ProxyChains is an open-source UNIX utility that forces network traffic through proxy servers. In the provided reporting, it is referenced as a tool used for network tunneling and traffic redirection on Linux. Unit 42 included ProxyChains among the publicly available tools observed in 2024 intrusion activity tracked as CL-STA-0969, which targeted telecommunications providers in Southwest Asia and overlapped with activity attributed to Liminal Panda. In that context, ProxyChains was used alongside other tunneling, proxying, and pivoting tools such as EarthWorm, Chisel, FRP, and Microsocks to support covert access and lateral movement. The content does not provide malware-specific persistence, payload, or infection-vector details for ProxyChains beyond its use as a proxying/tunneling utility on UNIX/Linux systems, and no ProxyChains-specific indicators of compromise are provided.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
“ProxyChains is an open-source UNIX program that forces the transmission of network traffic through different proxies.”
7 distinct techniques documented for this family, organized by ATT&CK tactic.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
ProxyChains is a tool that forces any TCP connection made by any given application to follow through proxy servers like TOR or any other SOCKS4, SOCKS5, and HTTP(S) proxies, often used for network tunneling and evasion.
Open-source proxy chaining utility used to route traffic (e.g., SCP file transfer) through configured proxies for pivoting/obfuscation.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.