Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors GhostSocks

Description

GhostSocks is an emerging threat that turns compromised devices into residential proxy nodes, enabling attackers to evade detection. Originally marketed on Russian underground forums as Malware-as-a-Service, it has gained popularity due to its partnership with Lumma Stealer. Written in GoLang, GhostSocks uses SOCKS5 proxy protocol and TLS encryption to blend malicious traffic into normal network activity. It also incorporates backdoor functionality for running arbitrary commands and deploying additional payloads. Darktrace observed an increase in GhostSocks activity, detecting it alongside Lumma Stealer in customer networks. The malware's versatility in converting devices into proxy nodes while enabling covert network access illustrates how threat actors maximize the value of compromised infrastructure.

Goals & Targeting

Targeted Sectors

Education

AI Analysis

· 2 months ago

Executive Summary

GhostSocks is an emerging threat actor that utilizes compromised devices as residential proxy nodes to evade detection, with a primary motivation that is currently unknown. The actor's goals and sophistication level are not well-defined, but their ability to blend malicious traffic into normal network activity using SOCKS5 proxy protocol and TLS encryption is a significant concern. Organizations in the education sector are likely at risk due to GhostSocks' targeting profile.

Goals & Targeting

GhostSocks' strategic objectives are not well-defined, but their targeting of the education sector suggests that they may be seeking to exploit vulnerabilities in this industry. The actor's use of residential proxy nodes and backdoor functionality indicates that they are looking to maximize the value of compromised infrastructure and conduct covert operations. Typical victims of GhostSocks are likely to be organizations in the education sector with vulnerable devices that can be compromised and converted into proxy nodes.

Enhanced Description

The fact that GhostSocks is marketed as a MaaS on Russian underground forums suggests that the actor is looking to monetize their capabilities and expand their reach. The use of GoLang as the programming language and the incorporation of backdoor functionality indicate a moderate to high level of sophistication. However, without more information on the actor's motivations and goals, it is difficult to fully assess their threat level.

Key Capabilities

  • Residential proxy node creation
  • SOCKS5 proxy protocol utilization
  • TLS encryption
  • Backdoor functionality
  • Arbitrary command execution
  • Payload deployment

MITRE ATT&CK Tactics

Command and Control
Defense Evasion
Execution
Lateral Movement
Persistence

ATT&CK Techniques

T1043
T1059.003
T1071.001
T1102
T1110
T1204

Software / Tooling

Lumma Stealer
Custom RAT

Campaigns & Victims

GhostSocks' campaign patterns are not well-defined, but their partnership with Lumma Stealer suggests that they may be conducting joint operations. The actor's operational tempo is likely to be moderate, with a focus on compromising devices and converting them into proxy nodes. Notable past operations include the detection of GhostSocks alongside Lumma Stealer in customer networks, which suggests that the actor is actively exploiting vulnerabilities and compromising devices.

IOC Patterns

  • Spear-phishing with macro-laced Office documents
  • C2 over DNS using fast-flux
  • Staging infrastructure on bulletproof hosting
  • SOCKS5 proxy protocol traffic

Recommended Actions

  • Implement robust network security controls
  • Conduct regular vulnerability assessments
  • Utilize threat intelligence to stay informed about emerging threats
  • Implement a defense-in-depth strategy
  • Monitor for suspicious network activity

Suggested Tags

APT
MaaS
Residential proxy
Backdoor
Education sector

Confidence Assessment

The confidence level in the available data is moderate, as there is limited information on GhostSocks' motivations, goals, and sophistication level. The fact that the actor is marketed as a MaaS on Russian underground forums and has partnered with Lumma Stealer suggests that they are a legitimate threat, but more information is needed to fully assess their threat level. Information gaps exist regarding the actor's primary motivation, targeted countries, and first and last seen dates.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

30

IOCs

0

Observed Data

0

Tactics

Tags

Backdoor / C2

Details

Type
Apt
Confidence
50%
Added
May 3, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.