Socksbot

MITRE ATT&CK: S0273 View on attack.mitre.org

Aliases: BIRDDOG, Nadrac, Socksbot

First seen
2018-03-15 00:00:00
Malware type
backdoor
Family
Malware family
Operating systems
windows
Profile updated
2026-07-07 12:45:25

Targeted industries: government-and-public-sector financial-services technology-and-telecommunications

Targeted regions: country_code:us country_code:ru country_code:cn

Context

Socksbot is a backdoor that abuses Socket Secure (SOCKS) proxies.

Detection coverage

  • 1 YARA rules
  • 221 Sigma rules

Malware & tools used

  • Dynamic-link Library Injection (attack-pattern)
  • PowerShell (attack-pattern)
  • Proxy (attack-pattern)
  • Screen Capture (attack-pattern)
  • Process Discovery (attack-pattern)

Detection rules

  • MALPEDIA_Win_Socksbot_Auto (yara-rule)

Reports & references

  • Mandiant — Fin7 Pursuing An Enigmatic And Evasive Global Criminal Operation (report)
  • Trend Micro — Tech Brief Untangling The Patchwork Cyberespionage Group (report)
  • cert.ssi.gouv.fr — 20220427 Np Tlpwhite Anssi Fin7 (report)
  • Mandiant — Cds18 Technical S05 Att&Cking Fin7 (report)
  • assets.sentinelone.com — Sentinellabs Blackbasta (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Socksbot (report)
  • accenture.com — Accenture Goldfin Security Alert (report)
  • threatminer.org — Report (report)
  • MITRE ATT&CK — S0273 (report)

External references