Socks5 Systemz

Aliases: ProxyBox

First seen
2016-01-01 00:00:00
Malware type
botnet
Family
Malware family
Last IoC activity
2026-07-22 01:55:25
Profile updated
2026-07-07 14:44:26

Context

The Socks5 Systemz malware is a proxy botnet distributed via the PrivateLoader and Amadey loaders. Active since at least 2016, this botnet infects devices to use them as proxies for malicious activities, offering access for prices ranging from $1 to $140 per day in cryptocurrency. It employs a domain generation algorithm (DGA) to evade detection and enhance its resilience. Persistence is maintained through a Windows service named ContentDWSvc, with the malware injected into memory via a file called previewer.exe. To date, it has compromised approximately 10,000 devices globally, excluding Russia.

Reports & references

  • bitsight.com — Unveiling Socks5Systemz Rise New Proxy Service Privateloader And Amadey (report)
  • any.run — Crackedcantil Breakdown (report)
  • bitsight.com — Unveiling Socks5Systemz Rise New Proxy Service Privateloader And Amadey (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Socks5 Systemz (report)
  • synthient.com — Proxybox Socks5Systemz Lives On (report)
  • bitsight.com — Proxyam Powered Socks5Systemz Botnet (report)
  • csirtasobancaria.com — Nueva Actividad Del Backdoor Socks5Systemz (report)

External references