Skip to main content
Mallory
MalwareUsed by 3 actors

ChainWorm

ChainWorm is a custom proxy tool used by the China-aligned Webworm intrusion set, also tracked as Space Pirates and UAT-8302. ESET reported Webworm expanded its proxy tooling in 2025 with WormFrp, ChainWorm, SmuxProxy, and WormSocket, and assessed that the breadth and complexity of these tools suggest the group may be building a larger covert proxy network from compromised systems. ChainWorm’s stated main function is to assist in expanding Webworm’s proxy infrastructure by opening a port on the compromised machine where it is deployed. The malware is associated with the sample svc.exe, SHA-1 7DCFE9EE25841DFD58D3D6871BF867FE32141DFB, which ESET detects as MSIL/HackTool.Proxy.H. Additional analysis notes a .NET MSIL proxy sample tied to this cluster contained a PDB path with the username "hello," suggesting shared developer artifacts with other Webworm tooling. Detection context also references a SOCKS5-related byte sequence used to identify ChainWorm, with logic to distinguish it from WormFrp. High-confidence targeting context comes from Webworm reporting rather than ChainWorm-specific deployment records: in 2025 Webworm targeted government organizations in Belgium, Italy, Poland, Serbia, and Spain, and activity also involved a university in South Africa.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

THREAT ACTORS

Groups observed using it

3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
Webworm

ChainWorm (MEDIUM-HIGH) -- promoted from scaffold; matches on the SOCKS5-error byte sequence 05 01 00 01 00 00 00 00 00 00 , with a guard against WormFrp.

via github gist webgist.github.com
Space Pirates

The group expanded its use of proxy tools. Existing proxy capabilities were supplemented with custom tools including WormFrp, ChainWorm, SmuxProxy, and WormSocket.

via help net securityhelpnetsecurity.com
UAT-8302

The group expanded its use of proxy tools. Existing proxy capabilities were supplemented with custom tools including WormFrp, ChainWorm, SmuxProxy, and WormSocket.

via help net securityhelpnetsecurity.com
MITRE ATT&CK

Techniques & procedures

4 distinct techniques documented for this family, organized by ATT&CK tactic.

T1090ProxyEvidence5

WormFrp proxy tool. ... ChainWorm proxy tool. ... WormSocket proxy tool. ... SmuxProxy, a custom iox with hardcoded IP.

T1090.001Internal ProxyEvidence1

ChainWorm and WormSocket can create internal proxies.

T1090.002External ProxyEvidence1

WormFrp, ChainWorm, WormSocket, SmuxProxy, and GraphWorm have the capability to connect to external proxies.

T1090.003Multi-hop ProxyEvidence2

WormSocket and ChainWorm create multiple proxy hops.

INDICATORS OF COMPROMISE

IOCs tracked for this family

1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.

View more in app
Hashes
1 tracked

File hashes (MD5, SHA-1, SHA-256) from samples and reports.

TypeValueLatest sighting
hash.sha1●●●●●●●●●●●●View more in app14 days ago
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching1

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution3

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping4

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.