RevSocket is a Go-based reverse SOCKS proxy used as a post-compromise tunneling utility in intrusion campaigns assessed to be operated by an initial access broker supporting ransomware or extortion activity. It has been observed alongside GoGRPC, BlindDoor, PyGRPC, S3Siphon, and RSOX in operations that begin with social engineering through Microsoft Teams and Quick Assist, after which PowerShell-based staging deploys follow-on tooling on compromised Windows systems.
RevSocket establishes an outbound WebSocket connection protected with TLS to command-and-control infrastructure and uses yamux multiplexing to relay multiple tunneled TCP sessions over a single connection. Its role is to provide reverse proxying and network tunneling from an infected host, enabling operator access to internal resources and supporting downstream post-exploitation activity. The malware is associated with selective targeting of corporate environments and fits a toolkit designed to maintain access, facilitate remote operations, and prepare victim networks for further monetization by follow-on actors.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
7 distinct techniques documented for this family, organized by ATT&CK tactic.
ThreatLabz analyzed the functionality of these tools along with the command-and-control (C2) communication methods used by the attackers.
These tools provide capabilities ranging from remote command execution and network tunneling to data theft
RevSocket : proxy SOCKS inverse en Go ... PyGRPC : proxy SOCKS inverse en Python ... RSOX : ... proxy SOCKS relay
24 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Reverse SOCKS proxy written in Go using WebSocket over TLS with yamux multiplexing for post-compromise network pivoting.
A tool used in the same campaign, associated with remote command execution or network tunneling.
Additional malware used in the same campaigns alongside GoGRPC.
A Go-based reverse SOCKS proxy that establishes a TLS-protected WebSocket tunnel to C2 and multiplexes multiple TCP tunnels using yamux, enabling the operator to relay traffic through the compromised host.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.