FRP

MITRE ATT&CK: S1144 View on attack.mitre.org

Aliases: FRP

Malware type
backdoor
Operating systems
linux, macos, windows
Related IoCs
12 (12 malicious)
Last IoC activity
2026-07-30 21:44:39
Profile updated
2026-07-07 13:18:41

Context

FRP, which stands for Fast Reverse Proxy, is an openly available tool that is capable of exposing a server located behind a firewall or Network Address Translation (NAT) to the Internet. FRP can support multiple protocols including TCP, UDP, and HTTP(S) and has been abused by threat actors to proxy command and control communications.

Recent IoC activity

12 malicious indicators in Maltiverse are attributed to FRP (S1144). The 12 most recently updated:

TypeIndicatorUpdatedSources
file sample file 2026-07-30 2
file sample 2026-06-12_92bc3b1ba378c14e601c4e617ec7c422_hive 2026-07-13 3
file sample frpc.exe 2026-06-29 3
file sample SecuriteInfo.com.Win64.MalwareX-gen.48495117 2026-06-18 2
file sample 73b2c01ca7f082bf4d999426e07886144b7bccaecead90e1acf661695fda39b1.bin 2026-06-11 3
file sample frpc.exe 2026-06-11 2
file sample 96103cf8fce293e362b32497b8e9c2c7c091ddf75f77ee9c15b467722e895bd2 2026-06-01 1
file sample frpc.exe 2026-03-21 1
file sample frps.exe 2026-03-21 1
file sample frpc.exe 2026-03-21 2
file sample frp_0.60.0-HAYFRP_windows_amd64.zip 2025-11-24 1
file sample 1 2025-08-06 1

Detection coverage

  • 129 Sigma rules

Malware & tools used

  • Non-Application Layer Protocol (attack-pattern)
  • JavaScript (attack-pattern)
  • Proxy (attack-pattern)
  • Protocol Tunneling (attack-pattern)
  • Asymmetric Cryptography (attack-pattern)
  • Network Service Discovery (attack-pattern)
  • System Network Connections Discovery (attack-pattern)
  • Multi-hop Proxy (attack-pattern)
  • Symmetric Cryptography (attack-pattern)
  • Web Protocols (attack-pattern)

Used by threat actors

  • Indian Critical Infrastructure Intrusions (campaign)
  • 3CX Supply Chain Attack (campaign)
  • Operation AkaiRyū (campaign)
  • Blue Mockingbird (threat-actor)
  • Magic Hound (threat-actor)
  • Volt Typhoon (threat-actor)

Reports & references

  • redcanary.com — Blue Mockingbird Cryptominer (report)
  • media.defense.gov — Csa Living Off The Land (report)
  • MITRE ATT&CK — S1144 (report)
  • github.com — Frp (report)
  • thedfirreport.com — Exchange Exploit Leads To Domain Wide Ransomware (report)

External references