rsocx is an open-source reverse SOCKS5 proxy tool used by threat actors to tunnel traffic from compromised systems to external infrastructure, enabling covert remote access, pivoting, and post-compromise communications across network boundaries. It has been observed in intrusions as a utility rather than a bespoke malware family, typically deployed after initial access to establish reverse proxy channels from internal hosts or appliances that would otherwise be difficult to reach directly.
Operational reporting links rsocx to multiple intrusion sets and campaigns. Scattered Spider has used rsocx on targeted ESXi appliances during post-compromise operations. PhantomCore has staged and deployed rsocx alongside other remote-access tooling from compromised legitimate servers. It was also used during the 2025 Poland wiper intrusions, including activity associated with DynoWiper deployment, where operators used a reverse SOCKS proxy to tunnel within victim infrastructure and maintain external connectivity.
The tool’s primary role is post-exploitation support: creating reverse connections, relaying traffic, and facilitating lateral access or operator control through SOCKS5 proxying. Its use is consistent with defense evasion and infrastructure-masking tradecraft because it helps adversaries bypass perimeter restrictions, avoid direct inbound exposure, and route follow-on activity through compromised assets. Reported deployments span both Windows and ESXi environments.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
PhantomCore gains access to servers of legitimate sites and later uses them to store samples of MeshAgent, PhantomTaskShell, and Rsocx.
Scattered Spider installed the open-source rsocx reverse proxy tool on a targeted ESXi appliance.
8 distinct techniques documented for this family, organized by ATT&CK tactic.
PhantomCore gains access to servers of legitimate sites and later uses them to store samples of MeshAgent, PhantomTaskShell, and Rsocx
Usage of the third-party tunneling tool Twingate... Tailscale, Ngrok, WsTunnel, Rsocx, and Socat.
T1090.001 Proxy: Internal Proxy PhantomCore использовали механизм проксирования трафика для организации связи между скомпрометированными узлами Rsocx, tsocks, wstunnel, microsocks, localtonet
Several entries mention use of proxy and tunneling tools including PLINK, Venom proxy, GOST reverse proxy, Ligolo, Cloudflared, rsocx reverse proxy, Iox proxy tool, NPS tunneling tool, and AirVPN.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Proxy/tunneling tool used to create a reverse SOCKS proxy for internal network traversal and communications over a non-standard port.
SOCKS5 proxy tool used to establish reverse connections to external servers, supporting attacker remote access and pivoting.
RSocx is used by PhantomCore as an external proxy/tunneling tool to relay traffic from infected hosts and support command-and-control communications.
Named as an example of a reverse proxy tool used by threat actors generally, not specifically tied to the observed intrusion.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.