WormSocket is a custom proxy tool used by the China-aligned APT group Webworm, which is also tracked as Space Pirates and UAT-8302. ESET reported it as part of Webworm’s 2025 tooling expansion alongside WormFrp, ChainWorm, and SmuxProxy, and assessed that the breadth and complexity of these proxy tools suggest the group may be building a larger covert proxy network from compromised systems. WormSocket is described as using configured servers running socket.io to establish a proxy for web requests. One referenced sample is MessengerClient.exe, detected by ESET as MSIL/HackTool.Proxy.I, with SHA-1 948159A7FC2E688386864BEA59FD40DFFC4B24D6. ESET also associated IP address 45.77.13[.]67 with a WormSocket web socket server, first seen on 2025-04-07; separate reporting noted that this host had exposed SOCKS5 on port 16755 in 2024 before later being confirmed as WormSocket infrastructure in 2025. Additional behavior noted for WormSocket includes message-class names InitiateForwarderClientReq, InitiateForwarderClientRep, SendDataMessage, and CheckInMessage. Within the broader Webworm campaign context, the malware was used in operations targeting government organizations in Belgium, Italy, Poland, Serbia, and Spain, as well as activity involving a university in South Africa.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
WormSocket (HIGH) -- adds message-class names InitiateForwarderClientReq , InitiateForwarderClientRep , SendDataMessage , CheckInMessage .
The group expanded its use of proxy tools. Existing proxy capabilities were supplemented with custom tools including WormFrp, ChainWorm, SmuxProxy, and WormSocket.
The group expanded its use of proxy tools. Existing proxy capabilities were supplemented with custom tools including WormFrp, ChainWorm, SmuxProxy, and WormSocket.
9 distinct techniques documented for this family, organized by ATT&CK tactic.
EchoCreep, GraphWorm, and WormSocket make use of HTTP and the WebSocket protocol.
WormFrp proxy tool. ... ChainWorm proxy tool. ... WormSocket proxy tool. ... SmuxProxy, a custom iox with hardcoded IP.
WormFrp, ChainWorm, WormSocket, SmuxProxy, and GraphWorm have the capability to connect to external proxies.
This confirms the actor delivers tools through operator-controlled open directories, not mass-mail or drive-by chains.
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A configurable proxy tool that uses socket.io/websocket infrastructure to establish scalable proxy nodes and forward web requests, supporting optional upstream proxy configuration.
A custom proxy tool used by Webworm as part of expanded proxy capabilities and likely hidden network infrastructure.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.