RevSocks is a reverse-SOCKS tunneling and proxy utility used by multiple threat actors to create covert access channels from compromised systems to attacker-controlled infrastructure. It is commonly employed as post-compromise tradecraft rather than as a standalone initial infection payload, enabling operators to proxy traffic such as Remote Desktop Protocol sessions, maintain redundant command-and-control paths, and support data exfiltration or persistent remote access.
The tool has been observed in intrusions involving espionage and disruptive actors, including Mantis (also known as Arid Viper, Desert Falcon, and APT-C-23), Cloud Atlas, MoustachedBouncer, and activity associated with Homeland Justice. In these operations, RevSocks was used on Windows systems as a reverse proxy or reverse SOCKS tunnel, sometimes over port 443, and in some cases alongside Tor or other tunneling utilities to conceal operator origin and preserve access if other channels were removed. It has also been seen in ransomware-related intrusions where attackers combined it with other proxy and tunneling tools to maintain covert connectivity during credential theft, lateral movement, and enterprise-wide deployment activity.
RevSocks is associated with defense evasion and persistence-oriented post-exploitation because it helps attackers traverse network boundaries, bypass inbound access restrictions, and blend malicious traffic into normal outbound communications. Its operational role is to relay attacker traffic through a compromised host, supporting command and control, remote administration, and potentially exfiltration, rather than to deliver a destructive or self-propagating payload itself.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
These included: Arid Gopher ... Reverse SOCKs Tunneler (aka Revsocks) (file name: windowsservicemanageav.exe)
In some cases, the group also deployed RevSocks, a Go-based proxy tool, and used Tor to route RDP access through hidden .onion addresses.
MoustachedBouncer has used a reverse proxy tool similar to the GitHub repository revsocks.
10 distinct techniques documented for this family, organized by ATT&CK tactic.
...established redundant remote access channels using revsocks, Chisel, and Cloudflare tunnels.
For covert command-and-control, the operator ran a reverse-SOCKS proxy (revsocks) to an external IP on port 443
Three separate network-tunneling utilities were deployed to the host in the first 10 minutes of activity.
Payloads and tools were delivered from the same external IP and from two external staging domains, in some cases, using .jpg extensions to disguise the files.
3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A reverse SOCKS proxy tool used by the attackers for covert command-and-control and redundant connectivity within the victim environment.
A Go-based proxy tool used by Cloud Atlas to create covert access channels and support remote operations through layered persistence.
Tool used for data exfiltration, command-and-control communications, and/or maintaining persistent access within compromised networks.
A reverse SOCKS tunneling utility used as a secondary payload by Micropsia to create a reverse SOCKS tunnel to external infrastructure, enabling covert access into compromised environments.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.