FRP
MITRE ATT&CK: S1144 View on attack.mitre.org
Aliases: FRP
- Malware type
- backdoor
- Operating systems
- linux, macos, windows
- Related IoCs
- 12 (12 malicious)
- Last IoC activity
- 2026-07-30 21:44:39
- Profile updated
- 2026-07-07 13:18:41
Context
FRP, which stands for Fast Reverse Proxy, is an openly available tool that is capable of exposing a server located behind a firewall or Network Address Translation (NAT) to the Internet. FRP can support multiple protocols including TCP, UDP, and HTTP(S) and has been abused by threat actors to proxy command and control communications.
Recent IoC activity
12 malicious indicators in Maltiverse are attributed to FRP (S1144). The 12 most recently updated:
| Type | Indicator | Updated | Sources |
|---|---|---|---|
| file sample | file | 2026-07-30 | 2 |
| file sample | 2026-06-12_92bc3b1ba378c14e601c4e617ec7c422_hive | 2026-07-13 | 3 |
| file sample | frpc.exe | 2026-06-29 | 3 |
| file sample | SecuriteInfo.com.Win64.MalwareX-gen.48495117 | 2026-06-18 | 2 |
| file sample | 73b2c01ca7f082bf4d999426e07886144b7bccaecead90e1acf661695fda39b1.bin | 2026-06-11 | 3 |
| file sample | frpc.exe | 2026-06-11 | 2 |
| file sample | 96103cf8fce293e362b32497b8e9c2c7c091ddf75f77ee9c15b467722e895bd2 | 2026-06-01 | 1 |
| file sample | frpc.exe | 2026-03-21 | 1 |
| file sample | frps.exe | 2026-03-21 | 1 |
| file sample | frpc.exe | 2026-03-21 | 2 |
| file sample | frp_0.60.0-HAYFRP_windows_amd64.zip | 2025-11-24 | 1 |
| file sample | 1 | 2025-08-06 | 1 |
Detection coverage
- 129 Sigma rules
Malware & tools used
- Non-Application Layer Protocol (attack-pattern)
- JavaScript (attack-pattern)
- Proxy (attack-pattern)
- Protocol Tunneling (attack-pattern)
- Asymmetric Cryptography (attack-pattern)
- Network Service Discovery (attack-pattern)
- System Network Connections Discovery (attack-pattern)
- Multi-hop Proxy (attack-pattern)
- Symmetric Cryptography (attack-pattern)
- Web Protocols (attack-pattern)
Used by threat actors
- Indian Critical Infrastructure Intrusions (campaign)
- 3CX Supply Chain Attack (campaign)
- Operation AkaiRyū (campaign)
- Blue Mockingbird (threat-actor)
- Magic Hound (threat-actor)
- Volt Typhoon (threat-actor)
Reports & references
- redcanary.com — Blue Mockingbird Cryptominer (report)
- media.defense.gov — Csa Living Off The Land (report)
- MITRE ATT&CK — S1144 (report)
- github.com — Frp (report)
- thedfirreport.com — Exchange Exploit Leads To Domain Wide Ransomware (report)