Stowaway is an open-source Go-based proxy and remote access tool used by multiple threat actors in espionage and financially motivated intrusions. It is commonly employed as a tunneling utility to maintain covert access, route traffic into compromised environments, and support follow-on operations. Reported capabilities include SOCKS5 proxying, port forwarding, reverse tunneling, remote shell access, file transfer, and SSH-based tunneling, with communications observed over TCP, HTTP, and WebSocket channels protected by TLS or AES-256-GCM in some variants or deployments.
The tool has been used to provide persistent backdoor-style access and multi-hop proxying inside enterprise networks, including routing external traffic through infected hosts to reach internal systems. It has also been observed delivered through DLL sideloading chains using legitimate binaries, and in some intrusions it served as an intermediary to deploy additional payloads. Documented follow-on uses include delivery of loader and exfiltration components in a Southeast Asian cyber-espionage campaign, deployment of employee-monitoring software during a Fog ransomware intrusion, and establishment of proxy tunnels during hands-on-keyboard post-compromise activity.
Stowaway has been associated with several China-nexus or suspected China-linked intrusion sets and campaigns, including activity targeting government and diplomatic entities in Southeast Asia, government organizations in South America and southeastern Europe, and high-value organizations in South Asia. It has also appeared in long-dwell intrusions against government networks and in operations involving other malware and tooling such as PlugX, Cobalt Strike, SoftEther VPN, and custom loaders. In these contexts, Stowaway primarily functions as an operational access and tunneling component rather than a standalone destructive payload.
The malware targets Windows environments in the supplied reporting. Its observed role is chiefly post-compromise enablement: maintaining access, enabling lateral reach through proxying and tunneling, and supporting stealthy operator interaction and payload delivery.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
A new Go-based RAT named Stowaway took the lead. It adds reverse tunneling and SSH-based tunneling on top of the proxy features.
Several executions of the Stowaway proxy tool were observed in the network under different names, such as ‘vhd.exe’, ‘vga.exe’ and ‘hhd.exe’.
To maintain persistent backdoor access, the group deploys Stowaway, a proxy tunneling tool written in Simplified Chinese, routing outside traffic into infected hosts within the enterprise.
23 distinct techniques documented for this family, organized by ATT&CK tactic.
Snippets showing both the listening and connecting executions of Stowaway, using a service installed on the machine... Windows event log ID 7045, showing the creation of the service which executes ‘vga.exe’... service named ‘RoHesJayPv’... remotely creating a service named ‘HkBnPoqLAj’.
Snippets showing both the listening and connecting executions of Stowaway, using a service installed on the machine... Windows event log ID 7045, showing the creation of the service which executes ‘vga.exe’... service named ‘RoHesJayPv’... remotely creating a service named ‘HkBnPoqLAj’.
This malware receives encrypted and base64-encoded command-line arguments... ThumbcacheService employs XOR encryption... TmcLoader employs dynamic API resolution through a circular XOR encryption... combined with Base64 encoding for string obfuscation.
the threat actor created a malicious file named ‘C:\Intel\svchost.exe’... attempting to mask the malware as benign activity... Additional executions of the Stowaway tunneling tool were also observed during this phase using the names ‘svchost.exe’, ‘tomcat.exe’, and ‘tomcat7.exe’.
Day 3: The threat actor successfully connected over RDP from the DESKTOP-PSGDD89 host to a server in the victim’s network... Phase 2: Lateral Movement... through RDP and tunneled connections.
The backdoor connects to command-and-control servers using ChaCha20 encryption for communications... Communications are transported over TCP, HTTP, or WebSocket channels with protection using AES-256-GCM or TLS encryption.
It can also spin up SOCKS5 proxies to route traffic through victims and hide the operator’s real IP.
It can also spin up SOCKS5 proxies to route traffic through victims and hide the operator’s real IP.
GoSerpent can establish SOCKS5 proxy servers to route traffic through compromised hosts, enabling attackers to access other networks while masking their true IP addresses.
The backdoor connects to command-and-control servers using ChaCha20 encryption for communications... Communications are transported over TCP...
The primary weapon in this campaign is the GoSerpent backdoor... Stowaway is a proxy and remote access tool... McMx is a basic Go-based proxy and remote access tool.
43 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Go-based remote access trojan introduced in the later phase of the campaign that provides reverse tunneling and SSH-based tunneling, and is used to deliver exfiltration components.
A customized proxy and remote access tool based on an open-source framework, supporting chained proxy paths, SOCKS5, port forwarding, reverse tunneling, remote shell, file transfer, and SSH-based tunneling over TCP, HTTP, or WebSocket with AES-256-GCM or TLS protection.
Go-based RAT/proxy compiled from an open-source framework and customized for stealth, supporting chained proxy paths, SOCKS5, port forwarding, reverse tunneling, remote shell, file transfer, and SSH-based tunneling over TCP, HTTP, or WebSocket with AES-256-GCM or TLS protection.
Proxy tunneling tool used to maintain persistent access by routing external traffic into infected enterprise hosts.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.