EarthWorm is a publicly available, open-source network tunneling utility used to create covert tunnels, including reverse SOCKS/SOCKS5 proxy tunnels and port-forwarding/port-transfer channels between compromised systems and attacker-controlled infrastructure. The content describes it as a tunneling tool written in C with support for Windows, Linux, macOS, and ARM/MIPS platforms, and notes its use for outbound command and control, firewall bypass, covert communications, lateral movement, and exposing internal systems to external operators.
The tool is repeatedly described as post-exploitation infrastructure rather than a standalone initial-access malware. Observed deployment contexts in the content include exploitation of Palo Alto Networks PAN-OS CVE-2026-0300, where attackers used EarthWorm alongside ReverseSocks5 after achieving root-level remote code execution on exposed firewalls. In those incidents, EarthWorm was used for outbound C2/persistent tunneling, following shellcode injection into nginx worker processes, credential extraction from the firewall, Active Directory enumeration, anti-forensic log cleanup, and in some cases repetition of the intrusion chain on secondary high-availability firewalls. One EarthWorm sample hash reported in that context is SHA256 e11f69b49b6f2e829454371c31ebf86893f82a042dae3f2faf63dcd84f97a584, and one reported download URL is hxxp[:]//146.70.100[.]69:8000/php_sess.
The content also associates EarthWorm with multiple China-linked or suspected China-linked threat actors and clusters, including BackdoorDiplomacy, Volt Typhoon, APT41, CL-STA-0046/Gelsemium, CL-STA-1132, UAT-8837, and Jewelbug. Reported uses include network tunneling with SOCKS5 server and port-transfer functionality, proxying traffic, creating reverse tunnels to attacker-controlled servers, and replacing blocked proxy tooling during intrusions. Additional observed intrusion contexts include exploitation of Sitecore CVE-2025-53690 by UAT-8837, where EarthWorm was used for network tunneling and firewall bypass; Southeast Asian government intrusions attributed with moderate confidence to Gelsemium, where EarthWorm was deployed after OwlProxy execution was blocked and used to tunnel victim LAN traffic to external C2; and Volt Typhoon operations, where EarthWorm was used with FRP and Impacket to proxy network traffic.
High-confidence indicators and artifacts directly mentioned in the content include the filename ew.exe, the SHA256 hash e11f69b49b6f2e829454371c31ebf86893f82a042dae3f2faf63dcd84f97a584, the download URL hxxp[:]//146.70.100[.]69:8000/php_sess, and C2/infrastructure references including 27.124.26[.]86 in one Gelsemium-linked tunneling case.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
A critical zero-day vulnerability (CVE-2025-53690) is being actively exploited in Sitecore. This flaw, originating from old, insecure keys, allows hackers to achieve Remote Code Execution (RCE) via ViewState deserialization attacks. | This included EARTHWORM for creating secret tunnels, DWAGENT for remote access, and SHARPHOUND for mapping the network.
CVE-2026-0300 is an unauthenticated buffer overflow in the User-ID Authentication Portal (Captive Portal) service of PAN-OS. The vendor advisory states that exploitation yields arbitrary code execution with root privileges on PA-Series and VM-Series firewalls... exploitation has been observed since April 9, 2026, with successful remote code execution achieved by April 16, 2026. | Observed post-exploitation activity includes shellcode injection into the nginx worker process on the firewall, Active Directory enumeration using credentials extracted from the firewall, anti-forensic log cleanup, and deployment of network tunneling tools (EarthWorm, ReverseSocks5) for outbound command and control.
7 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
After exploiting the flaw, attackers deployed tunneling tools such as EarthWorm and ReverseSocks5, used stolen credentials to probe Active Directory, and deleted logs and other evidence to hide the intrusion.
After exploiting the flaw, attackers deployed tunneling tools such as EarthWorm and ReverseSocks5, used stolen credentials to probe Active Directory, and deleted logs and other evidence to hide the intrusion.
After exploiting the flaw, attackers deployed tunneling tools such as EarthWorm and ReverseSocks5, used stolen credentials to probe Active Directory, and deleted logs and other evidence to hide the intrusion.
They repeated CVE-2026-0300 exploitation on that device, achieved RCE again, and downloaded the EarthWorm and ReverseSocks5 network tunneling tools, likely to establish persistent tunneling and proxy capabilities for continued access.
EarthWorm, to create a reverse tunnel to attacker-controlled servers using SOCKS
9 distinct techniques documented for this family, organized by ATT&CK tactic.
Then they deployed EarthWorm and ReverseSocks5 tunnels for outbound C2
“Earthworm: A network tunneling tool used to ‘expose internal endpoints to attacker-owned remote infrastructure’.”
"APT41 used a tool called CLASSFON to covertly proxy network communications." / "BADCALL functions as a proxy server between the victim and C2 server." / "Sandworm Team's BCS-server tool can create an internal proxy server to redirect traffic..."
Then they deployed EarthWorm and ReverseSocks5 tunnels for outbound C2
Aria-body has the ability to use a reverse SOCKS proxy module... BADHATCH can use SOCKS4 and SOCKS5 proxies... GoBear implements SOCKS5 proxy functionality... Neo-reGeorg has the ability to establish a SOCKS5 proxy... Remcos uses the infected hosts as SOCKS5 proxies...
3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
28 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Инструмент для SOCKS5-туннелирования и проксирования трафика, используемый после эксплуатации для C2 и пивотирования во внутреннюю сеть.
A network tunneling tool used post-exploitation to pivot through compromised PAN-OS firewalls, reduce forensic footprint, and support covert command-and-control and internal movement.
EarthWorm is an open-source tunneling tool written in C that works across Windows, Linux, macOS, and ARM/MIPS platforms. It acts as a SOCKS5 proxy and port-forwarding utility, enabling covert communication channels, bypassing network restrictions, and lateral movement within compromised environments.
Network tunneling tool used post-compromise for outbound command and control.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.