Darktrace reported rising activity tied to GhostSocks, a Go-based malware-as-a-service offering advertised on the Russian-language forum xss[.]is, which turns infected systems into residential SOCKS5 proxy nodes. The malware is designed to help threat actors evade IP-based detection and geographic restrictions by routing traffic through victim devices, using a relay-based command-and-control architecture and TLS-wrapped proxy traffic for stealth. Later variants added persistence through Windows registry run keys and expanded functionality beyond proxying to include backdoor features for arbitrary command execution and payload delivery.
The company said GhostSocks saw broader adoption after a 2024 partnership with Lumma Stealer and has also been linked to use by the Black Basta ransomware group for maintaining long-term access. In a December 2025 incident at an education-sector organization, a device contacted Lumma-linked infrastructure, downloaded a GhostSocks-associated executable called Renewable.exe, retrieved additional payloads from suspicious endpoints, and began likely early-stage beaconing to rare external destinations. Darktrace said blocking actions were recommended multiple times, but because the customer was operating in Human Confirmation Mode, mitigations were not automatically enforced, allowing the activity to continue.

Get the actors, campaigns, and ATT&CK mapping behind it.
8 events from the most recent confirmed update back to the earliest known activity.
Darktrace published detailed reporting on GhostSocks, describing its architecture, persistence mechanisms, Lumma partnership, and observed customer activity. The reports warned that infrastructure takedowns alone are unlikely to stop abuse because operators can quickly rebuild and continue monetizing victim systems as proxy nodes.
During the December 2025 education-sector incident, Darktrace's Autonomous Response repeatedly recommended blocking actions. Because the customer was operating in Human Confirmation Mode, the mitigations were not automatically enforced and the activity continued.
In December 2025, Darktrace observed an education-sector customer device contact infrastructure linked to Lumma and download a GhostSocks-associated executable, identified in one report as Renewable.exe. The host then retrieved additional payloads from suspicious endpoints and began likely early-stage command-and-control beaconing.
From late 2025, Darktrace said it observed increasing GhostSocks-related activity across its customer base. The trend suggested growing operational use of the malware in real-world intrusions.
SpyCloud Labs published analysis of GhostSocks on 2025-03-25, detailing its linkage to LummaC2, registry run-key persistence, static embedded configuration with dynamic C2 updates, and TLS 1.3-wrapped SOCKS5 relay traffic. The report also released a YARA rule, sample hashes, infrastructure IPs, and build distinctions tied to different GhostSocks creation methods.
GhostSocks was reportedly used by the Black Basta ransomware group to maintain long-term access in victim environments. This reflected the malware's role beyond proxying, including persistence and backdoor-style access.
In 2024, GhostSocks reportedly saw broader adoption after a partnership with Lumma Stealer was announced. The linkage helped expand its use among threat actors seeking stealthy residential proxy access and follow-on intrusion capability.
GhostSocks emerged as a Go-based malware-as-a-service offering on the Russian-language forum xss[.]is, marketed to turn infected devices into residential SOCKS5 proxies. Its capabilities included relay-based command-and-control, TLS-wrapped proxy traffic, and backdoor functions for command execution and payload delivery.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 89 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
3 references tracked. Mallory keeps watching after this page renders.
darktrace.com
Open sourcedarktrace.com
Open sourcespycloud.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.