Skip to content

Socks5Systemz

Socks5Systemz is a Windows proxy-bot malware family that converts infected systems into remotely controlled SOCKS-style traffic-forwarding nodes.

Profile source: Mallory opens in a new tab

Socks5Systemz

Family profile

Socks5Systemz is a Windows proxy-bot malware family that converts infected systems into remotely controlled SOCKS-style traffic-forwarding nodes. It has been distributed as a final payload by loaders including PrivateLoader and Amadey, including through pay-per-install operations and cracked-software lures. The malware has also historically been deployed as a proxy component by other commodity malware families.

Socks5Systemz establishes persistence primarily through a Windows service, with some variants falling back to replacement of a legitimate updater or other autostart mechanisms when service installation fails. Loaders decrypt a DLL-based proxy payload and inject or memory-load it, reducing its on-disk exposure. The malware uses a generated victim identifier, periodically contacts command-and-control infrastructure, and employs a domain-generation mechanism with a fallback C2-discovery mechanism. Its C2 discovery and beacon traffic use RC4 encryption over web protocols.

The bot accepts commands to connect, disconnect, idle, and update proxy or C2 configuration. On instruction, an infected host connects to a backconnect server and receives a unique port through which an authorized customer can relay traffic. Proxy access can be controlled through source-address allowlisting or username-and-password authentication. The resulting residential proxy capacity has been commercialized through services including PROXY.AM and its successor ProxyBox, and has been associated with carding, credential stuffing, and identity-theft activity. Socks5Systemz has infected systems globally and has been active since at least 2016.

Capabilities

  • Defense Evasion
  • Persistence
  • Post Exploitation
  • Process Injection

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Sep 9, 2026
Last activity
Sep 11, 2026
Feed role
C2 / Distribution
Host form
3 IP / 2 hostnames

Leading locations

  • NL3

Leading providers

  • Omegatech LTD2
  • FOP Dmytro Nedilskyi1

Infrastructure traits

  • Hosting 3

Samples

Recent associated samples

Reported operators

Threat actors

1 named in public reporting
CL-CRI-1171

« Une infection ultérieure (juin 2026) a livré GCleaner et Socks5Systemz via la même infrastructure. »

MITRE ATT&CK

Socks5Systemz in ATT&CK

30 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.