{"id":11737,"date":"2026-03-31T10:04:56","date_gmt":"2026-03-31T10:04:56","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2026\/03\/31\/ghostsocks-turns-victim-systems-into-residential-proxies-for-evasive-cyberattacks\/"},"modified":"2026-03-31T10:04:56","modified_gmt":"2026-03-31T10:04:56","slug":"ghostsocks-turns-victim-systems-into-residential-proxies-for-evasive-cyberattacks","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2026\/03\/31\/ghostsocks-turns-victim-systems-into-residential-proxies-for-evasive-cyberattacks\/","title":{"rendered":"GhostSocks Turns Victim Systems Into Residential Proxies for Evasive Cyberattacks"},"content":{"rendered":"<p>    GhostSocks Turns Victim Systems Into Residential Proxies for Evasive Cyberattacks<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>A new malware called GhostSocks has been quietly spreading through compromised systems, turning home and office devices into residential proxies that threat actors use to conceal their malicious traffic. <\/p>\n<p>Unlike traditional malware that simply steals data or locks files, GhostSocks hijacks the victim\u2019s internet connection to make attacker traffic appear as though it is coming from a regular household user. <\/p>\n<p>This makes it far harder for <a href=\"https:\/\/cybersecuritynews.com\/best-cloud-security-tools\/\" id=\"11635\" target=\"_blank\" rel=\"noreferrer noopener\">security tools<\/a> to flag the activity as suspicious, giving attackers a clear advantage.<\/p>\n<p>GhostSocks was first marketed on xss[.]is, a well-known Russian underground cybercrime forum, as a Malware-as-a-Service (MaaS) offering, meaning any criminal willing to pay can rent access without building it themselves. <\/p>\n<p>Written in GoLang, it uses the SOCKS5 proxy protocol to create a covert communication channel on infected devices, while a relay-based command-and-control (C2) architecture places an intermediary server between the attacker\u2019s real C2 infrastructure and the compromised machine. <\/p>\n<p>It wasn\u2019t until 2024, when GhostSocks announced a partnership with the notorious Lumma Stealer \u2014 a widely used information-stealing malware \u2014 that its adoption surged sharply across the threat landscape.<\/p>\n<p><a href=\"https:\/\/www.darktrace.com\/blog\/phantom-footprints-tracking-ghostsocks-malware\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Darktrace analysts identified a steady rise in GhostSocks<\/a> activity across its customer base from late 2025, with multiple incidents documented in detail. <\/p>\n<p>In one notable case from December 2025, Darktrace detected GhostSocks operating alongside <a href=\"https:\/\/cybersecuritynews.com\/lumma-stealer-github-delivery\/\" id=\"76764\" target=\"_blank\" rel=\"noreferrer noopener\">Lumma Stealer<\/a> within an education sector customer\u2019s network, confirming the partnership between the two malware families remains active despite recent efforts to disrupt Lumma\u2019s infrastructure.<\/p>\n<p>GhostSocks is particularly dangerous because it serves multiple criminal purposes at once. Beyond routing attacker traffic through residential connections, it also includes a backdoor component that allows operators to run arbitrary commands and deploy additional malicious payloads on infected systems. <\/p>\n<p>The ransomware group Black Basta reportedly used GhostSocks to maintain long-term, covert access to victim networks \u2014 making it a full-access enabler, not just a proxy tool.