EarthWorm is an open-source network tunneling utility used to create covert proxy channels and port-forwarding paths on compromised systems. It is commonly deployed during post-exploitation to establish SOCKS5 or reverse SOCKS5 tunnels, relay traffic through victim infrastructure, and provide operators with continued access to internal networks that are otherwise unreachable. The tool is widely treated as a successor to older TCP relay utilities such as HTran/lcx, extending those concepts with more flexible SOCKS-based tunneling and reverse proxy functionality.
EarthWorm has been observed across multiple intrusion sets and espionage campaigns, particularly in activity linked to China-aligned threat actors. Reported users include Volt Typhoon, BackdoorDiplomacy, APT41-associated activity, Gelsemium-linked operations, and clusters such as UAT-8837 and CL-STA-0046. It has also appeared in post-compromise activity following exploitation of edge devices and public-facing enterprise software, including Microsoft Exchange, Sitecore, Citrix, Ivanti-related intrusions, and PAN-OS firewall compromises. In these cases, operators used EarthWorm to pivot from an initial foothold, expose internal services, maintain outbound command-and-control paths, and support lateral movement or follow-on hands-on-keyboard operations.
The tool is not primarily an initial-access payload or a traditional backdoor; rather, it functions as an operator-controlled tunneling component that enables stealthy network access and traffic redirection. It has been used alongside other proxy and remote administration tools such as FRP, ReverseSocks5, reGeorg-family tunnels, Impacket, Cobalt Strike, and commodity web shells. Public reporting indicates implementations for multiple operating systems and architectures, including Windows and Linux, with broader cross-platform support also noted. Its prevalence in state-linked and intrusion-set tradecraft reflects its utility as a lightweight, reusable post-exploitation tunnel for persistence of access, internal pivoting, and defense evasion through proxying and encapsulated communications.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Some of the tools we saw used in post-compromise activity in those impacted since March 2 include: ... EarthWorm tunnel tool
The Earthworm tool came as a more powerful replacement to the ageing lcx/Htran one. It incorporated lcx's core concepts ... and added SOCKS5 proxy and reverse SOCKS5 proxy functionalities.
Some of the tools we saw used in post-compromise activity in those impacted since March 2 include: ... EarthWorm tunnel tool
CVE-2025-53690 is a ViewState deserialization vulnerability that affects any version of Sitecore Experience Manager (XM), Experience Platform (XP), Experience Commerce (XC), and Managed Cloud deployed in the manner above. Successful exploitation of the vulnerability might lead to remote code execution and non-authorised access to information. | EARTHWORM (lfe.ico, ufp.exe, ufp.ico)
CVE-2026-0300 is an unauthenticated buffer overflow in the User-ID Authentication Portal (Captive Portal) service of PAN-OS. The vendor advisory states that exploitation yields arbitrary code execution with root privileges on PA-Series and VM-Series firewalls... exploitation has been observed since April 9, 2026, with successful remote code execution achieved by April 16, 2026. | Observed post-exploitation activity includes shellcode injection into the nginx worker process on the firewall, Active Directory enumeration using credentials extracted from the firewall, anti-forensic log cleanup, and deployment of network tunneling tools (EarthWorm, ReverseSocks5) for outbound command and control.
9 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
We observed Earth Estries using the following post-exploitation tools... A VMProtected version of EarthWorm, a SOCK5 network tunnel
The Earthworm tool came as a more powerful replacement to the ageing lcx/Htran one. It incorporated lcx's core concepts ... and added SOCKS5 proxy and reverse SOCKS5 proxy functionalities.
The Earthworm tool came as a more powerful replacement to the ageing lcx/Htran one. It incorporated lcx's core concepts ... and added SOCKS5 proxy and reverse SOCKS5 proxy functionalities.
After exploiting the flaw, attackers deployed tunneling tools such as EarthWorm and ReverseSocks5, used stolen credentials to probe Active Directory, and deleted logs and other evidence to hide the intrusion.
After exploiting the flaw, attackers deployed tunneling tools such as EarthWorm and ReverseSocks5, used stolen credentials to probe Active Directory, and deleted logs and other evidence to hide the intrusion.
11 distinct techniques documented for this family, organized by ATT&CK tactic.
Then they deployed EarthWorm and ReverseSocks5 tunnels for outbound C2
Some of the tools we saw used in post-compromise activity in those impacted since March 2 include: ... EarthWorm tunnel tool ... ReGeorg web shells ... Chisel
Then they deployed EarthWorm and ReverseSocks5 tunnels for outbound C2
Some of the tools we saw used in post-compromise activity in those impacted since March 2 include: ... Stowaway multi-hop proxy tool
Aria-body has the ability to use a reverse SOCKS proxy module... BADHATCH can use SOCKS4 and SOCKS5 proxies... GoBear implements SOCKS5 proxy functionality... Neo-reGeorg has the ability to establish a SOCKS5 proxy... Remcos uses the infected hosts as SOCKS5 proxies...
3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
33 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
SOCKS5 tunneling tool used for post-exploitation network pivoting and access within compromised environments.
Инструмент для SOCKS5-туннелирования и проксирования трафика, используемый после эксплуатации для C2 и пивотирования во внутреннюю сеть.
A network tunneling tool used post-exploitation to pivot through compromised PAN-OS firewalls, reduce forensic footprint, and support covert command-and-control and internal movement.
EarthWorm is an open-source tunneling tool written in C that works across Windows, Linux, macOS, and ARM/MIPS platforms. It acts as a SOCKS5 proxy and port-forwarding utility, enabling covert communication channels, bypassing network restrictions, and lateral movement within compromised environments.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.