CowTunnel is a Linux-focused reverse proxy tunnel payload observed by Huntress in post-exploitation activity following exploitation of the critical React Server Components deserialization vulnerability CVE-2025-55182 (React2Shell), including against vulnerable Next.js deployments. It consists of a malicious wrapper called NSS and xfrpc version 2.9.644, an open-source Fast Reverse Proxy (FRP) client. CowTunnel initiates outbound connections to attacker-controlled FRP servers, allowing attackers to bypass firewalls that primarily monitor inbound connections. Reported decrypted configuration referenced FRP servers at 23.226.71[.]197:13306, 23.226.71[.]200:13306, and 23.226.71[.]209:13306 using the token "Nginx-1.22.1". Its capabilities include exposing compromised-host services and proxying traffic over telnet, SOCKS5, TCP, HTTP, FTP, and MSTSC, enabling remote access and network pivoting. Huntress identified a sample with SHA256 776850a1e6d6915e9bf35aa83554616129acd94e3a3f6673bd6ddaec530f4273. Detection content cited in the reporting includes YARA coverage for CowTunnel as a distinct Linux threat. The reporting ties CowTunnel to the broader React2Shell exploitation wave that affected multiple organizations, including construction and entertainment sectors, but does not attribute CowTunnel to a specific threat actor with high confidence.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
We also uncovered threat actors using a payload we call CowTunnel, which operates as a reverse proxy and initiates outbound connections to attacker-controlled FRP servers. | Huntress is seeing threat actors exploit a vulnerability in React Server Components (CVE-2025-55182) across several organizations... Dubbed “React2Shell”, CVE-2025-55182 exists due to insecure deserialization... and can be exploited by unauthenticated attackers merely by crafting one malicious HTTP request.
13 distinct techniques documented for this family, organized by ATT&CK tactic.
The payload, which we have named “ ZinFoq ” ... communicates with command-and-control infrastructure at “ api.qtss[.]cc ” over HTTPS using hex-encoded payloads
We also uncovered threat actors using a payload we call CowTunnel, which operates as a reverse proxy and initiates outbound connections to attacker-controlled FRP servers.
When executed on a compromised host, the payload initiates an outbound connection to attacker-controlled FRP servers. This outbound connection model is significant because most firewalls are configured to block inbound connections while allowing outbound traffic, enabling the tunnel to bypass perimeter defenses.
6 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Reverse proxy/tunneling tool delivered in React2Shell exploitation chains to provide covert connectivity.
A Linux ELF reverse-proxy tool (labeled as a distinct threat/hacktool) detected via YARA by unique strings related to functionality/persistence/debug messages.
Malware referenced as being involved in React2Shell exploitation; specific details not provided in the content.
Reverse proxy tool that connects to attacker-controlled FRP servers to bypass inbound-only firewall rules, enabling remote access to compromised systems.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.