Skip to content

GhostSocks

GhostSocks is a Go-based proxy malware family and malware-as-a-service offering that converts compromised Windows systems into residential SOCKS5 proxy nodes.

Profile source: Mallory opens in a new tab

GhostSocks

Family profile

GhostSocks is a Go-based proxy malware family and malware-as-a-service offering that converts compromised Windows systems into residential SOCKS5 proxy nodes. It is designed to let operators route traffic through victim devices so malicious activity appears to originate from legitimate home or office connections, helping evade IP reputation controls, geofencing, anti-fraud systems, and some device- or location-based authentication checks. Recent variants have been observed wrapping proxy traffic in TLS, improving stealth over earlier implementations that used less protected communications.

The malware is commonly deployed as a secondary payload alongside credential theft malware, especially Vidar and LummaC2. Public reporting has linked GhostSocks closely to the LummaC2 ecosystem, including use as a post-compromise reverse proxy capability that gives operators a backconnect channel into infected machines. This enables attackers to operate from the victim’s network context and can support abuse of stolen sessions or tokens. GhostSocks has also been reported in campaigns associated with fake software installers and AI-themed lures, including trojanized repositories and installers impersonating tools such as Claude Code, DeepSeek, and OpenClaw.

Functionally, GhostSocks establishes contact with command-and-control infrastructure, registers the infected host, and receives relay information used to expose proxy access through the victim machine. Analyses of newer samples indicate that binaries may contain embedded static configuration data, including affiliate or build metadata and initial controller information, while also supporting dynamic updates to controller infrastructure after check-in. Some variants implement persistence on Windows through autorun mechanisms, while earlier variants reportedly lacked built-in persistence. Reporting also indicates the malware can include backdoor-like capabilities for arbitrary command execution and delivery of additional payloads, extending its utility beyond simple proxying.

GhostSocks has been marketed on Russian-language cybercrime forums and is used by financially motivated threat actors as part of broader criminal operations. Its adoption appears to have increased after collaboration with LummaC2 operators. It has been observed in opportunistic malware distribution campaigns targeting developers and general users through search poisoning, fake GitHub repositories, malicious installers, and software impersonation. Victims have included home users, office users, and organizations in sectors such as education, while the malware’s residential proxy capability makes it broadly useful for fraud, stealthy follow-on intrusion activity, and resale of proxy access to other criminal actors. Reporting has also associated GhostSocks with long-term covert access in ransomware-related operations, including claimed use by Black Basta.

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Aug 6, 2026
Last activity
Aug 9, 2026
Feed role
C2 / Distribution
Host form
6 IP / 2 hostnames

Leading locations

  • NL3
  • RU2
  • US2
  • LU1

Leading providers

  • SERVERS TECH FZCO3
  • Cloudflare, Inc.2
  • Hosting technology LTD2
  • Ghosty Networks LLC1

Infrastructure traits

  • Hosting 8
  • Anycast 2

Samples

Recent associated samples

MITRE ATT&CK

GhostSocks in ATT&CK

30 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.