<\/p>\n<p>The threat extends well beyond any single organization. Both cybercriminal groups and state-sponsored actors increasingly rely on residential proxies to bypass IP-based <a href=\"https:\/\/cybersecuritynews.com\/best-fraud-detection-tools\/\" id=\"13681\" target=\"_blank\" rel=\"noreferrer noopener\">detection tools<\/a>, and GhostSocks delivers exactly this kind of cover at scale. <\/p>\n<p>As long as threat actors can rebuild infrastructure rapidly and maintain anonymity through proxy nodes, this malware will remain a persistent risk.<\/p>\n<h2 class=\"wp-block-heading\" id=\"how-ghostsocks-evades-detection\"><strong>How GhostSocks Evades Detection<\/strong><\/h2>\n<p>GhostSocks is built with evasion as a central design feature. The malware wraps its SOCKS5 tunnels in Transport Layer Security (TLS) encryption, allowing its traffic to blend into normal encrypted network communications and making it difficult for signature-based tools to identify it through traffic patterns alone.<\/p>\n<p>In the December 2025 incident, the first warning sign came when a device began connecting to an endpoint using a suspicious self-signed SSL certificate never seen on that network before. <\/p>\n<p>The endpoint, retreaw[.]click (159.89.46[.]92), was flagged by multiple <a href=\"https:\/\/cybersecuritynews.com\/open-source-intelligence-market-is-expected-to-reach-usd-60-bn-by-2032\/\" id=\"16065\" target=\"_blank\" rel=\"noreferrer noopener\">open-source intelligence<\/a> (OSINT) sources as part of Lumma Stealer\u2019s C2 infrastructure. <\/p>\n<p>Within two minutes, the same device downloaded an executable file named \u201cRenewable.exe\u201d from IP 86.54.24[.]29, confirmed by multiple OSINT vendors as a GhostSocks-linked payload.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEighO2iwmiWhC7JJ07PTpiDcRLzhyphenhyphenUml72eqeTO4TqTvc8-lH2__l23lmGNHE7SCNteLUVKMWcmg1-TFxjVsVSjKUjdZ0kLO-8wRQawdU4dBhfJazkZIhOj0vjQW7zHavLqUQSVFFZzcztFN3tkIrmAA2f5g4iNV1GA5wsKGS53iMYPOB-4jW9OvjuYRuE\/s16000\/Darktrace%25E2%2580%2599s%2520detection%2520of%2520suspicious%2520SSL%2520connections%2520to%2520retreaw%255B.%255Dclick%2C%2520indicating%2520an%2520attempted%2520link%2520to%2520Lumma%2520C2%2520infrastructure%2520%28Source%2520-%2520DarkTrace%29.webp?ssl=1\" alt=\"Detection of suspicious SSL connections to retreaw[.]click, indicating an attempted link to Lumma C2 infrastructure (Source - DarkTrace)\"><figcaption class=\"wp-element-caption\">Detection of suspicious SSL connections to retreaw[.]click, indicating an attempted link to Lumma C2 infrastructure (Source \u2013 DarkTrace)<\/figcaption><\/figure>\n<\/div>\n<p> Two days later, additional payloads including \u201cSetup.exe\u201d and \u201c\/vp6c63yoz.exe\u201d were downloaded from www.lbfs[.]site, followed by C2 beaconing to multiple rare external endpoints.\u00a0<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEj6Jy9kU6nmhTMpBXtQYt3tkMsdizO3_EvAqLVIdelffQ18wNNi2fv-a-PViD-QzHlLHqa0wNC2ixAQRSMcwUWP91RpBNfPZo3iKXocJmckXUPYXiUbaHrmhvf0eMplIlAxvGdEmjYQGaAN48aYQu89CJphyphenhyphen39K3nLYc7lJcsYjwKJaVb_FXxbPu8ds61w\/s16000\/Darktrace%27s%2520detection%2520of%2520the%2520device%2520downloading%2520%27Renewable.exe%27%2520%28Source%2520-%2520DarkTrace%29.webp?ssl=1\" alt=\"Detection of the device downloading 'Renewable.exe' (Source - DarkTrace)\"><figcaption class=\"wp-element-caption\">Detection of the device downloading \u2018Renewable.exe\u2019 (Source \u2013 DarkTrace)<\/figcaption><\/figure>\n<\/div>\n<p>Later GhostSocks versions achieve persistence through Windows registry run keys, ensuring the proxy stays active even after a system reboot \u2014 a capability absent in earlier variants, reflecting active ongoing development.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjNLtZgwnDpzEY0ik3AlUjfRq3qRfTrKF0vZwvDRZ3AjECG_dkGL2ajy_jl1LLiFn8DCugToVzdydwvc59sSWElanMQnsgEKHvoQgRlsKTnOAnrnot0OSl6qs3jLMIxrcHfSaKUJYiexO-jHdB75CWGR7kP72kNyacUnNQLSPBnCyCrkGFAfOjVpgS8khw\/s16000\/Darktrace%27s%2520detection%2520of%2520a%2520malicious%2520payload%2520from%2520www.lbfs%255B.