rsocx is a publicly available, open-source reverse SOCKS5 proxy tool used by threat actors to tunnel traffic through compromised systems. It establishes outbound reverse connections to external servers, providing a communications path into internal infrastructure and supporting remote access and network pivoting. Its tunneling functionality has been used to maintain access without relying on victims’ normal VPN and multifactor-authentication workflows. It is a dual-use networking utility rather than a purpose-built credential stealer, ransomware family, or destructive payload.
Observed deployments include Windows environments and VMware ESXi appliances. Scattered Spider, also tracked as UNC3944, has installed rsocx on compromised infrastructure, including an ESXi appliance and attacker-created virtual machines. Toy Ghouls has used it for traffic proxying and command-and-control communications. PhantomCore has staged rsocx on compromised legitimate web servers and phishing sites alongside other intrusion tools. The utility was also used for internal tunneling during the December 2025 destructive attacks against Polish infrastructure, including a DynoWiper incident at an energy company. These deployments demonstrate its role as a post-compromise access and communications tool across financially motivated and destructive operations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Various covert tunneling tools, such as NGROK, RSOCX, and Localtonet. The use of these tools allowed UNC3944 access to the device without the need to use VPN or MFA.
Toy Ghouls used Rsocx samples that established connections to C2 servers previously observed in Head Mare activity.
PhantomCore gains access to servers of legitimate sites and later uses them to store samples of MeshAgent, PhantomTaskShell, and Rsocx.
8 distinct techniques documented for this family, organized by ATT&CK tactic.
PhantomCore gains access to servers of legitimate sites and later uses them to store samples of MeshAgent, PhantomTaskShell, and Rsocx
Usage of the third-party tunneling tool Twingate... Tailscale, Ngrok, WsTunnel, Rsocx, and Socat.
T1090.001 Proxy: Internal Proxy PhantomCore использовали механизм проксирования трафика для организации связи между скомпрометированными узлами Rsocx, tsocks, wstunnel, microsocks, localtonet
The group uses reverse SSH tunnels with -R port forwarding and tools including GOST, rsocx, cloudflared, and localtonet to redirect traffic.
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Proxy/tunneling tool used to create a reverse SOCKS proxy for internal network traversal and communications over a non-standard port.
Proxy/tunneling utility used by Toy Ghouls for traffic forwarding and communications with C2 infrastructure.
SOCKS5 proxy tool used to establish reverse connections to external servers, supporting attacker remote access and pivoting.
RSocx is used by PhantomCore as an external proxy/tunneling tool to relay traffic from infected hosts and support command-and-control communications.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.