Socksbot
MITRE ATT&CK: S0273 View on attack.mitre.org
Aliases: BIRDDOG, Nadrac, Socksbot
- First seen
- 2018-03-15 00:00:00
- Malware type
- backdoor
- Family
- Malware family
- Operating systems
- windows
- Profile updated
- 2026-07-07 12:45:25
Targeted industries: government-and-public-sector financial-services technology-and-telecommunications
Targeted regions: country_code:us country_code:ru country_code:cn
Context
Socksbot is a backdoor that abuses Socket Secure (SOCKS) proxies.
Detection coverage
- 1 YARA rules
- 221 Sigma rules
Malware & tools used
- Dynamic-link Library Injection (attack-pattern)
- PowerShell (attack-pattern)
- Proxy (attack-pattern)
- Screen Capture (attack-pattern)
- Process Discovery (attack-pattern)
Detection rules
- MALPEDIA_Win_Socksbot_Auto (yara-rule)
Reports & references
- Mandiant — Fin7 Pursuing An Enigmatic And Evasive Global Criminal Operation (report)
- Trend Micro — Tech Brief Untangling The Patchwork Cyberespionage Group (report)
- cert.ssi.gouv.fr — 20220427 Np Tlpwhite Anssi Fin7 (report)
- Mandiant — Cds18 Technical S05 Att&Cking Fin7 (report)
- assets.sentinelone.com — Sentinellabs Blackbasta (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Socksbot (report)
- accenture.com — Accenture Goldfin Security Alert (report)
- threatminer.org — Report (report)
- MITRE ATT&CK — S0273 (report)