FRPC (Fast Reverse Proxy Client) is the client component of the open-source Fast Reverse Proxy (FRP) tunneling utility. It establishes reverse-proxy connections from hosts behind NAT or firewalls to an operator-controlled FRP server, enabling remote access to otherwise non-public internal services. FRPC supports TCP, UDP, HTTP, and HTTPS transports, and can use encryption, compression, TLS, token-based authentication, and SOCKS proxy functionality.
Threat actors commonly deploy FRPC after obtaining access to create persistent remote-access tunnels, expose Remote Desktop Protocol services, pivot into internal networks, and facilitate lateral movement. It has been used by Iranian-linked clusters including Fox Kitten/Pioneer Kitten, PHOSPHORUS-associated activity, and TunnelVision, as well as by Earth Kurma and Volt Typhoon. In documented intrusions, operators have downloaded FRPC to compromised Windows systems and configured scheduled-task execution to maintain the tunnel. Modified FRPC variants have also used benign-looking and attacker-controlled connection endpoints to blend tunnel traffic into ordinary network activity. FRPC is legitimate dual-use software rather than a purpose-built malware family.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The threat actor is known to exploit Fortinet CVE-2018-13379, Exchange ProxyShell, and the log4j vulnerabilities. Thanks to Deep Instinct’s prevention capabilities the threat actor was unsuccessful in executing the payloads in a customer environment despite successful exploitation of the Exchange server. | task_update.exe is responsible for downloading FRPC from an attacker-controlled server, followed by a creation of a scheduled task to run the downloaded FRPC. FRPC stands for Fast Reverse Proxy Client; the downloaded FRPC is configured to connect to yet another attacker-controlled server, creating a tunnel between the attacker and the compromised system.
In addition to the windows FRPC variants, ELF variants were identified that were also used with log4j exploitation. ... The threat actor is known to exploit Fortinet CVE-2018-13379, Exchange ProxyShell, and the log4j vulnerabilities.
task_update.exe is responsible for downloading FRPC from an attacker-controlled server, followed by a creation of a scheduled task to run the downloaded FRPC. FRPC stands for Fast Reverse Proxy Client; the downloaded FRPC is configured to connect to yet another attacker-controlled server, creating a tunnel between the attacker and the compromised system.
5 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Earth Kurma conducted lateral movement using several tools: NBTSCAN, LADON, FRPC, WMIHACKER and ICMPinger.
task_update.exe is responsible for downloading FRPC from an attacker-controlled server, followed by a creation of a scheduled task to run the downloaded FRPC. FRPC stands for Fast Reverse Proxy Client; the downloaded FRPC is configured to connect to yet another attacker-controlled server, creating a tunnel between the attacker and the compromised system.
When investigating one of the attacks, we identified that the attacker utilizes publicly available tools, such as FRPC... to enable Reverse Proxy in an infected machine.
The most commonly deployed tunneling tools used by the group are Fast Reverse Proxy Client (FRPC) and Plink.
"This packed file contains a compiled version of an open-source tool published on GitHub called \"FRPC\". The \"FRPC\" is a command-line tool written in Golang that is designed to open a reverse proxy between the compromised system and the TA's C2 server."
22 distinct techniques documented for this family, organized by ATT&CK tactic.
task_update.exe... is responsible for downloading FRPC from an attacker-controlled server, followed by a creation of a scheduled task to run the downloaded FRPC.
task_update.exe... is responsible for downloading FRPC from an attacker-controlled server, followed by a creation of a scheduled task to run the downloaded FRPC.
"packed using Ultimate Packer for Executables (UPX)"; "UPX compressed"; PE sections include "UPX0/UPX1/UPX2"
The hash of this root certificate file is b06c9d01cd4b89baa595f48736e6e31f2559381f1487f16304dde98ebd5e9d90 and it is impersonating Microsoft.
The threat actor used FRPC ( frpc.exe ) daily as reverse proxy, tunneling RDP over TLS. The FRPC ( frpc.exe ) task name was lpupdate and ran out of Input Method Editor (IME) directory. In other events, the threat actor has been observed hiding activity via ngrok.
The central component of the infrastructure is an HTTPS-accessible Command-and-Control (C2) server... Communication between the operator and the malicious application is carried out using standard web interfaces or APIs
“frpc ... establishes a secure, persistent reverse tunnel, giving attackers access to the ADB daemon for command execution.”
"APT41 used a tool called CLASSFON to covertly proxy network communications." / "BADCALL functions as a proxy server between the victim and C2 server." / "Sandworm Team's BCS-server tool can create an internal proxy server to redirect traffic..."
Symantec's published indicators point to a wider intrusion kit... FRPC for tunneling traffic out...
The threat actors exploited the ProxyShell and Log4j vulnerabilities to deploy TunnelFish, a custom Fast Reverse Proxy client (FRPC) variant and enable remote access to vulnerable systems.
The binary generates many connections to domains and subdomains of legitimate companies along with connection to visually similar subdomains that are attacker controlled.
One of the key elements is the launch of an FRP client (frpc — Fast Reverse Proxy Client), which establishes an outbound reverse-tunnel connection to an intermediary FRP server
The downloaded files were hosted on attacker-controlled sub-domain google.onedriver-srv[.]ml.
task_update.exe... is responsible for downloading FRPC from an attacker-controlled server...
54 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A named tool listed in the IoCs, commonly used for proxying or tunneling network traffic to support covert access or exfiltration.
A named tool listed in the IOCs. FRPC commonly refers to the Fast Reverse Proxy client, suggesting possible tunneling or remote connectivity use, though the content does not describe its role in this intrusion.
Weaponized FRPC is used by PHOSPHORUS to create reverse tunnels between compromised hosts and attacker-controlled infrastructure, enabling remote access such as RDP even when not directly exposed. Newer variants also blend malicious traffic with legitimate-looking domains to evade analysis.
A tunneling tool widely deployed by TunnelVision, often wrapped in a unique fashion during exploitation campaigns.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.