WormFrp is a custom proxy tunneling tool used by the China-aligned APT group Webworm, also tracked as Space Pirates and UAT-8302. It is described as a proxy tool inspired by the open-source Fast Reverse Proxy (frp) utility, and analysis of a garble-obfuscated Go PE showed retained FRP-internal log literals together with garble obfuscation artifacts, enabling differentiation from vanilla github.com/fatedier/frp via YARA. Webworm used WormFrp as part of an expanded proxy toolset alongside ChainWorm, SmuxProxy, and WormSocket, and ESET assessed the breadth of these proxy tools suggests the group may be building a larger covert proxy network from compromised systems. High-confidence reporting states WormFrp retrieved AES-encrypted configuration files from a compromised AWS S3 bucket at wamanharipethe.s3.ap-south-1.amazonaws[.]com, and that the same bucket was likely also used for data exfiltration; between December 2025 and January 2026, Webworm uploaded 20 files there, including files stolen from government entities in Spain and artifacts related to an Italian governmental machine. A reported WormFrp sample was distributed as ssh.exe, detected by ESET as WinGo/HackTool.Proxy.AE, with SHA-1 1DF40A4A31B30B62EC33DC6FECC2C4408302ADC7. Associated infrastructure includes 108.61.200[.]151, identified as a WormFrp proxy server and first seen on 2025-04-10. The malware is associated with Webworm operations targeting government organizations in Belgium, Italy, Poland, Serbia, and Spain, as well as activity involving a university in South Africa.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
A YARA rule that tells WormFrp apart from vanilla FRP. Strings extraction on the on-disk garble-obfuscated Go PE surfaced both (a) FRP-internal log literals shared with vanilla github.com/fatedier/frp and (b) garble obfuscation artifacts.
The group expanded its use of proxy tools. Existing proxy capabilities were supplemented with custom tools including WormFrp, ChainWorm, SmuxProxy, and WormSocket. During the investigation, ESET discovered that Webworm had started using WormFrp to retrieve configurations from a compromised AWS S3 bucket.
The group expanded its use of proxy tools. Existing proxy capabilities were supplemented with custom tools including WormFrp, ChainWorm, SmuxProxy, and WormSocket. During the investigation, ESET discovered that Webworm had started using WormFrp to retrieve configurations from a compromised AWS S3 bucket.
9 distinct techniques documented for this family, organized by ATT&CK tactic.
WormFrp proxy tool. ... ChainWorm proxy tool. ... WormSocket proxy tool. ... SmuxProxy, a custom iox with hardcoded IP.
WormFrp, ChainWorm, WormSocket, SmuxProxy, and GraphWorm have the capability to connect to external proxies.
These custom proxy tools are not only capable of encrypting communications, but also support chaining across multiple hosts both internally and externally to a network
During the investigation, ESET discovered that Webworm had started using WormFrp to retrieve configurations from a compromised AWS S3 bucket. “It is apparent that through this S3 bucket, Webworm can leverage data exfiltration while an unsuspecting victim foots the bill for the service,” Howard said.
3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A custom proxy tunneling tool derived from frp that retrieves encrypted configuration data from a compromised Amazon S3 bucket and opens reverse proxy and TCP SOCKS5 proxy connections.
A custom proxy tool used by Webworm, including for retrieving configurations from a compromised AWS S3 bucket and supporting hidden network/proxy infrastructure.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.