Neither Malware nor Harmless: Tracking the NPS Proxy Across the Internet
ID: 00838278-35ff-5955-8688-5591a09ef169
STIX ID: report--00838278-35ff-5955-8688-5591a09ef169
Feed Name: Censys Blog
Threat Score
This report analyzes NPS, a popular open-source reverse tunneling/proxy server frequently deployed in Chinese cloud infrastructure; while often legitimate, it has been observed abused by threat actors (including PRC-linked operators) as a secondary post-exploitation tunneller to pivot into internal networks, with Censys telemetry showing ~17,500 instances and documented cases alongside Cobalt Strike and webshells.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
