Volt Typhoon CISA Malware Analysis: FRPC Reverse Proxy, FRP NAT Traversal, and ScanLine Port Scanner Recovered from Compromised US Critical Infrastructure

CISA published malware analysis report AR24-038A on CISA (February 7, 2024) covering three files obtained from a US critical infrastructure organization compromised by Volt Typhoon — a People's Republic of China (PRC) state-sponsored cyber group. The submitted artifacts represent the discovery and command-and-control toolset deployed by Volt Typhoon during the intrusion, consistent with the group's known preference for living-off-the-land techniques and open-source tooling over custom malware.

Three Recovered Tools: FRPC, FRP, and ScanLine

The first artifact is an open-source Fast Reverse Proxy Client (FRPC) — used to establish a reverse proxy tunnel between the compromised internal system and a Volt Typhoon-controlled C2 server. FRPC enables the actor to route C2 traffic outbound through the victim's network perimeter, bypassing inbound firewall restrictions and making C2 communications appear as outbound connections originating from within the trusted network. The second artifact is the Fast Reverse Proxy (FRP) framework itself — a tool capable of exposing internal servers situated behind network firewalls or obscured by Network Address Translation (NAT), allowing the actor to reach otherwise non-routable internal hosts from external infrastructure. The third artifact is ScanLine — a publicly available port scanner used for internal network reconnaissance, enabling Volt Typhoon to enumerate live hosts, open ports, and accessible services within the compromised environment to identify targets for lateral movement.

Operational Context: Pre-Positioning in US Critical Infrastructure

The recovery of these tools from a compromised critical infrastructure organization is consistent with Volt Typhoon's documented strategy of establishing long-term persistent access to US critical infrastructure — including communications, energy, transportation, and water sectors — for strategic pre-positioning rather than immediate data theft. The combination of FRPC/FRP for persistent covert C2 channel maintenance and ScanLine for internal reconnaissance reflects the group's operational pattern: gain initial access via living-off-the-land techniques, establish durable C2 through legitimate or open-source tools that blend with normal network traffic, and quietly map internal networks in preparation for potential disruptive operations. CISA's full attribution context is detailed in the joint advisory PRC State-Sponsored Actors Compromise and Maintain Persistent Access to U.S. Critical Infrastructure.

Read the full analysis on IntelFusions