Socks5Systemz is a Windows proxy-bot malware family that converts infected systems into remotely controlled SOCKS-style traffic-forwarding nodes. It has been distributed as a final payload by loaders including PrivateLoader and Amadey, including through pay-per-install operations and cracked-software lures. The malware has also historically been deployed as a proxy component by other commodity malware families.
Socks5Systemz establishes persistence primarily through a Windows service, with some variants falling back to replacement of a legitimate updater or other autostart mechanisms when service installation fails. Loaders decrypt a DLL-based proxy payload and inject or memory-load it, reducing its on-disk exposure. The malware uses a generated victim identifier, periodically contacts command-and-control infrastructure, and employs a domain-generation mechanism with a fallback C2-discovery mechanism. Its C2 discovery and beacon traffic use RC4 encryption over web protocols.
The bot accepts commands to connect, disconnect, idle, and update proxy or C2 configuration. On instruction, an infected host connects to a backconnect server and receives a unique port through which an authorized customer can relay traffic. Proxy access can be controlled through source-address allowlisting or username-and-password authentication. The resulting residential proxy capacity has been commercialized through services including PROXY.AM and its successor ProxyBox, and has been associated with carding, credential stuffing, and identity-theft activity. Socks5Systemz has infected systems globally and has been active since at least 2016.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
« Une infection ultérieure (juin 2026) a livré GCleaner et Socks5Systemz via la même infrastructure. »
30 distinct techniques documented for this family, organized by ATT&CK tactic.
In an attempt to regain their once previous numbers the ProxyBox operators are observed utilizing pay per install (PPI) sites which distribute the malware through cracked software sites... These sites utilize NSIS installers which will dynamically install a series of applications.
Using a bot named BoostyProxy, the threat actor built a complete proxy service that allows users to subscribe to the service, manage the existing subscriptions, and access the current list of available proxies.
The install option is responsible for setting up the persistence on the system and to do so it will try to copy the loader to C:\ProgramData\ContentDWSvc\ContentDWSvc.exe and create a Windows service to run the copied loader with both the name and display name set to ContentDWSvc.
The loader main function will load the resource with ID 400 to memory and decrypt it. The decrypted data will be a valid DLL file containing the proxy bot that will be injected in memory.
The install option is responsible for setting up the persistence on the system and to do so it will try to copy the loader to C:\ProgramData\ContentDWSvc\ContentDWSvc.exe and create a Windows service to run the copied loader with both the name and display name set to ContentDWSvc.
The final payload of Socks5Systemz... heavily relies on junk code and control-flow obfuscation, making static analysis challenging.
I had been surprised to see the malware was signed. (I was new, this form of trust abuse was unknown to me.)
The loader main function will load the resource with ID 400 to memory and decrypt it. The decrypted data will be a valid DLL file containing the proxy bot that will be injected in memory.
Chunks of the encrypted payload are embedded within the .text section... Once the loader stub decrypts the second stage module... To decrypt the resource, it extracts a 32-byte key from the end of the resource... Both requests and responses are RC4 encrypted using the same RC4 encryption key.
The first operation the loader will perform in the main function is to register a service control handle... The advantage of this design decision is that it allows the module to function both as a service and as a regular PE/EXE.
Before unpacking, the loader will sleep in a loop to delay execution, both before and in the middle of the memory loading process.
It also uses timestamp stomping, showing that it was compiled in 2011, which is false.
If file copy or service creation fails, the loader will try to kill all Google update processes and replace the GoogleUpdate.exe original executable by itself.
If file copy or service creation fails, the loader will try to kill all Google update processes and replace the GoogleUpdate.exe original executable by itself.
The plain text beacon string has the following format: client_id=%.8x&connected=%d&server_port=%d&debug=%d&os=%d.%d.%04d&dgt=%d&dti=%d
Next, the bot generates a 32-bit client ID based on the creation date of the Windows directory on the infected system.
The data that goes in the c= parameter is the hex encoded result of encrypting the beacon string using the same RC4 key heyfg645fdhwi. The responses from the command and control servers are also hex encoded and encrypted using the same RC4 key.
Process 4440 is also seen communicating with its C2 server, 185[.]216.70.235 and 195.20.16[.]45 via port 80 (T1071 – Application Layer Protocol).
After getting the IP address of an active command and control server, the bot is ready to start the C2 communications by doing a HTTP GET request to the following endpoint /single.php?c=<rc4 data hex encoded>.
This sample, upon reverse engineering, was found to install a proxy bot on infected systems, turning them into proxies capable of forwarding traffic for someone else.
"Socks5Systemz Botnet Powers Illegal Proxy Service with 85,000+ Hacked Devices"
"Socks5Systemz Botnet Powers Illegal Proxy Service with 85,000+ Hacked Devices"
Additionally, it fetches a PDF file from hxxp://datasheet[.]fun/manual/avon_4_2022.pdf?<client_id> , saving it in the C:\ProgramData folder.
Finally, the bot tries to get the address of a C2 server that's online. To do so, the bot computes a domain name using a domain generation algorithm and uses a hardcoded list of DNS servers to resolve it.
172 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Botnet nommé distribué par la même infrastructure PPI lors d'une infection observée en juin 2026 ; aucune fonctionnalité supplémentaire n'est décrite dans le contenu.
A named payload delivered by the same OfferLoader-backed CL-CRI-1171 distribution infrastructure; the content provides no further technical characterization.
Proxy malware cited as a follow-on payload delivered by Amadey.
A malware family used to build and operate a large residential proxy botnet. It is distributed via cracked software and loaders, installs persistence via service or registry run key, unpacks a DLL payload in memory, and communicates with C2 servers over HTTP/HTTPS using RC4-encrypted parameters to receive commands such as connect, disconnect, idle, updips, and updurls.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.