Last seven days
- First activity
- Jul 23, 2026
- Last activity
- Jul 28, 2026
- Feed role
- C2 / Distribution
- Host form
- 8 IP / 3 hostnames
Socks5Systemz is a proxy bot malware that turns infected devices into traffic-forwarding proxies for malicious traffic.
Profile source: Mallory opens in a new tabSocks5Systemz
Socks5Systemz is a proxy bot malware that turns infected devices into traffic-forwarding proxies for malicious traffic. It has been sold on underground forums since 2013 and was widely commercialized through the PROXY[.]AM service, which later rebranded as ProxyBox after infrastructure disruption and sinkholing in early 2024. The malware has historically been distributed as a SOCKS5 proxy module embedded in other malware families including Andromeda, SmokeLoader, and Trickbot, and more recently as a standalone payload delivered by loaders such as PrivateLoader and Amadey. Observed infection chains also used cracked software lures and NSIS-based installers from pay-per-install and pirated software ecosystems.
The malwareβs purpose is to provide residential proxy access for criminal use cases including carding, credential stuffing, identity theft, and other abuse. In one documented multi-stage infection chain, Socks5Systemz was deployed alongside PrivateLoader, Smoke, Lumma, RedLine, RisePro, Amadey, StealC, a miner, and STOP/DJVU ransomware. In that case it executed as DTPanelQT.exe and TacDecoLIB.exe, contacted 185.196.8[.]22 over port 80, and connected to 176.9.47[.]240 over port 2023, sending repeated IP-and-port lists consistent with proxy bot behavior.
Technical reporting describes a multi-stage loader chain culminating in a Socks5Systemz DLL of roughly 600 KB that uses junk code and control-flow obfuscation. The malware can be installed as a Windows service or regular executable; when invoked with an install flag it attempts persistence via service creation and falls back to a registry Run key if service creation fails. It cycles through command-and-control servers, trying each address multiple times and alternating between HTTPS and HTTP until successful. C2 communication uses URLs of the form http(s)://ip/ai/?key=<encrypted parameters>, with both requests and responses RC4-encrypted using a 16-byte key that may vary by sample. It uses the user-agent string "Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)" and supports commands including Connect, Disconnect, Idle, Updips, and Updurls. Earlier reporting also states that Socks5Systemz connects to its C2 using a DGA.
The botnet has operated at significant scale. Reporting cited approximately 250,000 infected devices globally per day for the first iteration by late January 2024, while the rebranded ProxyBox service was observed maintaining roughly 32,000 to 35,000 daily active IPs. Significant concentrations of active IPs were observed in Russia, Brazil, and India.
C2 tracking
Derp observations, rolling seven-day window
Samples
499f27061cc38ec593b8104599919c92bb729a55640e6057778a18b05eb7191c 600cf8533d43cc3b073ab18ed728cb4c9c037870c53ab8f0eb66bf225a3ac7e3 9d0eada306e1f5f7beb45a1e5178e12daba9c4342fbd142540fd909253361d50 ad5d551335f98af221996306603a1618f990832bf6fdda23200e886be5a28f99 1a02f5724eaaa775d4718dd266d630b1f8cdbc218516c0afd70800240a07a150 45f16a66c72637fc6b473f23896e73b7a8a3e88d564ab1541a7ee39a5b41e441 e2ade9d3303ff03e5e73c8d90da926e3c2390aa3698924d2397c692138c9a141 824c913c874d3300c7deefd16ea653d323cfa6a5a7680f10beb00a8cbfa398a4 bfe2c25627eec3369b94ec60c1592e9cb38868f83f812a4ec506947d59ac8891 f50688b538fecc5ef7c893e148ddbb3cc1919fcb7c6462033fb72cb469242461 MITRE ATT&CK
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.