Splunk released an Enterprise Security analytic to detect socat processes that pair exec: with -listen: arguments, a pattern that can bind an executable to inbound TCP or OpenSSL connections. The resulting listener can provide a bind shell, remote command execution, lateral movement, or command-and-control (C2) tunneling. The detection generates notable findings and risk events from endpoint process telemetry; defenders should tune it for legitimate development, debugging, protocol testing, and network-troubleshooting activity.
Protocol tunneling remains a widely used ATT&CK technique (T1572) for concealing C2 within common services and protocols, including SSH, DNS/DoH, HTTP CONNECT, SOCKS, TLS, and reverse-tunnel platforms such as ngrok. Recent investigations illustrate the risk: REF0657 used iox, Rakshasa, and ICMP tunneling during a financial-services intrusion, while SOMNIRECORD disguised C2 and exfiltration as DNS TXT queries. Elastic also observed suspicious macOS activity in which a coding agent preceded Cloudflare Quick Tunnel use, an ngrok alert, and LaunchAgent persistence, underscoring the need to investigate tunnel creation and persistence even when trusted developer tools initiate them.

See real exploitation activity before you spend the cycle.
10 events from the most recent confirmed update back to the earliest known activity.
Splunk updated its "Socat Network Listener Binding an Executable" Enterprise Security analytic, which detects socat command lines containing both exec: and -listen: arguments. The analytic is intended to identify potential bind shells, remote command execution, lateral movement, or protocol tunneling.
The observed session started cloudflared to expose a local service through Cloudflare Quick Tunnels and raised alerts for lhr[.]life and api.trycloudflare[.]com connections. It also wrote and loaded a LaunchAgent watchdog configured to perform 60-second liveness checks against a trycloudflare login endpoint; Elastic also detected an ngrok binary under zsh and later launchd.
Shells parented by Claude Code made credentialed HTTP(S) requests to lhr[.]life localhost.run tunnel subdomains and Cloudflare Quick Tunnel URLs. The sessions repeatedly polled a tunnel-published login endpoint, submitted credentials, and retrieved API summary metrics.
The macOS host showed increased GenAI or MCP Server Child Process Execution activity during the suspicious multi-day activity chain.
Elastic observed zsh launching a Python script from /tmp that made outbound HTTPS requests to an analytics domain and appeared to retrieve data through plaintext MCP-style JSON-RPC requests. A generic cat utility also wrote to a Claude project MEMORY.md file.
Elastic telemetry recorded malicious_file events involving pritunl-client and wireguard-go on a macOS developer endpoint where Claude Code was installed and actively used.
Elastic observed initial enumeration activity in a REF0657 intrusion affecting a financial-services organization in South Asia. The actors likely used a remotely accessible Microsoft SQL Server and abused xp_cmdshell to execute commands.
Within roughly 24 hours of initial access, REF0657 compressed .bak data and exfiltrated it through the Mega file-hosting service using MEGA CMD renamed as ms_edge.exe. The actors also cleared Windows System and Security event logs.
During the 2022 Ukraine Electric Power Attack, Sandworm Team deployed the GOGETTER tunneler to establish a Yamux TLS-based command-and-control channel with external servers.
Elastic Security Labs identified the SOMNIRECORD C++ backdoor associated with the REF2924 activity group. The malware retrieves commands through DNS TXT records and exfiltrates hex-encoded command output through DNS queries to masquerade command-and-control traffic as DNS.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 11 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
6 references tracked. Mallory keeps watching after this page renders.
research.splunk.com
Open sourceelastic.co
Open sourceelastic.co
Open sourceelastic.co
Open sourceattack.mitre.org
Open sourcegtfobins.github.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.