Socks5 Systemz
Aliases: ProxyBox
- First seen
- 2016-01-01 00:00:00
- Malware type
- botnet
- Family
- Malware family
- Last IoC activity
- 2026-07-22 01:55:25
- Profile updated
- 2026-07-07 14:44:26
Context
The Socks5 Systemz malware is a proxy botnet distributed via the PrivateLoader and Amadey loaders. Active since at least 2016, this botnet infects devices to use them as proxies for malicious activities, offering access for prices ranging from $1 to $140 per day in cryptocurrency. It employs a domain generation algorithm (DGA) to evade detection and enhance its resilience. Persistence is maintained through a Windows service named ContentDWSvc, with the malware injected into memory via a file called previewer.exe. To date, it has compromised approximately 10,000 devices globally, excluding Russia.
Reports & references
- bitsight.com — Unveiling Socks5Systemz Rise New Proxy Service Privateloader And Amadey (report)
- any.run — Crackedcantil Breakdown (report)
- bitsight.com — Unveiling Socks5Systemz Rise New Proxy Service Privateloader And Amadey (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Socks5 Systemz (report)
- synthient.com — Proxybox Socks5Systemz Lives On (report)
- bitsight.com — Proxyam Powered Socks5Systemz Botnet (report)
- csirtasobancaria.com — Nueva Actividad Del Backdoor Socks5Systemz (report)