GhostSocks is an emerging threat that turns compromised devices into residential proxy nodes, enabling attackers to evade detection. Originally marketed on Russian underground forums as Malware-as-a-Service, it has gained popularity due to its partnership with Lumma Stealer. Written in GoLang, GhostSocks uses SOCKS5 proxy protocol and TLS encryption to blend malicious traffic into normal network activity. It also incorporates backdoor functionality for running arbitrary commands and deploying additional payloads. Darktrace observed an increase in GhostSocks activity, detecting it alongside Lumma Stealer in customer networks. The malware's versatility in converting devices into proxy nodes while enabling covert network access illustrates how threat actors maximize the value of compromised infrastructure.
Targeted Sectors
Executive Summary
GhostSocks is an emerging threat actor that utilizes compromised devices as residential proxy nodes to evade detection, with a primary motivation that is currently unknown. The actor's goals and sophistication level are not well-defined, but their ability to blend malicious traffic into normal network activity using SOCKS5 proxy protocol and TLS encryption is a significant concern. Organizations in the education sector are likely at risk due to GhostSocks' targeting profile.
Goals & Targeting
GhostSocks' strategic objectives are not well-defined, but their targeting of the education sector suggests that they may be seeking to exploit vulnerabilities in this industry. The actor's use of residential proxy nodes and backdoor functionality indicates that they are looking to maximize the value of compromised infrastructure and conduct covert operations. Typical victims of GhostSocks are likely to be organizations in the education sector with vulnerable devices that can be compromised and converted into proxy nodes.
Enhanced Description
The fact that GhostSocks is marketed as a MaaS on Russian underground forums suggests that the actor is looking to monetize their capabilities and expand their reach. The use of GoLang as the programming language and the incorporation of backdoor functionality indicate a moderate to high level of sophistication. However, without more information on the actor's motivations and goals, it is difficult to fully assess their threat level.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
GhostSocks' campaign patterns are not well-defined, but their partnership with Lumma Stealer suggests that they may be conducting joint operations. The actor's operational tempo is likely to be moderate, with a focus on compromising devices and converting them into proxy nodes. Notable past operations include the detection of GhostSocks alongside Lumma Stealer in customer networks, which suggests that the actor is actively exploiting vulnerabilities and compromising devices.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The confidence level in the available data is moderate, as there is limited information on GhostSocks' motivations, goals, and sophistication level. The fact that the actor is marketed as a MaaS on Russian underground forums and has partnered with Lumma Stealer suggests that they are a legitimate threat, but more information is needed to fully assess their threat level. Information gaps exist regarding the actor's primary motivation, targeted countries, and first and last seen dates.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
30
IOCs
0
Observed Data
0
Tactics