Skip to content

GhostSocks

GhostSocks is a Golang-based SOCKS5 backconnect proxy malware offered as a Malware-as-a-Service and closely associated with the Lumma infostealer ecosystem.

Profile source: Mallory opens in a new tab

GhostSocks

Family profile

GhostSocks is a Golang-based SOCKS5 backconnect proxy malware offered as a Malware-as-a-Service and closely associated with the Lumma infostealer ecosystem. First publicly observed in 2023 on Russian-language criminal forums and later marketed more broadly, it is designed to convert compromised Windows and Linux systems into residential proxy nodes so operators can route traffic through victim devices and appear to originate from the victimโ€™s network and device context. This capability is used to mask malicious activity, evade IP-based fraud controls, and support follow-on intrusion activity.

GhostSocks commonly appears as a secondary payload alongside commodity stealers such as Lumma and Vidar in fake software installer and trojanized archive campaigns, including lures themed around popular AI tools and developer software. In these operations, a dropper installs both an infostealer and GhostSocks, pairing credential and session theft with proxy access for later abuse.

The malware uses a relay-based command-and-control architecture. Infected hosts register with controller infrastructure, receive relay information, and establish SOCKS5 backconnect tunnels through the victim machine. Newer variants have been observed wrapping relay traffic in TLS, improving stealth and blending with normal encrypted traffic. GhostSocks stores an obfuscated JSON configuration, includes embedded proxy credentials and build metadata, and can receive updated controller information after initial check-in, increasing resilience against infrastructure disruption.

Beyond proxying, GhostSocks exposes backdoor functionality including arbitrary command execution, modification of SOCKS5 credentials, and download-and-execute of additional payloads. Anti-analysis measures reported for the family include sandbox-evasion checks and obfuscation consistent with hardened Go builds. Later Windows variants also added persistence mechanisms, including autorun-based startup persistence.

Operational reporting links GhostSocks strongly to Lumma through automated provisioning and panel integration, suggesting a close commercial or developmental relationship. It has also been reported in broader crimeware ecosystems and has been associated in some reporting with long-term covert access preceding other criminal operations. Its primary value to operators is post-compromise proxy access from legitimate residential or enterprise endpoints, enabling concealment, anti-fraud bypass, and monetization of infected hosts as proxy infrastructure.

Capabilities

  • Defense Evasion
  • Exfiltration
  • Persistence
  • Post Exploitation
  • Spoofing

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Sep 20, 2026
Last activity
Sep 20, 2026
Feed role
C2
Host form
3 IP / 4 hostnames

Leading locations

  • DE2
  • US2
  • FI1
  • NL1

Leading providers

  • Cloudflare, Inc.2
  • INTERNATIONAL HOSTING COMPANY LIMITED2
  • Emil Vitukhnovskii trading as Great Flower1
  • NetCrafters OU1

Infrastructure traits

  • Hosting 6
  • Anycast 2

Samples

Recent associated samples

MITRE ATT&CK

GhostSocks in ATT&CK

36 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.