RAT

LocalXpose

LocalXpose (loclx) is a free/subscription tunneling service from localxpose.io that exposes local TCP/UDP/HTTP services over the internet via the operator-controlled `*.localxpose.io` infrastructure. Marketed for developer use cases (webhook testing, local-server sharing), it is catalogued by the LOTTunnels project under the "shell access" category because the `loclx tunnel tcp/udp --port <PORT>` command pattern can expose an SSH or RDP listener through the operator's tenant subdomain, providing remote interactive access without a traditional RMM agent or open inbound firewall. Documented abuse cases include shell exposure for post-exploitation remote access, HTTP tunneling for data exfiltration, and tunnel-fronted phishing infrastructure.

Tool overview

Category
RAT
Research authors
@MHaggis
Created
2026-05-18
Last modified
2026-05-18
Privileges
User
Free / availability
Yes (free tier + paid subscription)
Verification required
Tenant signup required (free); API-key authenticated via `loclx account login`
Supported platforms
LinuxWindowsmacOS

Capabilities

TCP tunnel (`loclx tunnel tcp --port <PORT>`) — used to expose SSH/RDP/other shell-access servicesUDP tunnel (`loclx tunnel udp --port <PORT>`)HTTP/HTTPS tunnel (`loclx tunnel http --port <PORT>`) — used for webhook testing or to front phishing infrastructureCustom domain support (paid tier)Reserved tunnel addresses

Executables & installation paths

Filename
loclx.exe
OriginalFileName
loclx.exe
Description
LocalXpose command-line client (Windows). Single static Go binary; invoked as `loclx tunnel <type> --port <PORT>` after `loclx account login`.
Filename
loclx
OriginalFileName
loclx
Description
LocalXpose command-line client (Linux/macOS).

Installation paths

loclx.exe
loclx
*\loclx.exe
C:\Users\*\AppData\Local\Programs\loclx\loclx.exe
/usr/local/bin/loclx
%APPDATA%\loclx\*

FORENSIC EVIDENCE

Disk artifacts

File
loclx.exe
Description
LocalXpose CLI client (Go static binary). Often run from the user's Downloads or AppData directory rather than a system install path.
OS
Windows
File
%APPDATA%\loclx\config.yaml
Description
LocalXpose CLI configuration (account API key after `loclx account login`)
OS
Windows
File
~/.loclx/config.yaml
Description
LocalXpose CLI configuration on Linux/macOS (account API key)
OS
Linux

FORENSIC EVIDENCE

Event log artifacts

EventID
4688
ProviderName
Microsoft-Windows-Security-Auditing
LogFile
Security.evtx
CommandLine
loclx.exe tunnel tcp --port <PORT>
Description
LocalXpose tunnel-create process invocation — `tcp` and `udp` tunnel subcommands are the high-signal abuse pattern (used to expose SSH/RDP for inbound remote access through the operator-controlled relay).

FORENSIC EVIDENCE

Network artifacts

Description
LocalXpose tenant tunnel control plane and per-tunnel relay endpoints (wildcard subdomain pattern matches all operator-assigned tunnel hostnames).
Domains
  • localxpose.io
  • *.localxpose.io
  • api.localxpose.io
Ports
  • 443

FORENSIC EVIDENCE

Other artifacts

Type
Other
Value
Install via npm (`npm install -g loclx`), choco, snap, or direct binary download from localxpose.io
Type
Other
Value
LOTTunnels project — Shell Access category: https://lottunnels.github.io/lottunnels/Binaries/localxpose/

Detections

Sigma
https://github.com/magicsword-io/LOLRMM/blob/main/detections/sigma/localxpose_files_sigma.yml
Description
Detects potential file activity of LocalXpose RMM tool
Sigma
https://github.com/magicsword-io/LOLRMM/blob/main/detections/sigma/localxpose_network_sigma.yml
Description
Detects potential network activity of LocalXpose RMM tool
Sigma
https://github.com/magicsword-io/LOLRMM/blob/main/detections/sigma/localxpose_processes_sigma.yml
Description
Detects potential process activity of LocalXpose RMM tool

References

Acknowledgements

Person
rcKillam
Handle
@rcKillam
Person
Michael Haag
Handle
@MHaggis