GSocket, also known as the Global Socket Toolkit, is an open-source peer-to-peer proxying and tunneling utility that uses an encrypted relay network to establish TCP connectivity across NAT and firewall boundaries. Threat actors frequently repurpose or modify it as a covert backdoor and reverse-shell mechanism. Observed malicious deployments use GSocket to maintain persistent remote access, establish encrypted command-and-control channels, and tunnel traffic that might otherwise be blocked or visible through conventional network controls. Operators have used process-name masquerading, cron jobs, shell-profile modifications, and macOS LaunchAgents to conceal and persist GSocket-based implants. Modified GSocket deployments have appeared in Linux server intrusions, including compromises involving exposed enterprise applications and e-commerce platforms, and in the ClickLock macOS infostealer operation, where it remains after data theft to provide durable remote access. GSocket has also been used for covert rsync-based data staging and transfer through user-space tunnels.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The binary file dropped in ~/.config/htop/defunct is identified as gsocket. The Global Socket Toolkit facilitates peer-to-peer TCP connections, even through NAT/Firewalls, using end-to-end encryption and a relay network.
The binary file dropped in ~/.config/htop/defunct is identified as gsocket. The Global Socket Toolkit facilitates peer-to-peer TCP connections, even through NAT/Firewalls, using end-to-end encryption and a relay network.
Cisco Talos said it observed multiple threat clusters exploiting CVE-2026-20133, CVE-2026-20128, and CVE-2026-20122 beginning March 2026. The three vulnerabilities, when chained together, can allow a remote unauthenticated attacker to gain unauthorized access to the device. They were added to the CISA's KEV catalog last month. The activity has been found to leverage publicly available proof-of-concept exploit code to deploy web shells on hacked systems.
Cisco Talos said it observed multiple threat clusters exploiting CVE-2026-20133, CVE-2026-20128, and CVE-2026-20122 beginning March 2026. The three vulnerabilities, when chained together, can allow a remote unauthenticated attacker to gain unauthorized access to the device. They were added to the CISA's KEV catalog last month. The activity has been found to leverage publicly available proof-of-concept exploit code to deploy web shells on hacked systems.
Cisco Talos said it observed multiple threat clusters exploiting CVE-2026-20133, CVE-2026-20128, and CVE-2026-20122 beginning March 2026. The three vulnerabilities, when chained together, can allow a remote unauthenticated attacker to gain unauthorized access to the device. They were added to the CISA's KEV catalog last month. The activity has been found to leverage publicly available proof-of-concept exploit code to deploy web shells on hacked systems.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
“Feral Wolf used command execution within the compromised Confluence Docker container to deploy the GSocket utility.”
26 distinct techniques documented for this family, organized by ATT&CK tactic.
Этот компонент предоставляет атакующим реверс-шелл и закрепляется через LaunchAgent, cron и конфигурационные шелл-файлы.
With command execution via PostgreSQL, Feral Wolf installed GSocket and configured it to start automatically ... var\spool\cron\postgres, a job added to crontab.
Этот компонент предоставляет атакующим реверс-шелл и закрепляется через LaunchAgent, cron и конфигурационные шелл-файлы.
With command execution via PostgreSQL, Feral Wolf installed GSocket and configured it to start automatically ... var\spool\cron\postgres, a job added to crontab.
The third backdoor is by using a webshell of tmate[.]io... TeamTNT is utilizing this tool as a backdoor. The fourth backdoor is by utilizing a socket connected over HTTP service with Ngrok product.
To ensure their access survived server reboots, file deletions, or malware cleanups, they established an hourly cron job
Этот компонент предоставляет атакующим реверс-шелл и закрепляется через LaunchAgent, cron и конфигурационные шелл-файлы.
With command execution via PostgreSQL, Feral Wolf installed GSocket and configured it to start automatically ... var\spool\cron\postgres, a job added to crontab.
RUDEDEVIL configuration blobs and custom apache2 strings are XOR-encoded; the GSOCKET cron payload is Base64-encoded.
The attackers used exec -a to modify the displayed process name, disguising it as a Linux kernel thread.
GSOCKET executes with exec -a [process_name], masquerading as kernel processes including [raid5wq] and [mm_percpu_wq].
00.sh deletes log files and execution traces; downloaded l64 and l86 payloads are removed after execution.
After installation, GSOCKET ensures that all files created or modified are timestomped to erase traces of installation.
Numerous new tools have been used to support command and control (C2) and stealth. These include publicly available tools like Nezha... and GSocket, which allows workstations on different private networks to connect and bypass firewalls.
Payloads are transferred through HTTP wget/curl requests; the gambling automation script uses HTTP GET and POST requests; Telegram communication uses POST requests.
GSOCKET supports Telegram webhooks, and a second-stage script sends command output to a Telegram chat bot.
The actors repeatedly downloaded scripts and binaries with wget and curl, including KAIJI, RUDEDEVIL, GSOCKET, XMRIG, pspy64, and custom payloads.
The fourth installed GSocket, an open-source reverse-shell tool reused with roughly 80% of its original code, disguised on macOS as an iCloud process.
10 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
18 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
GSocket samples were listed among the campaign indicators; no further behavior is described in the content.
A remote-access and tunneling utility deployed by Feral Wolf for persistent access in a compromised Confluence container and later on the Docker host. The actor disguised its processes as Linux kernel threads and configured automatic startup.
Tool used by the Medusa operators as part of their command-and-control stack.
A modified GSocket component is used as a persistent reverse-shell backdoor left behind by ClickLock Stealer after other modules self-delete.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.