logo

Detecting IOX, FRP, Rakshasa, and Stowaway Proxies Using Hunt.io

ID: 88163b1d-fb98-5f35-8ce6-e2172be7088d

STIX ID: report--88163b1d-fb98-5f35-8ce6-e2172be7088d

Feed Name: Hunt.io Blog

Threat Score
65/100

Date Published: 2026-02-16

Date Updated: 2026-04-28

...
...

This report examines how adversaries leverage open-source proxy tools (IOX, FRP, Rakshasa) to obscure origin infrastructure and enable lateral movement, documents observable traits (static TLS certificate fields, JA4X fingerprint, HTTP body hashes, default config tokens), provides Hunt.io/HuntSQL queries and AttackCapture pivots to identify likely deployments, and cites multiple APT groups that have used these proxies in real intrusions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.