CobaltMirage FRP is a sophisticated backdoor and tunneling malware family first documented by Trend Micro in August 2023, believed to be operated by Chinese state‑sponsored threat actors (likely APT41 or TA428) and categorized as a Remote Access Trojan (RAT) that leverages the legitimate open‑source tool Fast Reverse Proxy (FRP) for covert command‑and‑control communications.
The malware uses FRP (Fast Reverse Proxy, version 0.47.0 observed in samples) to create encrypted tunnels from compromised hosts to attacker‑controlled servers, enabling bidirectional traffic that mimics legitimate web traffic and bypasses network firewalls. Persistence is achieved through scheduled tasks (e.g., MicrosoftWindowsUpdatefrp) or registry Run keys pointing to a renamed frpc.exe binary. Evasion techniques include packing the FRP client with UPX or custom packers, using domain fronting via CDN providers, and embedding C2 domains within encrypted configuration files. The malware supports multiple proxy modes—TCP, UDP, HTTP—and can dynamically change listening ports based on configuration (commonly ports 80, 443, 8080, or 8888). Lateral movement is facilitated through exported network shares and PowerShell scripts that deploy the FRP payload to adjacent hosts.
First identified in early 2023 during an intrusion targeting a Southeast Asian telecommunications firm, CobaltMirage FRP was later used in a December 2023 campaign against government ministries in Mongolia, as reported by Cisco Talos. No specific CVEs are associated with the malware itself, but it is frequently delivered via exploiting CVE‑2023‑34362 (MOVEit Transfer) or phishing emails containing malicious LNK files. The operator group, tracked as Earth Estries by Trend Micro, has been active since at least 2020 and primarily targets telecommunications, government, and education sectors across Asia.
Known file hashes from public sandbox reports include SHA256: 2a7e9f1b... (frpc.exe variant) and MD5: 4c3b2a1d...; however, hashes change frequently due to packing. Network indicators include outbound connections to ports 7000‑9000 with User‑Agent strings like FRP/0.47.0 or Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.1) used for domain fronting. Behavioural signatures include the creation of frpc.ini in %APPDATA% and scheduled tasks named WindowsUpdateTask or FRPClient.
CobaltMirage FRP enables persistent remote access, data exfiltration (often targeting databases and file servers), and lateral movement that can lead to full network compromise. Affected sectors include telecommunications (42% of incidents), government (28%), and education (15%), with financial losses estimated at over $5 million collectively across reported intrusions. The malware’s use of encrypted tunnels makes detection by traditional network‑based signature systems particularly difficult.
Recommended defenses include blocking outbound connections to unknown ports (especially 7000‑9000), deploying YARA rules that detect FRP binary patterns (e.g., rule FRP_client { strings: $a = "Fast Reverse Proxy" condition: $a }), and applying endpoint detection rules for renamed frpc.exe and suspicious scheduled tasks. Regular patching of internet‑facing applications (e.g., MOVEit, Exchange) reduces initial attack surface, and network segmentation limits lateral movement of the FRP tunnel.
⚠️
Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.
Check My Site for FreeFree to start · Cancel anytime
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.