GhostSocks
- First seen
- 2023-10-01 00:00:00
- Malware type
- botnet
- Family
- Malware family
- Last IoC activity
- 2026-07-22 01:55:25
- Profile updated
- 2026-07-07 14:49:28
Context
GhostSocks, a Golang-based proxy malware, was first advertised as a Malware-as-a-Service (MaaS) on Russian-speaking underground forums in October 2023. It uses back-connect socket secure internet protocol (SOCKS5) connections and is available for rent for US $100 per month. In February 2024, the author of Lumma Stealer released an update introducing the integration of proxying capabilities. This feature, developed in partnership with GhostSocks, allows the use of infected hosts as SOCKS5 proxies and is available to all subscribers who purchase the "Professional" or higher tier plan. This integration allows Lumma Stealer users to establish a network of residential IP addresses for various purposes, including credential checking, spam distribution, or as general-purpose proxies.
Detection coverage
- 1 YARA rules
Detection rules
- MALPEDIA_Win_Ghostsocks_Auto (yara-rule)
Reports & references
- rapid7.com — Ongoing Social Engineering Campaign Refreshes Payloads (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Ghostsocks (report)
- spycloud.com — On The Hunt For Ghostsocks (report)
- synthient.com — Ghostsocks From Initial Access To Residential Proxy (report)
- thedfirreport.com — Cobalt Strike And A Pair Of Socks Lead To Lockbit Ransomware (report)
- twitter.com — 1754630820650696875 (report)
- zscaler.com — Inside Zloader S Latest Trick Dns Tunneling (report)
- infrawatch.app — Ghostsocks Lummas Partner In Proxy (report)
- spycloud.com — Lummac2 Malware Stealthier Capabilities (report)