Last seven days
- First activity
- Sep 9, 2026
- Last activity
- Sep 11, 2026
- Feed role
- C2 / Distribution
- Host form
- 3 IP / 2 hostnames
Socks5Systemz is a Windows proxy-bot malware family that converts infected systems into remotely controlled SOCKS-style traffic-forwarding nodes.
Profile source: Mallory opens in a new tabSocks5Systemz
Socks5Systemz is a Windows proxy-bot malware family that converts infected systems into remotely controlled SOCKS-style traffic-forwarding nodes. It has been distributed as a final payload by loaders including PrivateLoader and Amadey, including through pay-per-install operations and cracked-software lures. The malware has also historically been deployed as a proxy component by other commodity malware families.
Socks5Systemz establishes persistence primarily through a Windows service, with some variants falling back to replacement of a legitimate updater or other autostart mechanisms when service installation fails. Loaders decrypt a DLL-based proxy payload and inject or memory-load it, reducing its on-disk exposure. The malware uses a generated victim identifier, periodically contacts command-and-control infrastructure, and employs a domain-generation mechanism with a fallback C2-discovery mechanism. Its C2 discovery and beacon traffic use RC4 encryption over web protocols.
The bot accepts commands to connect, disconnect, idle, and update proxy or C2 configuration. On instruction, an infected host connects to a backconnect server and receives a unique port through which an authorized customer can relay traffic. Proxy access can be controlled through source-address allowlisting or username-and-password authentication. The resulting residential proxy capacity has been commercialized through services including PROXY.AM and its successor ProxyBox, and has been associated with carding, credential stuffing, and identity-theft activity. Socks5Systemz has infected systems globally and has been active since at least 2016.
C2 tracking
Derp observations, rolling seven-day window
Samples
052f0caff530a67f9a17df5795806d9b01a551f309e434cd4eb92fba8e024051 1a0ea15923467dd4ea00efcaddc815ab14a0bcd9433f676dbbd413e3e8f89240 a08eeb6cb3b1bcb3331318a87664e5a29f8025bb3eb2bdb74a678d4f423fade5 f6c46c325441c6407ee6a7ccbc322ce04d4b499085ed80e1c3a86431d647610d f9b2120a061c50d6385976c360feadf9f1791b743bc43b3702e35734e718d25d 05dbb515120ec8a6a453c91833eacf432e67ffe89fd650ac704eefc6bf8de290 32ead15908ca61088701ec6ee4c692658585746bafb52cce23c047d035fc91a5 40b643468356c0fd751893647ad0dc9e2a0019427e4f5f0e2f6e559efcecb977 f270a80b90acb4302bb29b2f4c7436f6d7eedc4738ca63351f59f22bd59ce28d 2fcad226b17131da4274e1b9f8f31359bdd325c9568665f08fd1f6c5d06a23ce Reported operators
« Une infection ultérieure (juin 2026) a livré GCleaner et Socks5Systemz via la même infrastructure. »
MITRE ATT&CK
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.