go-socks5 is a SOCKS5-based reverse tunneling and proxy utility used by intrusion operators to establish covert network pivoting and remote access channels inside compromised environments. It has been observed as supporting tooling in espionage-oriented operations rather than as a primary payload, enabling attackers to route traffic through victim networks, maintain access, and facilitate follow-on activity while reducing direct exposure of command-and-control infrastructure.
The tool has been associated with MuddyWater activity targeting organizations in Israel and Egypt across sectors including government, engineering, manufacturing, technology, transportation, utilities, and academia. In these operations, it was deployed alongside custom loaders, backdoors, and credential- and browser-data theft tooling, indicating a role in post-compromise access, tunneling, and operational stealth. Reporting also places go-socks5 among a broader set of reverse proxy and tunneling tools commonly used by threat actors for internal pivoting and remote connectivity.
go-socks5 is implemented in Go and functions as a reverse tunnel or proxy component rather than a standalone espionage implant. Its operational value lies in enabling lateral access paths, relaying attacker traffic, and supporting persistence of access within Windows enterprise environments after initial compromise. Observed delivery was via attacker-deployed loaders in established intrusions, but high-confidence evidence does not support a single universal initial infection vector specific to go-socks5 itself.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The attackers also employed CE-Notes and LP-Notes stealers and go-socks5 reverse tunnels.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
SOCKS5-based reverse tunneling/proxy tool used to provide covert network access (reverse tunnels).
An open-source reverse tunneling proxy used for covert network access.
Named as an example of a reverse proxy tool used by threat actors generally, not specifically tied to the observed intrusion.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.