Researchers reported that GhostSocks, a Golang-based SOCKS5 backconnect proxy sold as a malware-as-a-service, is tightly integrated with the LummaC2 infostealer ecosystem and can be automatically deployed on Lumma-infected hosts through a partnership promoted on Telegram. GhostSocks supports both Windows and Linux, stores an obfuscated JSON configuration in %APPDATA%\config, communicates with relay-based C2 infrastructure over HTTP, and assigns infected systems as Tier 1 backconnect nodes to create SOCKS5 tunnels for criminal customers. Analysts said the malware also enables arbitrary command execution, SOCKS5 credential changes, and download-and-execute activity, extending Lumma-compromised machines beyond credential theft into proxy infrastructure for follow-on abuse.
Separate analysis of LummaC2 v4.0 showed the stealer continuing to evolve with stronger evasion and anti-analysis features, including control-flow-flattening obfuscation, XOR-encrypted strings, dynamic C2-delivered configuration, and a two-layer packer designed to frustrate reverse engineering. KrakenLabs found Lumma delays execution until it detects human-like mouse movement, calculating cursor angles and restarting its checks if movement appears unnatural, a technique that can block detonation in sandboxes. The combined findings indicate that Lumma operators and affiliates are pairing a mature infostealer with a dedicated proxy service, while using anti-sandbox protections and hardened packing to reduce detection and sustain access.

Pull IOCs and campaign context straight into your stack.
5 events from the most recent confirmed update back to the earliest known activity.
Infrawatch says the GhostSocks sample they analyzed was observed on this date; the sample was heavily obfuscated and linked to relay-based C2 infrastructure.
GhostSocks expanded promotion to an English-speaking criminal forum under the moniker "GhostSocks," broadening its visibility beyond Russian-language venues.
A Telegram announcement introduced automatic provisioning of GhostSocks within the Lumma administration panel and discounted pricing for existing Lumma customers, indicating close integration between the two services.
Infrawatch reports GhostSocks was first identified in October 2023 when it was advertised on a Russian-language criminal forum as a SOCKS5 backconnect proxy malware service.
Outpost24 states that LummaC2, an information-stealing malware sold as a MaaS offering, has been sold in underground forums since December 2022.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.