RSOCKS is the name associated with a cybercrime-operated proxy botnet and proxy service built from compromised internet-connected devices. It has been described as leveraging large numbers of hijacked systems, including IoT devices, Android phones, and computers, to provide proxy infrastructure for downstream abuse. This activity aligns with financially motivated cybercrime operations centered on monetizing illicit access to compromised devices. High-confidence reporting also associates the name with a separate intrusion set targeting organizations in Japan since January 2025 through exploitation of CVE-2024-4577 in PHP-CGI on Windows. In that activity, operators gained initial access via remote code execution, executed PowerShell scripts, and deployed Cobalt Strike with TaoWu plugins for post-exploitation and persistent remote access. Observed victim sectors in Japan included technology, telecommunications, entertainment, education, and e-commerce. The available information does not firmly establish the actor's geographic origin, and attribution beyond the observed tooling and intrusion pattern remains unconfirmed.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.