No AI analysis yet.
According to TeamT5, SoxAgent is a Linux backdoor that covertly converts compromised hosts into SOCKS5 relay nodes. It maintains a persistent reverse connection to a hardcoded C2 and negotiates AES-encrypted tunnels, enabling the attacker to forward TCP traffic through the victim to conceal their origin. It supports remote updates, self-deletion, and heartbeat reporting with falsified tunnel metrics to enhance stealth. The activity associated with SoxAgent is part of a campaign that deployed the backdoor to form an ORB network tracked as GOBLIN14. Attributed to: SLIME88.