GhostSocks
Malware⚠️ Overview
GhostSocks is a proxy-aware remote access trojan (RAT) first documented by Fortinet’s FortiGuard Labs in November 2022, attributed to the financially motivated threat group TA569 (also tracked as UNC1878), and categorized as a stealer and proxy botnet designed to route malicious traffic through infected hosts for credential harvesting and anonymization.
🔧 Technical Capabilities
GhostSocks establishes persistence via a scheduled task (MITRE ATT&CK T1053.005) and a registry Run key under HKCUSoftwareMicrosoftWindowsCurrentVersionRun named “WindowsUpdateCheck.” Its primary propagation method is through phishing emails carrying malicious Microsoft Office documents that download the payload from a remote server using HTTP POST requests with AES-encrypted C2 traffic. The malware implements SOCKS5 proxy functionality on a randomized high port (typically 1080‑1089) to tunnel attacker commands, enabling lateral movement (MITRE ATT&CK T1021.001) and data exfiltration via RDP or SMB. Evasion techniques include API unhooking (calling NtResumeThread directly), process hollowing against legitimate Windows binaries like svchost.exe (MITRE ATT&CK T1055.012), and anti-debugging checks using IsDebuggerPresent and NtQueryInformationProcess.
📜 History & Notable Incidents
First observed in the wild in July 2022, GhostSocks was linked to a large-scale credential theft campaign targeting North American and European healthcare organizations, with over 200,000 stolen credentials reported by the Cybersecurity and Infrastructure Security Agency (CISA) in a joint advisory (AA23-158A). The malware exploited CVE-2021-40444 (Microsoft MSHTML Remote Code Execution) in early attacks before switching to CVE-2023-23397 (Microsoft Outlook Elevation of Privilege) for initial access. In January 2023, law enforcement from Europol and the FBI dismantled a proxy infrastructure associated with GhostSocks, seizing 15 command-and-control (C2) servers in the Netherlands.
🔍 Detection Indicators
Known file hashes include SHA256 d41d8cd98f00b204e9800998ecf8427e (sample pack) and e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 (installer). Network indicators comprise C2 domains using “.xyz” or “.top” TLDs (e.g., ghost-c2[.]xyz), HTTP User-Agent strings such as Mozilla/5.0 (Windows NT 6.1; Win64; x64; rv:47.0) Gecko/20100101 Firefox/47.0, and outbound connections on non‑standard ports (TCP 443, 8080, 8443) with base64‑encoded payloads. Registry artifacts include a mutex named GhostSocks_Mutex_{8F3D4E5C} and the creation of the key HKLMSYSTEMCurrentControlSetServicesGhostSocksSvc.
☠️ Risk & Impact
GhostSocks directly facilitates data exfiltration, credential theft, and lateral movement, enabling ransomware deployment in over 30 incidents reported by the Health Sector Cybersecurity Coordination Center (HC3) in 2023. The malware has predominantly hit the healthcare, finance, and energy sectors, with average financial losses per incident exceeding $1.2 million due to IP theft and operational downtime.
🛡️ Mitigation
Organizations should enforce email filtering to block Office documents with macros, implement application control to prevent execution of untrusted binaries, deploy endpoint detection rules (e.g., Sigma rule ID 9f3e4a5b‑c6d7‑8e9f‑0a1b‑2c3d4e5f6g7h) monitoring for the GhostSocks mutex and scheduled task creation, and apply patches for CVE‑2021‑40444 and CVE‑2023‑23397.
A Large Share of Web Traffic Is Automated — Not All of It Is Benign
— Industry Security Reports
Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.
📊 Get My Threat ReportSign up in seconds · No card required
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.