PortStarter

Aliases: SocksProxyGo

Malware type
trojan
Family
Malware family
Profile updated
2026-07-07 13:11:32

Targeted industries: technology-and-telecommunications

Context

PortStarter, also known as SocksProxyGo, is a Trojan malware that facilitates unauthorized network access by enabling port forwarding and establishing proxy connections. It is primarily written in Go, making it versatile across different systems.

Detection coverage

  • 2 YARA rules

Detection rules

  • MALPEDIA_Win_Socksproxygo_Auto (yara-rule)
  • MALPEDIA_Win_Portstarter_Auto (yara-rule)

Reports & references

  • Microsoft — Dev 0832 Vice Society Opportunistic Ransomware Campaigns Impacting Us Education Sector (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Portstarter (report)
  • asiapacificdefencereporter.com — Final Crwd 2023 Threat Hunting Report (report)

External references