%255Dsite%2520%28Source%2520-%2520DarkTrace%29.webp?ssl=1\" alt=\"Detection of a malicious payload from www.lbfs[.]site (Source - DarkTrace)\"><figcaption class=\"wp-element-caption\">Detection of a malicious payload from www.lbfs[.]site (Source \u2013 DarkTrace)<\/figcaption><\/figure>\n<\/div>\n<p>Security teams should closely <a href=\"https:\/\/cybersecuritynews.com\/postgresql-monitoring-tools\/\" id=\"37526\" target=\"_blank\" rel=\"noreferrer noopener\">monitor connections<\/a> to rare external endpoints using self-signed SSL certificates, as this was the first detectable warning in documented cases. <\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgADI3YM-17y0lJ9WB3SxeFJJTbICC741lkdCSUd3AxStUL2LwgOB82Bf7U1Nw3aJlksU4Lz135ZpXjbkhNOyLiUDDq-HNCev3PsKUOjcf-h_Vsw8Z9WeeKbDS-lsrm6IwTCkrTbMnbLAJDVVwdniyFqx_jvW9ZsIAyUEd0PaDnVf9PrCfJp9zeCa0KAeY\/s16000\/An%2520overview%2520of%2520download%2520activity%2520and%2520Autonomous%2520Response%2520%28Source%2520-%2520DarkTrace%29.webp?ssl=1\" alt=\"An overview of download activity and Autonomous Response (Source - DarkTrace)\"><figcaption class=\"wp-element-caption\">An overview of download activity and Autonomous Response (Source \u2013 DarkTrace)<\/figcaption><\/figure>\n<\/div>\n<p>Enabling automated response capabilities is strongly advised, since manual confirmation modes delayed containment in the reported attack. <\/p>\n<p>Keeping indicators of compromise current \u2014 including SHA1 file hashes and hostnames such as retreaw[.]click, www.lbfs[.]site, and 86.54.24[.]29 \u2014 alongside enforcing strict outbound traffic controls, can limit the malware\u2019s ability to establish sustained C2 communications.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 90%,rgb(169,184,195) 100%)\"><strong>Follow us on\u00a0<a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>,\u00a0<a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>,\u00a0and\u00a0<a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a>\u00a0to Get More Instant Updates<\/strong>,\u00a0<strong>Set CSN as a Preferred Source in\u00a0<a href=\"https:\/\/www.google.com\/preferences\/source?q=cybersecuritynews.com\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google<\/a>.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/ghostsocks-turns-victim-systems\/\">GhostSocks Turns Victim Systems Into Residential Proxies for Evasive Cyberattacks<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Tushar Subhra Dutta<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/ghostsocks-turns-victim-systems\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>GhostSocks Turns Victim Systems Into Residential Proxies for Evasive Cyberattacks A new malware called GhostSocks has been quietly spreading through compromised systems, turning home and office devices into residential proxies that threat actors use to conceal their malicious traffic. Unlike traditional malware that simply steals data or locks files, GhostSocks hijacks the victim\u2019s internet connection [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[63,1],"tags":[130],"class_list":["post-11737","post","type-post","status-publish","format-standard","hentry","category-cyber-security-news","category-uncategorized","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/11737"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=11737"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/11737\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=11737"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=11737"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=11737"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}