216.73.217.69

GhostSocks - Partner In Proxy

· Published 25/02/2025 13:58 · Modified 25/02/2025 14:43

Export JSON

Essential information

Published
25/02/2025 13:58
Modified
25/02/2025 14:43
Tags
2025-02-25 anti-fraud bypass backconnect proxy c2 infrastructure credential abuse ghostsocks golang lummac2 malware-as-a-service socks5 vdsina
Related entities
17 observables, 8 techniques (mitre), 2 malware, 1 others

Description

is a -based malware first identified in October 2023. It is primarily deployed alongside the information stealer and offered as . uses a relay-based C2 implementation with HTTP API, allowing attackers to route traffic through infected systems. The malware's integration with Lumma, including automatic provisioning and discounted pricing, enhances post-infection capabilities for and anti-fraud bypassing. contains additional backdoor functionality, such as arbitrary command execution and credential modification. Its largely operates on (AS216071), a Russian-speaking server provider. The malware exemplifies the commodification of backconnect malware in the criminal ecosystem, posing a significant threat to financial institutions and high-value targets.

External references