Rsockstun is an open-source reverse SOCKS tunneling utility used to establish tunnels from compromised environments to attacker-controlled command-and-control infrastructure. In the provided reporting, a modified variant was observed as "rr.exe" and described as a modified open-source reverse socks tunneler named Rsockstun. It has been used post-compromise to create dedicated conduits into affected network segments and to facilitate delivery of next-stage payloads. The content associates its use with Russian state-linked activity: Microsoft reported Seashell Blizzard (Sandworm/APT44/GRU Unit 74455) deploying tunneling utilities such as Chisel, plink, and rsockstun during its BadPilot campaign, and a joint advisory on SVR activity exploiting JetBrains TeamCity CVE-2023-42793 stated that operators used a modified Rsockstun-based reverse SOCKS tunneler to tunnel into compromised environments. Reported associated infrastructure for the modified TeamCity-related use included 65.20.97[.]203:443 and poetpages[.]com:8443. High-confidence context indicates use against compromised enterprise and government environments, including globally targeted internet-facing infrastructure and sectors such as energy, oil and gas, telecommunications, shipping, arms manufacturing, and government.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
...deploying tunneling utilities such as Chisel, plink, and rsockstun to established dedicated conduits into affected network segments.
“…‘rr.exe’—a modified open source reverse socks tunneler named Rsockstun—to establish a tunnel to the C2 infrastructure.”
“…‘rr.exe’—a modified open source reverse socks tunneler named Rsockstun—to establish a tunnel to the C2 infrastructure.”
1 distinct technique documented for this family, organized by ATT&CK tactic.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Tunneling tool used to proxy network traffic, often for evasion or persistence.
Tunneling utility used by the subgroup to establish reverse tunnels and maintain access.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.