Stowaway is an open-source, Go-based remote-access and multi-hop proxy tool used in post-compromise operations. It supports SOCKS5 proxying, port forwarding, reverse tunneling, remote shell access, file transfer, and SSH-based tunneling. Its communications can use TCP, HTTP, or WebSocket channels protected with AES-256-GCM or TLS, enabling operators to relay and conceal traffic through compromised hosts. Stowaway has been deployed through DLL side-loading and used to establish inbound TCP access, proxy encrypted traffic, and maintain access within victim networks. It has appeared in China-nexus espionage activity affecting telecommunications organizations and government entities in South Asia, Southeast Asia, South America, and southeastern Europe. It has also been observed in ransomware-associated intrusions, including a Fog ransomware incident targeting an Asian financial institution, where it was used to deliver employee-monitoring software.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Some of the tools we saw used in post-compromise activity in those impacted since March 2 include: ... Stowaway multi-hop proxy tool
Some of the tools we saw used in post-compromise activity in those impacted since March 2 include: ... Stowaway multi-hop proxy tool
5 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The Cobalt Strike beacon was injected into an SQL server process, enabling C2 communication to deliver additional malware such as `Stowaway` and `iox` to tunnel network traffic through compromised systems.
Another example from this incident demonstrates the use of the PowerShell cmdlet Start-BitsTransfer. In this case, the second-stage Stowaway implant is extracted as follows.
A new Go-based RAT named Stowaway took the lead. It adds reverse tunneling and SSH-based tunneling on top of the proxy features.
Several executions of the Stowaway proxy tool were observed in the network under different names, such as ‘vhd.exe’, ‘vga.exe’ and ‘hhd.exe’.
To maintain persistent backdoor access, the group deploys Stowaway, a proxy tunneling tool written in Simplified Chinese, routing outside traffic into infected hosts within the enterprise.
26 distinct techniques documented for this family, organized by ATT&CK tactic.
Snippets showing both the listening and connecting executions of Stowaway, using a service installed on the machine... Windows event log ID 7045, showing the creation of the service which executes ‘vga.exe’... service named ‘RoHesJayPv’... remotely creating a service named ‘HkBnPoqLAj’.
Snippets showing both the listening and connecting executions of Stowaway, using a service installed on the machine... Windows event log ID 7045, showing the creation of the service which executes ‘vga.exe’... service named ‘RoHesJayPv’... remotely creating a service named ‘HkBnPoqLAj’.
Obfuscated Files or Information T1027 Basic description To bypass security solutions, attackers employ obfuscation.
the threat actor created a malicious file named ‘C:\Intel\svchost.exe’... attempting to mask the malware as benign activity... Additional executions of the Stowaway tunneling tool were also observed during this phase using the names ‘svchost.exe’, ‘tomcat.exe’, and ‘tomcat7.exe’.
The actors use SSH endpoints and chained relays to enable interactive remote access.
Day 3: The threat actor successfully connected over RDP from the DESKTOP-PSGDD89 host to a server in the victim’s network... Phase 2: Lateral Movement... through RDP and tunneled connections.
The actors open non-standard SSH and HTTP ports and use separate C2 channels within high-traffic nodes.
The attacker used various tools for different purposes: collecting information for infiltration, port forwarding for establishing an external connection...
The group leverages STOWAWAY to build chained relays and enable interactive remote access.
The backdoor connects to command-and-control servers using ChaCha20 encryption for communications... Communications are transported over TCP...
Technical details | Command and Control TA0011 | Ingress Tool Transfer T1105
The primary weapon in this campaign is the GoSerpent backdoor... Stowaway is a proxy and remote access tool... McMx is a basic Go-based proxy and remote access tool.
The malware accepted inbound TCP network connections via port 7475. VSOCKpuppet accepts connections via the VSOCK interface (including port 6667).
49 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
17 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Go-based remote access trojan introduced in the later phase of the campaign that provides reverse tunneling and SSH-based tunneling, and is used to deliver exfiltration components.
A customized proxy and remote access tool based on an open-source framework, supporting chained proxy paths, SOCKS5, port forwarding, reverse tunneling, remote shell, file transfer, and SSH-based tunneling over TCP, HTTP, or WebSocket with AES-256-GCM or TLS protection.
Go-based RAT/proxy compiled from an open-source framework and customized for stealth, supporting chained proxy paths, SOCKS5, port forwarding, reverse tunneling, remote shell, file transfer, and SSH-based tunneling over TCP, HTTP, or WebSocket with AES-256-GCM or TLS protection.
Proxy tunneling tool used to maintain persistent access by routing external traffic into infected enterprise hosts.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.