iox is a Go-based open-source tunneling utility used for port forwarding, intranet pivoting, and proxying in post-compromise operations. It is commonly positioned as an alternative to HTran/lcx and Earthworm, with support for SOCKS5 proxying, reverse SOCKS-style tunneling, port forwarding, optional traffic encryption, and UDP forwarding. Its design enables operators to relay traffic through compromised hosts, obscure the true origin of attacker communications, and maintain covert access paths into segmented internal networks.
The tool has been observed in intrusion sets as a practical post-exploitation enabler rather than as a standalone initial-access payload. Reported use includes deployment on internet-facing appliances and servers to preserve access after exploitation, establish covert communication channels, and support lateral movement or follow-on operations. Optional encryption of forwarded traffic, including use of XChaCha20 in some reporting, is intended to reduce visibility to network monitoring and intrusion prevention systems. Investigations have also noted obfuscated builds and customized variants, indicating that operators may modify the tool for stealth or operational fit.
iox has been associated with multiple espionage and intrusion clusters, particularly China-aligned activity. It has been reported in operations involving Webworm, SHADOW-EARTH-053, Cinnamon Tempest, and other clusters using commodity tunneling ecosystems alongside tools such as GOST, FRP, Wstunnel, Earthworm, and reGeorg-derived utilities. In these campaigns, iox typically serves as a lightweight proxy and pivot mechanism on compromised Windows systems or edge appliances, helping attackers traverse network boundaries, maintain persistence of access, and conceal command-and-control routing.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
While the group continued to use existing proxy solutions, specifically the Go-written iox (port forwarding and intranet proxy tool) and frp (fast reverse proxy)
Observed tooling included IOX Proxy, GOST, Wstunnel, and multiple tunnel-core.exe variants. These tools established SOCKS5 proxies, HTTPS tunnels, and reverse communication channels to attacker infrastructure.
Observed tooling included IOX Proxy, GOST, Wstunnel, and multiple tunnel-core.exe variants. These tools established SOCKS5 proxies, HTTPS tunnels, and reverse communication channels to attacker infrastructure.
Cinnamon Tempest has used a customized version of the Iox port-forwarding and proxy tool.
“Network tunneling was achieved using GO Simple Tunnel (GOST), Fast Reverse Proxy Server (FRPS), and IOX.”
14 distinct techniques documented for this family, organized by ATT&CK tactic.
We found the threat actors attempting to build reverse tunnels with the following tools for persistent control access to compromised machines
Several entries mention use of proxy and tunneling tools including PLINK, Venom proxy, GOST reverse proxy, Ligolo, Cloudflared, rsocx reverse proxy, Iox proxy tool, NPS tunneling tool, and AirVPN.
Observed tooling included IOX Proxy, GOST, Wstunnel, and multiple tunnel-core.exe variants. These tools established SOCKS5 proxies, HTTPS tunnels, and reverse communication channels to attacker infrastructure.
The threat actor abused certutil to download the PlugX component from a remote domain... Once the threat actor gained a foothold inside the network, they attempted to upload additional tools.
“Network tunneling was achieved using GO Simple Tunnel (GOST), Fast Reverse Proxy Server (FRPS), and IOX.”
Communications that are forwarded inside the victim's internal network are encrypted with symmetric encryption algorithm XChaCha20. This encryption is not meant to be a bullet-proof protection of the privacy of forwarded content, but an evasion technique against NIDS/NIPS.
20 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An existing Go-written port forwarding and intranet proxy tool used by Webworm as part of its proxy infrastructure.
A tunneling/proxy tool used to establish covert outbound communications, including SOCKS5 proxying and reverse channels, to maintain persistence and operational redundancy.
A proxy tool used to create covert communication channels within the intrusion.
Tunneling/pivoting tool used to route traffic and facilitate lateral movement within victim networks.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.