GhostSocks: From Initial Access to Residential Proxy
Oct. 1, 2025, 9:14 a.m.
Description
GhostSocks is a Malware-as-a-Service (MAAS) that converts compromised devices into residential proxies, enabling threat actors to bypass anti-fraud mechanisms. Introduced in October 2023, it gained popularity after partnering with LummaStealer in February 2024. The malware, coded in Golang, uses obfuscation techniques and can be built as a 32-bit DLL or executable. It doesn't implement persistence mechanisms but focuses on SOCKS5 functionality. GhostSocks uses a configuration file or hardcoded config to connect to C2 servers, randomly generates credentials, and establishes a SOCKS5 connection using open-source libraries. Despite law enforcement actions against related platforms, GhostSocks continues to operate, posing ongoing risks of double victimization and long-term network access for cybercriminals.
Tags
Date
- Created: Oct. 1, 2025, 7:39 a.m.
- Published: Oct. 1, 2025, 7:39 a.m.
- Modified: Oct. 1, 2025, 9:14 a.m.
Indicators
- f52fa1b8be929a42aafab8f0a80932e52b949ee35498f22b6d58e5e6ed107b99
- cda5f18be615ad27e0477c6d249d245d368ac1de81ee48239a3e39814345c04d
- b4709cfb8f9cf0eaabe16ab218d60a0e64c3fa568d42fcac51f867e1d2cdc1fe
- 91.212.166.9
- 147.45.196.157
- 86.54.24.25
- 91.212.166.91
- 46.8.236.61
- 46.8.232.106
- http://46.8.232.106:30001/api/helper-first-register?buildVersion=0pTk.PWh2DyJ&md5=&proxyPassword=&proxyUsername=&userId=
- https://synthient.com/blog/ghostsocks-from-initial-access-to-residential-proxy
- proton66.ru
Additional Informations
- Russian Federation