Last seven days
- First activity
- Sep 20, 2026
- Last activity
- Sep 20, 2026
- Feed role
- C2
- Host form
- 3 IP / 4 hostnames
GhostSocks is a Golang-based SOCKS5 backconnect proxy malware offered as a Malware-as-a-Service and closely associated with the Lumma infostealer ecosystem.
Profile source: Mallory opens in a new tabGhostSocks
GhostSocks is a Golang-based SOCKS5 backconnect proxy malware offered as a Malware-as-a-Service and closely associated with the Lumma infostealer ecosystem. First publicly observed in 2023 on Russian-language criminal forums and later marketed more broadly, it is designed to convert compromised Windows and Linux systems into residential proxy nodes so operators can route traffic through victim devices and appear to originate from the victimโs network and device context. This capability is used to mask malicious activity, evade IP-based fraud controls, and support follow-on intrusion activity.
GhostSocks commonly appears as a secondary payload alongside commodity stealers such as Lumma and Vidar in fake software installer and trojanized archive campaigns, including lures themed around popular AI tools and developer software. In these operations, a dropper installs both an infostealer and GhostSocks, pairing credential and session theft with proxy access for later abuse.
The malware uses a relay-based command-and-control architecture. Infected hosts register with controller infrastructure, receive relay information, and establish SOCKS5 backconnect tunnels through the victim machine. Newer variants have been observed wrapping relay traffic in TLS, improving stealth and blending with normal encrypted traffic. GhostSocks stores an obfuscated JSON configuration, includes embedded proxy credentials and build metadata, and can receive updated controller information after initial check-in, increasing resilience against infrastructure disruption.
Beyond proxying, GhostSocks exposes backdoor functionality including arbitrary command execution, modification of SOCKS5 credentials, and download-and-execute of additional payloads. Anti-analysis measures reported for the family include sandbox-evasion checks and obfuscation consistent with hardened Go builds. Later Windows variants also added persistence mechanisms, including autorun-based startup persistence.
Operational reporting links GhostSocks strongly to Lumma through automated provisioning and panel integration, suggesting a close commercial or developmental relationship. It has also been reported in broader crimeware ecosystems and has been associated in some reporting with long-term covert access preceding other criminal operations. Its primary value to operators is post-compromise proxy access from legitimate residential or enterprise endpoints, enabling concealment, anti-fraud bypass, and monetization of infected hosts as proxy infrastructure.
C2 tracking
Derp observations, rolling seven-day window
Samples
0f6c506f7616965500f242819fb13aee6459fad1e08624b871219b2859b0a493 0fa77d5a4b80f4153dbc489ac4b18e22c6ff98fa54ce6c0a17ff12c61f92eb22 12ce747f92de61b2de345cecdf3e9378b6857d4715164d6b14b0c8986a833234 2d499700e1319d9203e322cb1e8a8cfec4aa997f86d1fcf76156cfaa0a72054c 3f81758c69ee4a5e55575988d8a2d596ec994c4340d34071ce89981491447597 4fd281c9b5fb0a23a852294ee425bbc5982526ebe23535c38daf221a235296fa 5fe1eaf4f3232ca2d18c6c2cd5bb395248b81d993c29c8050e783591e5be6867 9bf8c972ec2b3243279933359a0e7751fa55d32401e8eebf31aa2ef9109f6252 MITRE ATT&CK
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.