iox is a Go-based port-forwarding and intranet-proxy utility used after compromise to tunnel network traffic through victim environments. It supports TCP port forwarding, SOCKS5 proxying, reverse SOCKS5 proxying, chained relay paths, optional traffic encryption, and UDP forwarding. These functions enable operators to reach otherwise inaccessible internal systems, relay command-and-control traffic through compromised hosts, and obscure the apparent origin of attacker connections. iox has been used in cyberespionage intrusions by multiple China-aligned or China-nexus activity clusters, including CL-STA-0048, Webworm, SHADOW-EARTH-053, and TGR-STA-1030/UNC6619; Cinnamon Tempest has used a customized version. It has also been observed in post-exploitation activity following exploitation of exposed enterprise appliances and servers. Windows builds are detectable as a hacktool, including in file and memory scanning contexts.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
6 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The Cobalt Strike beacon was injected into an SQL server process, enabling C2 communication to deliver additional malware such as `Stowaway` and `iox` to tunnel network traffic through compromised systems.
While the group continued to use existing proxy solutions, specifically the Go-written iox (port forwarding and intranet proxy tool) and frp (fast reverse proxy)
Observed tooling included IOX Proxy, GOST, Wstunnel, and multiple tunnel-core.exe variants. These tools established SOCKS5 proxies, HTTPS tunnels, and reverse communication channels to attacker infrastructure.
Observed tooling included IOX Proxy, GOST, Wstunnel, and multiple tunnel-core.exe variants. These tools established SOCKS5 proxies, HTTPS tunnels, and reverse communication channels to attacker infrastructure.
Cinnamon Tempest has used a customized version of the Iox port-forwarding and proxy tool.
“Network tunneling was achieved using GO Simple Tunnel (GOST), Fast Reverse Proxy Server (FRPS), and IOX.”
15 distinct techniques documented for this family, organized by ATT&CK tactic.
The attacker established a proxy connection to 206.237.0[.]49 ... [and] Rakshasa ... creates a proxy tunnel to the threat actor infrastructure.
Several entries mention use of proxy and tunneling tools including PLINK, Venom proxy, GOST reverse proxy, Ligolo, Cloudflared, rsocx reverse proxy, Iox proxy tool, NPS tunneling tool, and AirVPN.
Observed tooling included IOX Proxy, GOST, Wstunnel, and multiple tunnel-core.exe variants. These tools established SOCKS5 proxies, HTTPS tunnels, and reverse communication channels to attacker infrastructure.
The threat actor abused certutil to download the PlugX component from a remote domain... Once the threat actor gained a foothold inside the network, they attempted to upload additional tools.
“Stowaway and iox [were used] to tunnel network traffic through compromised systems.”
Communications that are forwarded inside the victim's internal network are encrypted with symmetric encryption algorithm XChaCha20. This encryption is not meant to be a bullet-proof protection of the privacy of forwarded content, but an evasion technique against NIDS/NIPS.
23 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An existing Go-written port forwarding and intranet proxy tool used by Webworm as part of its proxy infrastructure.
A tunneling/proxy tool used to establish covert outbound communications, including SOCKS5 proxying and reverse channels, to maintain persistence and operational redundancy.
A proxy tool used to create covert communication channels within the intrusion.
Tunneling/pivoting tool used to route traffic and facilitate lateral movement within victim networks.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.