Suo5 is an open-source HTTP proxy and tunneling tool used by threat actors for covert traffic forwarding through compromised systems. It is commonly deployed post-compromise as a server-side web component or injected payload that relays attacker traffic over HTTP or HTTPS, typically exposing a SOCKS5-style proxy on the operator side and encapsulating arbitrary TCP traffic inside web requests. Suo5 is widely characterized as a higher-performance alternative to older tunneling webshells such as reGeorg and Neo-reGeorg, using long-lived HTTP/1.1 chunked connections to improve throughput and interactivity.
Observed implementations include .NET, Java, and experimental PHP variants, and the tool has been used both as a webshell-like tunnel on internet-facing application servers and as an in-memory or injected proxy component on edge appliances. In SonicWall SMA 1000 intrusions attributed to UTA0533 and later associated with activity overlapping INC Ransomware operations, Suo5 was deployed via the KNUCKLEBALL loader as a Java agent inside a legitimate SonicWall process to provide covert forwarding and remote access through the compromised appliance. In Ivanti CSA-related intrusions, attackers deployed Suo5 on a Microsoft Exchange server to tunnel into internal networks reachable from that host. ANSSI also documented use of Suo5 by the Houken cluster, which it assessed as likely linked to UNC5174, including deployment on an internet-facing Exchange server during post-exploitation activity.
Suo5’s primary role is post-exploitation pivoting and traffic relay rather than initial compromise. It enables operators to reach internal systems, traverse otherwise inaccessible network segments, and mask follow-on activity behind legitimate-looking web traffic. Its use over HTTPS can complicate network detection, and reported use of randomized TLS client behavior further reduces straightforward fingerprinting. In incident investigations, Suo5 has been associated with broader intrusion sets involving credential theft, persistence, lateral movement, and covert access maintenance, but those functions are generally provided by companion tooling rather than by Suo5 itself.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
SonicWall has disclosed two vulnerabilities affecting SMA 1000 Series secure remote access appliances - CVE-2026-15409 (Server-Side Request Forgery, CVSSv3.1 10.0) and CVE-2026-15410 (Code Injection / path traversal, CVSSv3.1 7.2) - which can be chained by an unauthenticated remote attacker to achieve root-level remote code execution. | Match against known malware from this campaign ... Malware File MD5 Suo5 (proxy tool) agent_wp8.jar 54d21399b8b52b48a0fef68450593e45
CVE-2026-15410 — Code Injection / Path Traversal Severity: High (CVSSv3.1 7.2). Vulnerability type: Path traversal in the remove_hotfix helper invoked by the appliance's control-service sysCtrl.execRemoveHotfix function, which normally requires administrator access to the Appliance Management Console (AMC). | Match against known malware from this campaign ... Malware File MD5 Suo5 (proxy tool) agent_wp8.jar 54d21399b8b52b48a0fef68450593e45
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Match against known malware from this campaign ... Malware File MD5 Suo5 (proxy tool) agent_wp8.jar 54d21399b8b52b48a0fef68450593e45
while the second type is Suo5, which supports tunneling functionality.
18 distinct techniques documented for this family, organized by ATT&CK tactic.
SonicWall has disclosed two vulnerabilities affecting SMA 1000 Series secure remote access appliances... which can be chained by an unauthenticated remote attacker to achieve root-level remote code execution. SonicWall has confirmed both vulnerabilities were actively exploited in the wild as zero-days before a patch existed.
The suo5.aspx webshell was dropped on the Exchange Server at the location C:\Program Files\Microsoft\Exchange Server\V15\FrontEnd\HttpProxy\owa\auth\OutlookEN.aspx .
The latter injected two hidden Java components directly into a legitimate running SonicWall process, to keep the malware in memory.
The attacks are suspected to involve the exploitation of CVE-2026-15409 and CVE-2026-15410, which could be chained to facilitate arbitrary command execution and take over susceptible devices.
The attacker exploits CVE-2026-15410, a path-traversal flaw in the removehotfix process, causing a staged script to execute with full root privileges.
The latter injected two hidden Java components directly into a legitimate running SonicWall process, to keep the malware in memory.
port-forwarding/proxy tunneling tool used to relay traffic through compromised hosts
GlassFish : scripts Node.js déployant des WAR shells ... via SOCKS5 proxy local (127.0.0.1:1111)
They planted an HTTP proxy tunnel going by the name of suo5... The suo5.aspx webshell was dropped on the Exchange Server... a SOCKS5 proxy must be set up and the suo5 binary communicates with the server-side code to transmit TCP data encapsulated in the HTTP(S) communication.
36 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
19 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Open-source HTTP proxy launched during the attacks as part of post-exploitation activity.
An HTTP forwarding proxy agent deployed on compromised appliances to covertly forward traffic and support post-exploitation activity.
An HTTP forwarding proxy agent deployed on compromised appliances to covertly relay traffic.
A memory-injected HTTP forwarding proxy implanted into the Workplace JVM to provide covert tunneling, internal pivoting, reverse proxying, C2, and traffic forwarding through the compromised VPN appliance.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.