Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
GhostSocks Malware Transforms Devices into Proxy Nodes

GhostSocks Malware Transforms Devices into Proxy Nodes

Posted on March 31, 2026 By CWS

A newly identified malware, GhostSocks, is making waves by converting compromised systems into residential proxies, effectively disguising malicious activities. This malware operates silently on infected devices, causing the traffic from cyber attackers to blend in with normal household internet usage.

Understanding GhostSocks’ Unique Approach

Unlike typical malware that focuses on data theft or file encryption, GhostSocks leverages the victim’s internet connection to mask attacker activities as legitimate traffic. This strategy significantly hinders security measures from identifying malicious behavior, providing cybercriminals with a strategic advantage.

GhostSocks initially appeared on the Russian cybercrime forum xss[.]is, marketed as a Malware-as-a-Service (MaaS) product. Developed in GoLang, it employs the SOCKS5 proxy protocol to establish covert communication channels, utilizing a relay-based command-and-control (C2) system to obscure the true source of the attack.

Rising Threat and Notable Incidents

The malware’s popularity grew in 2024 when it partnered with Lumma Stealer, a prevalent information-stealing malware. This collaboration led to a rapid increase in its adoption within the cybercriminal community. Darktrace experts observed a rise in GhostSocks activities from late 2025, particularly within the education sector where it was detected alongside Lumma Stealer.

GhostSocks is particularly alarming due to its multifunctionality. Beyond routing traffic, it possesses a backdoor capability, allowing cybercriminals to execute commands and deploy further malicious payloads. The ransomware group Black Basta has reportedly used GhostSocks to maintain prolonged, covert access to networks, highlighting its role as more than just a proxy tool.

Evading Detection and Persistent Risks

GhostSocks is designed with evasion in mind, wrapping its communications in Transport Layer Security (TLS) encryption to blend seamlessly with normal encrypted traffic. This makes it challenging for traditional signature-based tools to detect it based solely on traffic patterns.

A December 2025 incident revealed GhostSocks’ stealth capabilities when an infected device attempted to connect using an unusual self-signed SSL certificate. This connection led to the download of a file named “Renewable.exe,” linked to GhostSocks, as confirmed by multiple OSINT sources.

Countermeasures and Future Outlook

To counter GhostSocks, security teams are advised to monitor connections to uncommon endpoints using self-signed SSL certificates. Enabling automated response systems is crucial to prevent delayed containment, as manual verification can slow down reaction times.

Keeping updated indicators of compromise, such as file hashes and associated hostnames, and enforcing strict outbound traffic controls are essential strategies to disrupt GhostSocks’ ability to maintain C2 communications.

The persistence of GhostSocks underscores the need for vigilant cybersecurity measures. As attackers continue to adapt and refine their techniques, organizations must remain proactive to mitigate the risks posed by advanced threats like GhostSocks.

Cyber Security News Tags:automated response, Black Basta, C2 infrastructure, Cybersecurity, Darktrace, GhostSocks, Golang, Lumma Stealer, MaaS, Malware, Proxies, SOCKS5, SSL certificates, TLS encryption

Post navigation

Previous Post: OpenAI Codex Vulnerability Exposes GitHub Tokens
Next Post: DeepLoad Malware Utilizing AI Evasion Tactics in Networks

Related Posts

Threat Actors Advertising Anivia Stealer Malware on Dark Web Bypassing UAC Controls Threat Actors Advertising Anivia Stealer Malware on Dark Web Bypassing UAC Controls Cyber Security News
Google Patches Critical Gemini CLI Vulnerability Google Patches Critical Gemini CLI Vulnerability Cyber Security News
CredShields Enhances OWASP 2026 Smart Contract Security CredShields Enhances OWASP 2026 Smart Contract Security Cyber Security News
700+ Malicious Android Apps Abusing NFC Relay to Exfiltrate Banking Login Credentials 700+ Malicious Android Apps Abusing NFC Relay to Exfiltrate Banking Login Credentials Cyber Security News
Phishing Attacks Exploit RCS and iMessage to Evade Security Phishing Attacks Exploit RCS and iMessage to Evade Security Cyber Security News
Malicious npm Packages Compromise Developer Systems Malicious npm Packages Compromise Developer Systems Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Dell Wyse Security Flaws Allow Remote Code Attacks
  • Oracle E-Business Suite Vulnerability Actively Exploited
  • Malicious Chrome Extension Compromises User Searches
  • U.S. Seizes Hundreds of Domains for Illegal World Cup Streaming
  • EvilTokens Phishing Exposes Finance Firms with ‘Ghost’ Code

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Dell Wyse Security Flaws Allow Remote Code Attacks
  • Oracle E-Business Suite Vulnerability Actively Exploited
  • Malicious Chrome Extension Compromises User Searches
  • U.S. Seizes Hundreds of Domains for Illegal World Cup Streaming
  • EvilTokens Phishing Exposes Finance Firms with ‘Ghost’ Code

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark