GhostSocks is a Go-based proxy malware family and malware-as-a-service offering that converts compromised Windows systems into residential SOCKS5 proxy nodes. It is designed to let operators route traffic through victim devices so malicious activity appears to originate from legitimate home or office connections, helping evade IP reputation controls, geofencing, anti-fraud systems, and some device- or location-based authentication checks. Recent variants have been observed wrapping proxy traffic in TLS, improving stealth over earlier implementations that used less protected communications.
The malware is commonly deployed as a secondary payload alongside credential theft malware, especially Vidar and LummaC2. Public reporting has linked GhostSocks closely to the LummaC2 ecosystem, including use as a post-compromise reverse proxy capability that gives operators a backconnect channel into infected machines. This enables attackers to operate from the victim’s network context and can support abuse of stolen sessions or tokens. GhostSocks has also been reported in campaigns associated with fake software installers and AI-themed lures, including trojanized repositories and installers impersonating tools such as Claude Code, DeepSeek, and OpenClaw.
Functionally, GhostSocks establishes contact with command-and-control infrastructure, registers the infected host, and receives relay information used to expose proxy access through the victim machine. Analyses of newer samples indicate that binaries may contain embedded static configuration data, including affiliate or build metadata and initial controller information, while also supporting dynamic updates to controller infrastructure after check-in. Some variants implement persistence on Windows through autorun mechanisms, while earlier variants reportedly lacked built-in persistence. Reporting also indicates the malware can include backdoor-like capabilities for arbitrary command execution and delivery of additional payloads, extending its utility beyond simple proxying.
GhostSocks has been marketed on Russian-language cybercrime forums and is used by financially motivated threat actors as part of broader criminal operations. Its adoption appears to have increased after collaboration with LummaC2 operators. It has been observed in opportunistic malware distribution campaigns targeting developers and general users through search poisoning, fake GitHub repositories, malicious installers, and software impersonation. Victims have included home users, office users, and organizations in sectors such as education, while the malware’s residential proxy capability makes it broadly useful for fraud, stealthy follow-on intrusion activity, and resale of proxy access to other criminal actors. Reporting has also associated GhostSocks with long-term covert access in ransomware-related operations, including claimed use by Black Basta.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
19 distinct techniques documented for this family, organized by ATT&CK tactic.
For web searches such as “DeepSeek v4 weights GitHub,” the malicious repository and its forks were positioned among top results, at times appearing ahead of official references like the Hugging Face release page.
GhostSocks executes this command with PowerShell, which means defenders should be on the lookout for the above command string as it could be indicative of a GhostSocks infection.
MITRE ATT&CK Mapping Technique Mapping Evidence T1106 Native API Native DLL loaded via Electron FFI.
Some of these values are obfuscated using GhostSock’s custom obfuscation algorithm, which splits each string into four (4) byte chunks and then uses arithmetic shifts to reveal the deobfuscated text... After GhostSocks assembles its JSON configuration dictionary, it encrypts the dictionary with XOR using the key “config”
After GhostSocks assembles its JSON configuration dictionary, it encrypts the dictionary with XOR using the key “config” and sends it to one of the C2s contained in its hardcoded C2 list in a basic request... While older samples communicate over HTTP, newer samples have been spotted leveraging HTTPS...
MITRE ATT&CK Mapping Technique Mapping Evidence T1071.001 Web Protocols HTTPS /register and /ping C2.
MITRE ATT&CK Mapping Technique Mapping Evidence T1090 Proxy Backconnect/proxy strings and yamux-based session code.
Within four hours, victims were downloading malware associated with Vidar infostealer and GhostSocks proxy malware.
115 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
28 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned only as an example of another malware family that uses SOCKS5 traffic.
Additional downstream payload documented in related research as part of the broader fake-AI lure ecosystem alongside Vidar.
Additional downstream malware documented by external research as part of the broader fake-AI lure ecosystem alongside Vidar.
Malware distributed through fake repositories themed around the Claude Code leak; likely used to provide covert access or proxy functionality based on its name, but the content does not further specify.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.