frps is the Fast Reverse Proxy server component referenced in the reporting as a tunneling and proxy tool used by TeamPCP during post-compromise operations in containerized environments. Elastic Security Labs documented TeamPCP using frps alongside gost to establish persistent tunnels, proxy traffic through compromised containers, expose internal services, and maintain reliable external access. In the modeled TeamPCP container attack chain, use of frps appears after initial compromise and environment discovery as part of command-and-control and persistence-enabling activity rather than as an initial access vector. The activity is associated with TeamPCP’s broader cloud-native intrusion operations affecting container and Kubernetes environments, including campaigns tied to the Trivy supply chain compromise (CVE-2026-33634). The content specifically highlights execution of tunneling tools such as frps inside containers as uncommon for legitimate workloads and therefore useful as a detection signal. No standalone indicators of compromise specific to frps beyond its observed use as a process/tool name are provided in the content.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Tunneling tools: TeamPCP uses frps (fast reverse proxy) and gost for establishing persistent tunnels and proxying through compromised container environments
6 distinct techniques documented for this family, organized by ATT&CK tactic.
TeamPCP uses frps (fast reverse proxy) and gost for establishing persistent tunnels and proxying through compromised container environments
Filename: Audio.exe or frpc.exe... Note: Identical to “frpc.exe”... Filename: Frps.exe... Note: Identical to “frps.exe”
One of the key elements is the launch of an FRP client (frpc — Fast Reverse Proxy Client), which establishes an outbound reverse-tunnel connection to an intermediary FRP server
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Used by TeamPCP to establish persistent tunnels and proxy traffic through compromised container environments.
Tunneling/proxy tooling used to expose internal services and maintain external access from compromised containers.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.