GSocket is an open-source peer-to-peer tunneling and remote access utility that enables encrypted TCP connectivity across NAT and firewall boundaries through a relay network. Although legitimate in origin, it is frequently repurposed by threat actors as a covert backdoor or reverse shell because it can provide persistent remote access without relying on conventional inbound connectivity.
Malicious use of GSocket has been documented across multiple intrusion sets and platforms. On macOS, modified GSocket builds have been deployed as the persistent backdoor component of ClickLock Stealer, where they remain installed after the stealer’s data-theft modules self-delete. In that role, GSocket provides attackers with long-term reverse shell access and has been observed persisting through LaunchAgents, cron, and shell configuration file modifications while masquerading as benign system software. On Linux, GSocket has been used after server compromise to maintain covert access, including in campaigns targeting Adobe Commerce and Magento environments and in broader Linux intrusion activity where operators disguised related processes as kernel threads or system processes. It has also been observed in post-exploitation activity against Cisco SD-WAN appliances and in Linux intrusion frameworks that abuse GSocket user-space tunnels for covert operator access or data movement.
When weaponized, GSocket is primarily used for persistent remote shell access, covert communications, and post-compromise control. Threat actors favor it for encrypted communications, relay-assisted connectivity, and its ability to blend into legitimate administrative or tunneling activity. Observed tradecraft includes process masquerading, persistence through scheduled tasks and startup scripts, and deployment as a modified or repackaged component alongside stealers, webshells, skimmers, miners, or other post-exploitation tooling. Targeting is therefore broad and opportunistic, spanning macOS endpoints, Linux servers, e-commerce infrastructure, and network appliances, depending on the intrusion set using it.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The binary file dropped in ~/.config/htop/defunct is identified as gsocket. The Global Socket Toolkit facilitates peer-to-peer TCP connections, even through NAT/Firewalls, using end-to-end encryption and a relay network.
The binary file dropped in ~/.config/htop/defunct is identified as gsocket. The Global Socket Toolkit facilitates peer-to-peer TCP connections, even through NAT/Firewalls, using end-to-end encryption and a relay network.
Cisco Talos said it observed multiple threat clusters exploiting CVE-2026-20133, CVE-2026-20128, and CVE-2026-20122 beginning March 2026. The three vulnerabilities, when chained together, can allow a remote unauthenticated attacker to gain unauthorized access to the device. They were added to the CISA's KEV catalog last month. The activity has been found to leverage publicly available proof-of-concept exploit code to deploy web shells on hacked systems.
Cisco Talos said it observed multiple threat clusters exploiting CVE-2026-20133, CVE-2026-20128, and CVE-2026-20122 beginning March 2026. The three vulnerabilities, when chained together, can allow a remote unauthenticated attacker to gain unauthorized access to the device. They were added to the CISA's KEV catalog last month. The activity has been found to leverage publicly available proof-of-concept exploit code to deploy web shells on hacked systems.
Cisco Talos said it observed multiple threat clusters exploiting CVE-2026-20133, CVE-2026-20128, and CVE-2026-20122 beginning March 2026. The three vulnerabilities, when chained together, can allow a remote unauthenticated attacker to gain unauthorized access to the device. They were added to the CISA's KEV catalog last month. The activity has been found to leverage publicly available proof-of-concept exploit code to deploy web shells on hacked systems.
26 distinct techniques documented for this family, organized by ATT&CK tactic.
Этот компонент предоставляет атакующим реверс-шелл и закрепляется через LaunchAgent, cron и конфигурационные шелл-файлы.
The backdoor establishes persistence through multiple methods, including a LaunchAgent, crontab entries, and modifications to shell configuration files.
Этот компонент предоставляет атакующим реверс-шелл и закрепляется через LaunchAgent, cron и конфигурационные шелл-файлы.
The backdoor establishes persistence through multiple methods, including a LaunchAgent, crontab entries, and modifications to shell configuration files.
The end goal of the compromises is to establish persistent, covert access on the host via GSocket ...
To ensure their access survived server reboots, file deletions, or malware cleanups, they established an hourly cron job
Этот компонент предоставляет атакующим реверс-шелл и закрепляется через LaunchAgent, cron и конфигурационные шелл-файлы.
The backdoor establishes persistence through multiple methods, including a LaunchAgent, crontab entries, and modifications to shell configuration files.
Затем ClickLock показывает жертве фальшивое системное окно с настоящим именем пользователя и иконкой Apple, предлагая ввести пароль.
SSH from Workstation B to Workstation A through any firewall/NAT $ gsocket /usr/sbin/sshd # Workstation A $ gsocket ssh root@gsocket # Workstation B
Talos is also aware of the widespread in-the-wild active exploitation of three vulnerabilities in unpatched Cisco Catalyst SD-WAN Manager infrastructure (CVE-2026-20133, CVE-2026-20128, and CVE-2026-20122) that, when chained together, can allow a remote unauthenticated attacker to gain access to the device.
the function zypeergsdeploy() helps to connect to a C2 server through GSocket
Access entirety of Workstation A's private LAN (Sock4/4a/5 proxy) $ gs-netcat -l -S # Workstation A (EXIT) $ gs-netcat -p 1080 # Workstation B
Uses the Global Socket Relay Network to connect TCP pipes... Once connected the library then negotiates a secure TLS connection(End-2-End).
Meanwhile, it pulls four modules in the background from compromised WordPress sites.
6 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A modified GSocket component is used as a persistent reverse-shell backdoor left behind by ClickLock Stealer after other modules self-delete.
A modified version of GSocket is installed by ClickLock as a persistent reverse-shell backdoor, masquerading on disk as iCloud and using the process name “SystemUIServerl”.
A modified GSocket backdoor is used by the ClickLock operation to maintain persistent remote access after the stealer components self-delete.
A persistent backdoor component installed by ClickLock Stealer on macOS, disguised as iCloud and masquerading as SystemUIServerl. It uses built-in persistence mechanisms including crontab injection, shell RC file infection, and LaunchAgent creation.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.