilities. Thanks to Deep Instinct’s prevention capabilities the threat actor was unsuccessful in executing the payloads in a customer environment despite successful exploitation of the Exchange server. | task_update.exe is responsible for downloading FRPC from an attacker-controlled server, followed by a creation of a scheduled task to run the downloaded FRPC. FRPC stands for Fast Reverse Proxy Client; the downloaded FRPC is configured to connect to yet another attacker-controlled server, creating a tunnel between the attacker and the compromised system.
In addition to the windows FRPC variants, ELF variants were identified that were also used with log4j exploitation. ... The threat actor is known to exploit Fortinet CVE-2018-13379, Exchange ProxyShell, and the log4j vulnerabilities.
task_update.exe is responsible for downloading FRPC from an attacker-controlled server, followed by a creation of a scheduled task to run the downloaded FRPC. FRPC stands for Fast Reverse Proxy Client; the downloaded FRPC is configured to connect to yet another attacker-controlled server, creating a tunnel between the attacker and the compromised system.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
task_update.exe is responsible for downloading FRPC from an attacker-controlled server, followed by a creation of a scheduled task to run the downloaded FRPC. FRPC stands for Fast Reverse Proxy Client; the downloaded FRPC is configured to connect to yet another attacker-controlled server, creating a tunnel between the attacker and the compromised system.
When investigating one of the attacks, we identified that the attacker utilizes publicly available tools, such as FRPC... to enable Reverse Proxy in an infected machine.
The most commonly deployed tunneling tools used by the group are Fast Reverse Proxy Client (FRPC) and Plink.
"This packed file contains a compiled version of an open-source tool published on GitHub called \"FRPC\". The \"FRPC\" is a command-line tool written in Golang that is designed to open a reverse proxy between the compromised system and the TA's C2 server."
22 distinct techniques documented for this family, organized by ATT&CK tactic.
task_update.exe... is responsible for downloading FRPC from an attacker-controlled server, followed by a creation of a scheduled task to run the downloaded FRPC.
task_update.exe... is responsible for downloading FRPC from an attacker-controlled server, followed by a creation of a scheduled task to run the downloaded FRPC.
"packed using Ultimate Packer for Executables (UPX)"; "UPX compressed"; PE sections include "UPX0/UPX1/UPX2"
The hash of this root certificate file is b06c9d01cd4b89baa595f48736e6e31f2559381f1487f16304dde98ebd5e9d90 and it is impersonating Microsoft.
The threat actor used FRPC ( frpc.exe ) daily as reverse proxy, tunneling RDP over TLS. The FRPC ( frpc.exe ) task name was lpupdate and ran out of Input Method Editor (IME) directory. In other events, the threat actor has been observed hiding activity via ngrok.
The central component of the infrastructure is an HTTPS-accessible Command-and-Control (C2) server... Communication between the operator and the malicious application is carried out using standard web interfaces or APIs
FRPC stands for Fast Reverse Proxy Client; the downloaded FRPC is configured to connect to yet another attacker-controlled server, creating a tunnel between the attacker and the compromised system.
"APT41 used a tool called CLASSFON to covertly proxy network communications." / "BADCALL functions as a proxy server between the victim and C2 server." / "Sandworm Team's BCS-server tool can create an internal proxy server to redirect traffic..."
Symantec's published indicators point to a wider intrusion kit... FRPC for tunneling traffic out...
The threat actors exploited the ProxyShell and Log4j vulnerabilities to deploy TunnelFish, a custom Fast Reverse Proxy client (FRPC) variant and enable remote access to vulnerable systems.
The binary generates many connections to domains and subdomains of legitimate companies along with connection to visually similar subdomains that are attacker controlled.
One of the key elements is the launch of an FRP client (frpc — Fast Reverse Proxy Client), which establishes an outbound reverse-tunnel connection to an intermediary FRP server
The downloaded files were hosted on attacker-controlled sub-domain google.onedriver-srv[.]ml.
task_update.exe... is responsible for downloading FRPC from an attacker-controlled server...
54 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A named tool listed in the IoCs, commonly used for proxying or tunneling network traffic to support covert access or exfiltration.
A named tool listed in the IOCs. FRPC commonly refers to the Fast Reverse Proxy client, suggesting possible tunneling or remote connectivity use, though the content does not describe its role in this intrusion.
Weaponized FRPC is used by PHOSPHORUS to create reverse tunnels between compromised hosts and attacker-controlled infrastructure, enabling remote access such as RDP even when not directly exposed. Newer variants also blend malicious traffic with legitimate-looking domains to evade analysis.
A tunneling tool widely deployed by TunnelVision, often wrapped in a unique fashion during exploitation campaigns.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.