Skip to main content
Meet us at Black Hat USA 2026— Las Vegas, August 1–6Book a Meeting
Mallory
MalwareUsed by 5 actors

IOX

IOX is a Go-written open-source port-forwarding and intranet proxy/tunneling tool used by threat actors to establish covert communication channels, reverse communication paths, and network pivoting inside compromised environments. Reporting in the provided content describes IOX being used alongside other tunneling utilities such as FRP/FRPS, GOST, Wstunnel, and SoftEther VPN to create SOCKS5 proxies, HTTPS tunnels, and port-forwarding paths to attacker-controlled infrastructure. It has been observed as an alternative proxy tool when other tooling failed, and in some cases as a customized variant.

The content associates IOX use with multiple China-aligned espionage clusters and campaigns. Unit 42 reported CL-STA-0048 using iox as an alternative proxy or port-forwarding tool after using Stowaway during intrusions targeting high-value organizations in South Asia, including a telecommunications entity, following exploitation attempts against IIS, Apache Tomcat/ColdFusion, and MSSQL servers. ESET reported Webworm continuing to use iox in 2025 together with frp and custom proxy tooling while targeting government entities in Belgium, Italy, Serbia, and Poland, as well as a university in South Africa. Trend Micro reported SHADOW-EARTH-053 using IOX Proxy with GOST and Wstunnel after exploiting unpatched Microsoft Exchange and IIS systems via the ProxyLogon chain and deploying ShadowPad in intrusions affecting government, defense-adjacent, transportation, technology, and critical infrastructure organizations across Asia, with at least one victim in Poland. Additional reporting in the content states Cinnamon Tempest used a customized version of the Iox port-forwarding and proxy tool. Unit 42 also listed IOX among tunneling utilities used by TGR-STA-1030/UNC6619 in the Shadow Campaigns, a large espionage operation targeting government and critical infrastructure organizations across 37 countries.

High-confidence behavior directly described in the content is limited to proxying and tunneling: IOX provides port forwarding and intranet proxy capability and is used to tunnel desired network traffic, maintain covert communications, and support attacker access within victim networks. No malware-specific persistence, payload delivery, or standalone indicators of compromise for IOX itself are provided in the content.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

THREAT ACTORS

Groups observed using it

5 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
Webworm

While the group continued to use existing proxy solutions, specifically the Go-written iox (port forwarding and intranet proxy tool) and frp (fast reverse proxy)

via eset welivesecurity blogwelivesecurity.com
Shadow-Earth-053

Observed tooling included IOX Proxy, GOST, Wstunnel, and multiple tunnel-core.exe variants. These tools established SOCKS5 proxies, HTTPS tunnels, and reverse communication channels to attacker infrastructure.

via polyswarmblog.polyswarm.io
Shadow-Earth-054

Observed tooling included IOX Proxy, GOST, Wstunnel, and multiple tunnel-core.exe variants. These tools established SOCKS5 proxies, HTTPS tunnels, and reverse communication channels to attacker infrastructure.

via polyswarmblog.polyswarm.io
Cinnamon Tempest

Cinnamon Tempest has used a customized version of the Iox port-forwarding and proxy tool.

via mitre attack websiteattack.mitre.org
TGR-STA-1030

“Network tunneling was achieved using GO Simple Tunnel (GOST), Fast Reverse Proxy Server (FRPS), and IOX.”

via rescana blogrescana.com
MITRE ATT&CK

Techniques & procedures

11 distinct techniques documented for this family, organized by ATT&CK tactic.

Resource Development

1 technique
T1588.002ToolEvidence1

The content repeatedly states that threat actors 'obtained,' 'acquired,' or 'used' publicly available, open-source, legitimate, or modified tools such as Mimikatz, Cobalt Strike, PsExec, Empire, Impacket, and many others.

Persistence

2 techniques
T1112Modify RegistryEvidence1

We observed the group leveraging the IOX proxy by creating local accounts and setting the LocalAccountTokenFilterPolicy value to 1.

T1136Create AccountEvidence1

We observed the group leveraging the IOX proxy by creating local accounts and setting the LocalAccountTokenFilterPolicy value to 1.

Defense Impairment

1 technique
T1112Modify RegistryEvidence1

We observed the group leveraging the IOX proxy by creating local accounts and setting the LocalAccountTokenFilterPolicy value to 1.

Lateral Movement

2 techniques
T1021.001Remote Desktop ProtocolEvidence2

$ proxychains rdesktop 192.168.0.100:3389 ... For example, we forward 3389 port in the intranet to our VPS

T1550.002Pass the HashEvidence1

This configuration grants full administrative privileges to remote connections from all local administrators... enabling lateral movement via Pass-the-Hash.

Command and Control

6 techniques
T1090ProxyEvidence6

The threat sideloaded the malicious DLLs to the legitimate binaries to load Stowaway, a multi-hop proxy tool... After failing to load the malicious DLLs, the threat actor tried to use another tool for the same purpose: iox, a port forward and intranet proxy tool.

T1090.002External ProxyEvidence1

Several entries mention use of proxy and tunneling tools including PLINK, Venom proxy, GOST reverse proxy, Ligolo, Cloudflared, rsocx reverse proxy, Iox proxy tool, NPS tunneling tool, and AirVPN.

T1090.003Multi-hop ProxyEvidence2

Observed tooling included IOX Proxy, GOST, Wstunnel, and multiple tunnel-core.exe variants. These tools established SOCKS5 proxies, HTTPS tunnels, and reverse communication channels to attacker infrastructure.

T1105Ingress Tool TransferEvidence2

The threat actor abused certutil to download the PlugX component from a remote domain... Once the threat actor gained a foothold inside the network, they attempted to upload additional tools.

T1572Protocol TunnelingEvidence1

“Network tunneling was achieved using GO Simple Tunnel (GOST), Fast Reverse Proxy Server (FRPS), and IOX.”

T1573Encrypted ChannelEvidence1

What's more, iox provides traffic encryption feature (it's useful when there is a IDS on target) ... traffic between be-controlled host and our VPS:8888 will be encrypted ... then encrypt with Xchacha20

INDICATORS OF COMPROMISE

IOCs tracked for this family

14 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.

View more in app
Hashes
14 tracked

File hashes (MD5, SHA-1, SHA-256) from samples and reports.

TypeValueLatest sighting
hash.sha1●●●●●●●●●●●●View more in app1 month ago
hash.sha256●●●●●●●●●●●●View more in app1 month ago
hash.sha256●●●●●●●●●●●●View more in app1 month ago
hash.sha256●●●●●●●●●●●●View more in app1 month ago
hash.sha256●●●●●●●●●●●●View more in app1 month ago
hash.sha256●●●●●●●●●●●●View more in app1 month ago
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching14

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution5

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping11

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.