Skip to main content
Mallory
Back to malware
MalwareUsed by 2 actorsExploits 1 CVE

ReverseSocks5

ReverseSocks5 is an open-source reverse SOCKS5 proxy and proxy tunneling utility, written in Go, used to establish outbound SOCKS5 proxy tunnels from compromised systems to attacker-controlled infrastructure for command and control, persistence, and continued access. The content describes it as a publicly available networking/tunneling tool rather than bespoke malware. It was observed in post-exploitation activity following exploitation of Palo Alto Networks PAN-OS CVE-2026-0300, where suspected state-linked activity tracked by Unit 42 as CL-STA-1132 deployed ReverseSocks5 alongside EarthWorm on compromised PA-Series and VM-Series firewalls. In that activity, attackers achieved root-level access, injected shellcode into nginx worker processes, extracted credentials from the firewall, enumerated Active Directory, deleted logs and crash artifacts, and used ReverseSocks5 for outbound command and control and proxy tunneling; reporting also states the attackers downloaded ReverseSocks5 onto a secondary firewall after forcing HA failover via a SAML flood. The content also links ReverseSocks5 to the China-aligned espionage group LongNosedGoblin, which reportedly used NosyDownloader to deploy ReverseSocks5, NosyLogger, and an argument runner in campaigns targeting government entities in Southeast Asia and Japan. Separately, BI.ZONE reporting says the actor tracked as Cavalry Werewolf executed ReverseSocks5 and ReverseSocks5Agent on compromised hosts during phishing-led intrusions targeting the Russian public sector and related industries. A specific download IOC mentioned in the content is hxxps[:]//github[.]com/Acebond/ReverseSocks5/releases/download/v2.2.0/ReverseSocks5-v2.2.0-linux-amd64.tar[.]gz.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

EXPLOITED CVES

Vulnerabilities exploited

1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.

1 CVES
CVE-2026-0300Unauthenticated RCE in Palo Alto PAN-OS User-ID Authentication Portal (Captive Portal)Exploited in the wild

CVE-2026-0300 is an unauthenticated buffer overflow in the User-ID Authentication Portal (Captive Portal) service of PAN-OS. The vendor advisory states that exploitation yields arbitrary code execution with root privileges on PA-Series and VM-Series firewalls... exploitation has been observed since April 9, 2026, with successful remote code execution achieved by April 16, 2026. | Observed post-exploitation activity includes shellcode injection into the nginx worker process on the firewall, Active Directory enumeration using credentials extracted from the firewall, anti-forensic log cleanup, and deployment of network tunneling tools (EarthWorm, ReverseSocks5) for outbound command and control.

via censys othercensys.com
THREAT ACTORS

Groups observed using it

2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
CL-STA-1132

Развёртывание EarthWorm и ReverseSocks5 для SOCKS5-туннелирования

via codebycodeby.net
Cavalry Werewolf

Also executed on the compromised hosts are tools like ReverseSocks5Agent and ReverseSocks5, as well as commands to gather device information.

via the hacker newsthehackernews.com
MITRE ATT&CK

Techniques & procedures

5 distinct techniques documented for this family, organized by ATT&CK tactic.

T1071Application Layer ProtocolEvidence1

Then they deployed EarthWorm and ReverseSocks5 tunnels for outbound C2

T1090ProxyEvidence7

Observed post-exploitation activity includes... deployment of network tunneling tools (EarthWorm, ReverseSocks5) for outbound command and control.

T1090.002External ProxyEvidence1

Then they deployed EarthWorm and ReverseSocks5 tunnels for outbound C2

T1105Ingress Tool TransferEvidence1

Post-exploitation activities conducted by the adversary included conducting Active Directory (AD) enumeration and dropping additional payloads like EarthWorm and ReverseSocks5 against a second device on April 29, 2026.

T1572Protocol TunnelingEvidence1

Command & Control Proxy (T1090) / Protocol Tunneling (T1572) Развёртывание EarthWorm и ReverseSocks5 для SOCKS5-туннелирования

ACTIVITY FEED

Recent activity

10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution2

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities1

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping5

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.