Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
MalwareRansomwareUsed by 2 actors

RSOCX

rsocx is an open-source reverse SOCKS proxy / SOCKS5 proxy tool used to establish reverse connections and tunnel traffic within compromised environments. The provided content describes it being used for covert tunneling, internal pivoting, and remote access, including reverse-connect operation over non-standard port 8008. It has been observed in multiple intrusion contexts rather than as a bespoke malware family. In the 2025 Poland wiper intrusions, adversaries used rsocx (including filenames r.exe and rsocx.exe) to create a reverse SOCKS proxy inside internal infrastructure; ESET reported attempted reverse-connect use to 31.172.71[.]5:8008 prior to DynoWiper deployment. In that incident, rsocx activity was associated with a broader multi-stage intrusion involving credential theft, reconnaissance, and eventual destructive malware deployment, and ESET noted the IP was likely a compromised host associated with progamevl[.]ru and hosted by Fornex Hosting S.L. The content also states PhantomCore stored or staged rsocx samples on compromised legitimate servers and used the utility alongside MeshAgent and other tools. Mandiant observed UNC3944 / Scattered Spider using covert tunneling tools including rsocx, and specifically reported Scattered Spider installing the open-source rsocx reverse proxy tool on a targeted ESXi appliance during activity cluster C0027. Across the cited reporting, rsocx is associated with Sandworm-linked destructive activity in Poland, PhantomCore operations, and Scattered Spider / UNC3944 intrusions, where it supports proxying, tunneling, and access to devices without relying on normal VPN or MFA pathways.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

THREAT ACTORS

Groups observed using it

2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
PhantomCore

PhantomCore gains access to servers of legitimate sites and later uses them to store samples of MeshAgent, PhantomTaskShell, and Rsocx.

via ptsecurity globalglobal.ptsecurity.com
Scattered Spider

Scattered Spider installed the open-source rsocx reverse proxy tool on a targeted ESXi appliance.

via mitre attack websiteattack.mitre.org
MITRE ATT&CK

Techniques & procedures

8 distinct techniques documented for this family, organized by ATT&CK tactic.

Resource Development

3 techniques
T1584.004ServerEvidence1

PhantomCore gains access to servers of legitimate sites and later uses them to store samples of MeshAgent, PhantomTaskShell, and Rsocx

T1588.002ToolEvidence3

The content repeatedly states that threat actors 'obtained,' 'acquired,' or 'used' publicly available, open-source, legitimate, or modified tools such as Mimikatz, Cobalt Strike, PsExec, Empire, Impacket, and many others.

T1608.002Upload ToolEvidence1

PhantomCore uploads MeshAgent and RSocx to directories on compromised legitimate sites and phishing sites, and uploads XenArmor All‑In‑One Password Recovery Pro and RClone to VPS servers

Command and Control

5 techniques
T1090ProxyEvidence3

During the 2025 Poland Wiper Attacks, the adversaries utilized the rsocx tool identified as r.exe and rsocx.exe to tunnel within the internal infrastructure using a Reverse SOCKS Proxy.

T1090.001Internal ProxyEvidence2

T1090.001 Proxy: Internal Proxy PhantomCore использовали механизм проксирования трафика для организации связи между скомпрометированными узлами Rsocx, tsocks, wstunnel, microsocks, localtonet

T1090.002External ProxyEvidence2

Several entries mention use of proxy and tunneling tools including PLINK, Venom proxy, GOST reverse proxy, Ligolo, Cloudflared, rsocx reverse proxy, Iox proxy tool, NPS tunneling tool, and AirVPN.

T1219Remote Access ToolsEvidence1

The following are persistence tools that Scattered Spider deployed on various hosts in the customer’s environment: PDQConnectAgent ScreenConnect fleet.io rsocx

T1571Non-Standard PortEvidence1

During the 2025 Poland Wiper Attacks, the adversaries had created a Reverse SOCKS Proxy and communicated over the non-standard port 8008.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution2

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping8

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.