216.73.217.22

Phantom Footprints: Tracking GhostSocks Malware

· Published 31/03/2026 16:14 · Modified 31/03/2026 18:49

Export JSON

Essential information

Published
31/03/2026 16:14
Modified
31/03/2026 18:49
Tags
2026-03-31 backdoor c2 infrastructure evasion techniques ghostsocks golang lumma stealer residential proxy socks5 tls encryption
Related entities
4 observables, 1 intrusion sets (apt), 7 techniques (mitre), 3 others

Description

is an emerging threat that turns compromised devices into nodes, enabling attackers to evade detection. Originally marketed on Russian underground forums as Malware-as-a-Service, it has gained popularity due to its partnership with . Written in , uses proxy protocol and to blend malicious traffic into normal network activity. It also incorporates functionality for running arbitrary commands and deploying additional payloads. Darktrace observed an increase in activity, detecting it alongside in customer networks. The malware's versatility in converting devices into proxy nodes while enabling covert network access illustrates how threat actors maximize the value of compromised infrastructure.

External references