Last seven days
- First activity
- Aug 2, 2026
- Last activity
- Aug 7, 2026
- Feed role
- C2 / Distribution
- Host form
- 6 IP / 5 hostnames
GhostSocks is a Go-based proxy malware family and malware-as-a-service offering that converts compromised Windows systems into residential SOCKS5 proxy nodes.
Profile source: Mallory opens in a new tabGhostSocks
GhostSocks is a Go-based proxy malware family and malware-as-a-service offering that converts compromised Windows systems into residential SOCKS5 proxy nodes. It is designed to let operators route traffic through victim devices so malicious activity appears to originate from legitimate home or office connections, helping evade IP reputation controls, geofencing, anti-fraud systems, and some device- or location-based authentication checks. Recent variants have been observed wrapping proxy traffic in TLS, improving stealth over earlier implementations that used less protected communications.
The malware is commonly deployed as a secondary payload alongside credential theft malware, especially Vidar and LummaC2. Public reporting has linked GhostSocks closely to the LummaC2 ecosystem, including use as a post-compromise reverse proxy capability that gives operators a backconnect channel into infected machines. This enables attackers to operate from the victim’s network context and can support abuse of stolen sessions or tokens. GhostSocks has also been reported in campaigns associated with fake software installers and AI-themed lures, including trojanized repositories and installers impersonating tools such as Claude Code, DeepSeek, and OpenClaw.
Functionally, GhostSocks establishes contact with command-and-control infrastructure, registers the infected host, and receives relay information used to expose proxy access through the victim machine. Analyses of newer samples indicate that binaries may contain embedded static configuration data, including affiliate or build metadata and initial controller information, while also supporting dynamic updates to controller infrastructure after check-in. Some variants implement persistence on Windows through autorun mechanisms, while earlier variants reportedly lacked built-in persistence. Reporting also indicates the malware can include backdoor-like capabilities for arbitrary command execution and delivery of additional payloads, extending its utility beyond simple proxying.
GhostSocks has been marketed on Russian-language cybercrime forums and is used by financially motivated threat actors as part of broader criminal operations. Its adoption appears to have increased after collaboration with LummaC2 operators. It has been observed in opportunistic malware distribution campaigns targeting developers and general users through search poisoning, fake GitHub repositories, malicious installers, and software impersonation. Victims have included home users, office users, and organizations in sectors such as education, while the malware’s residential proxy capability makes it broadly useful for fraud, stealthy follow-on intrusion activity, and resale of proxy access to other criminal actors. Reporting has also associated GhostSocks with long-term covert access in ransomware-related operations, including claimed use by Black Basta.
C2 tracking
Derp observations, rolling seven-day window
Samples
0fa77d5a4b80f4153dbc489ac4b18e22c6ff98fa54ce6c0a17ff12c61f92eb22 c7b43ba65c93416885aac3f8dd532d867781119f56552316ba1a24ece5f1c66e 2e2e035ece4accdee838ecaacdc263fa526939597954d18d1320d73c8bf810c2 2fd3e4fed8a88f9aa00a921cbb6fb564aa64943b20fc512ce3eb134d5ebfd2d3 401b70e0313d7f6dd1fd444a8d61e25ae433a5944a2607405fe5ddbc9b8f7afc 65ba3988d38f83b9ee1f31cafa5bd37dc6b72279f5618aac94d71a904efa0cac b4a3205341b7d6eee7d8a810300a39960ac66c7fb89f585a06c6e1e921a49820 3e0ae3e42dc5fa2d5eda6c5c8579d1d4d3757c6ef8598195a302ce0e6a9dcee2 ae9ec6a5285300fa90e8502df3cad8c16faae58fc88b935f503d7bb9bc92b19b ba5be09836c1061bb64f558f8614c1bb463276a026252937c9bdf2d06a530dc5 MITRE ATT&CK
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.