FRP (Fast Reverse Proxy) is an open-source reverse proxy tool that has been observed used operationally by threat actors rather than being malware developed by a specific actor. The provided content states it is used by groups including Volt Typhoon, APT35, and in 2025 Ivanti EPMM intrusions attributed with high confidence by EclecticIQ to the China-nexus espionage group UNC5221. In the Ivanti Endpoint Manager Mobile (EPMM) compromises exploiting CVE-2025-4427 and CVE-2025-4428, attackers downloaded an FRP binary from attacker-controlled IP 103.244.88[.]125 on port 8080 and saved it as /tmp/.alog on compromised hosts. EclecticIQ assessed FRP was installed to provide reverse SOCKS5 proxying, enabling internal reconnaissance and lateral movement from the victim environment. Separate reporting in the content notes that FRP Dashboard infrastructure associated with attacker operations had a median observed lifespan of 12 days, indicating temporary operational use. High-confidence indicators mentioned in the content include the download source 103.244.88[.]125:8080 and the dropped file path /tmp/.alog.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct techniques documented for this family, organized by ATT&CK tactic.
3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
FRP (Fast Reverse Proxy) is a tool used to create reverse proxy tunnels, enabling attackers to access internal resources from outside the network.
FRP is an open-source reverse proxy tool used by threat actors to establish reverse SOCKS5 proxies, enabling persistent access, network reconnaissance, and lateral movement within compromised environments.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.