Last seven days
- First activity
- Aug 6, 2026
- Last activity
- Aug 9, 2026
- Feed role
- C2 / Distribution
- Host form
- 6 IP / 2 hostnames
GhostSocks is a Go-based proxy malware family and malware-as-a-service offering that converts compromised Windows systems into residential SOCKS5 proxy nodes.
Profile source: Mallory opens in a new tabGhostSocks
GhostSocks is a Go-based proxy malware family and malware-as-a-service offering that converts compromised Windows systems into residential SOCKS5 proxy nodes. It is designed to let operators route traffic through victim devices so malicious activity appears to originate from legitimate home or office connections, helping evade IP reputation controls, geofencing, anti-fraud systems, and some device- or location-based authentication checks. Recent variants have been observed wrapping proxy traffic in TLS, improving stealth over earlier implementations that used less protected communications.
The malware is commonly deployed as a secondary payload alongside credential theft malware, especially Vidar and LummaC2. Public reporting has linked GhostSocks closely to the LummaC2 ecosystem, including use as a post-compromise reverse proxy capability that gives operators a backconnect channel into infected machines. This enables attackers to operate from the victim’s network context and can support abuse of stolen sessions or tokens. GhostSocks has also been reported in campaigns associated with fake software installers and AI-themed lures, including trojanized repositories and installers impersonating tools such as Claude Code, DeepSeek, and OpenClaw.
Functionally, GhostSocks establishes contact with command-and-control infrastructure, registers the infected host, and receives relay information used to expose proxy access through the victim machine. Analyses of newer samples indicate that binaries may contain embedded static configuration data, including affiliate or build metadata and initial controller information, while also supporting dynamic updates to controller infrastructure after check-in. Some variants implement persistence on Windows through autorun mechanisms, while earlier variants reportedly lacked built-in persistence. Reporting also indicates the malware can include backdoor-like capabilities for arbitrary command execution and delivery of additional payloads, extending its utility beyond simple proxying.
GhostSocks has been marketed on Russian-language cybercrime forums and is used by financially motivated threat actors as part of broader criminal operations. Its adoption appears to have increased after collaboration with LummaC2 operators. It has been observed in opportunistic malware distribution campaigns targeting developers and general users through search poisoning, fake GitHub repositories, malicious installers, and software impersonation. Victims have included home users, office users, and organizations in sectors such as education, while the malware’s residential proxy capability makes it broadly useful for fraud, stealthy follow-on intrusion activity, and resale of proxy access to other criminal actors. Reporting has also associated GhostSocks with long-term covert access in ransomware-related operations, including claimed use by Black Basta.
C2 tracking
Derp observations, rolling seven-day window
Samples
0fa77d5a4b80f4153dbc489ac4b18e22c6ff98fa54ce6c0a17ff12c61f92eb22 708e4c73217d10e821899bfb5296b72328520407f4cc38c4a525707568efa57d 2378e1f171faad176f8cd95a3c106e06dbe74a135ce8e8dabc0e41cf2405ef54 c7b43ba65c93416885aac3f8dd532d867781119f56552316ba1a24ece5f1c66e 2e2e035ece4accdee838ecaacdc263fa526939597954d18d1320d73c8bf810c2 2fd3e4fed8a88f9aa00a921cbb6fb564aa64943b20fc512ce3eb134d5ebfd2d3 401b70e0313d7f6dd1fd444a8d61e25ae433a5944a2607405fe5ddbc9b8f7afc 65ba3988d38f83b9ee1f31cafa5bd37dc6b72279f5618aac94d71a904efa0cac b4a3205341b7d6eee7d8a810300a39960ac66c7fb89f585a06c6e1e921a49820 MITRE ATT&CK
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.