3proxy is an open-source, dual-use proxy-server utility that can provide HTTP, SOCKS, and reverse-proxy tunneling. Although legitimate in administrative contexts, it has been embedded or deployed by malicious operations to relay traffic through compromised hosts, traverse NAT and firewall boundaries, and maintain remote access. It has been observed as a native component of Android-based residential-proxy infrastructure, where compromised streaming devices were used as non-consensual proxy nodes and traffic could be routed through victims’ residential connections. A Windows backdoor associated with LaiXi Android Screen Mirroring embedded 3proxy and was assessed as using it to monitor and intercept network traffic. 3proxy has also been deployed in intrusions attributed with low-to-medium confidence to the North Korean Andariel group before DTrack and Maui ransomware activity, and in Lazarus-linked compromises of energy-sector organizations alongside reverse-tunneling tooling. It is listed among open-source and dual-use tools used or customized by Andariel.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Suspicious 3proxy tool... The “3Proxy” tool... was compiled on 2020-09-09 and deployed to the victim on 2020-12-25... used... to maintain access.
11 distinct techniques documented for this family, organized by ATT&CK tactic.
Netway registers with backend C2 applinked5.ukturks.store via HTTPS GET and has a second HTML C2 channel allowing the server to order authenticated HTTP requests from the residential IP.
These two tools working together create a proxy on the victim system which has its listening port 'exported' to a port on a remote host.
"...preceded by 3proxy months earlier." and "Using legitimate proxy and tunneling tools after initial infection or deploying them to maintain access"
Netway integrates 3proxy and uses a reverse 3proxy tunnel (-r 79.127.248.199:10975) to traverse NAT and firewalls; the infrastructure mapped more than 60,000 unique residential IPs.
4 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Open-source proxy server compiled into the malicious Netway SDK to provide reverse-tunnel residential proxy functionality on compromised devices.
A legitimate freeware proxy server embedded inside the malicious backdoor, assessed to be used for monitoring and intercepting network traffic on infected systems.
Legitimate proxy utility abused to stand up a local SOCKS/HTTP proxy on compromised hosts; used with SSH reverse tunneling (plink) to provide attacker-side access into victim networks.
Legitimate proxy/tunneling tool abused by the actor post-compromise to maintain access and support operations inside victim networks.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.