Skip to content

Socks5Systemz

Socks5Systemz is a proxy bot malware that turns infected devices into traffic-forwarding proxies for malicious traffic.

Profile source: Mallory opens in a new tab

Socks5Systemz

Family profile

Socks5Systemz is a proxy bot malware that turns infected devices into traffic-forwarding proxies for malicious traffic. It has been sold on underground forums since 2013 and was widely commercialized through the PROXY[.]AM service, which later rebranded as ProxyBox after infrastructure disruption and sinkholing in early 2024. The malware has historically been distributed as a SOCKS5 proxy module embedded in other malware families including Andromeda, SmokeLoader, and Trickbot, and more recently as a standalone payload delivered by loaders such as PrivateLoader and Amadey. Observed infection chains also used cracked software lures and NSIS-based installers from pay-per-install and pirated software ecosystems.

The malware’s purpose is to provide residential proxy access for criminal use cases including carding, credential stuffing, identity theft, and other abuse. In one documented multi-stage infection chain, Socks5Systemz was deployed alongside PrivateLoader, Smoke, Lumma, RedLine, RisePro, Amadey, StealC, a miner, and STOP/DJVU ransomware. In that case it executed as DTPanelQT.exe and TacDecoLIB.exe, contacted 185.196.8[.]22 over port 80, and connected to 176.9.47[.]240 over port 2023, sending repeated IP-and-port lists consistent with proxy bot behavior.

Technical reporting describes a multi-stage loader chain culminating in a Socks5Systemz DLL of roughly 600 KB that uses junk code and control-flow obfuscation. The malware can be installed as a Windows service or regular executable; when invoked with an install flag it attempts persistence via service creation and falls back to a registry Run key if service creation fails. It cycles through command-and-control servers, trying each address multiple times and alternating between HTTPS and HTTP until successful. C2 communication uses URLs of the form http(s)://ip/ai/?key=<encrypted parameters>, with both requests and responses RC4-encrypted using a 16-byte key that may vary by sample. It uses the user-agent string "Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)" and supports commands including Connect, Disconnect, Idle, Updips, and Updurls. Earlier reporting also states that Socks5Systemz connects to its C2 using a DGA.

The botnet has operated at significant scale. Reporting cited approximately 250,000 infected devices globally per day for the first iteration by late January 2024, while the rebranded ProxyBox service was observed maintaining roughly 32,000 to 35,000 daily active IPs. Significant concentrations of active IPs were observed in Russia, Brazil, and India.

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Jul 23, 2026
Last activity
Jul 28, 2026
Feed role
C2 / Distribution
Host form
8 IP / 3 hostnames

Leading locations

  • NL2
  • US2
  • BG1
  • CA1
  • FR1
  • LU1
  • PL1
  • RU1
  • SC1

Leading providers

  • Omegatech LTD3
  • Cloudflare, Inc.2
  • Ghosty Networks LLC2
  • AS56971 Cloud1
  • Emil Vitukhnovskii trading as Great Flower1
  • Intezio Worldwide Limited1

Infrastructure traits

  • Hosting 11
  • Anycast 2
  • Proxy 1

Samples

Recent associated samples

MITRE ATT&CK

Socks5Systemz in ATT&CK

18 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.