kitty-socks5

Malware

⚠️ Overview

Kitty-Socks5 is a stealthy SOCKS5 proxy malware first documented in September 2022 by Trend Micro researchers as part of a broader campaign targeting Linux-based IoT devices. It is categorized as a proxy trojan, designed to turn infected devices into anonymous SOCKS5 proxies for criminal relay of traffic, often associated with Chinese-speaking threat actors. The malware is a variant of the Kitty family, sharing code with older Gafgyt and Mirai strains.

🔧 Technical Capabilities

The malware propagates by exploiting weak Telnet and SSH credentials on exposed IoT devices, using a built-in dictionary of over 100 common username-password pairs. Kitiy-Socks5 establishes a persistent SOCKS5 proxy on port 1080 or 1081, accepting connections from a hardcoded command-and-control (C2) server via encrypted TCP or UDP. It uses process name spoofing under /usr/sbin/atd or /bin/bash and checks for existing proxy services to avoid duplicate infection. Evasion includes killing competing malware processes and disabling firewall rules using iptables -F. The proxy traffic is typically forwarded through the C2, enabling anonymized attacks or data exfiltration.

📜 History & Notable Incidents

First sightings in August 2022 via Shodan telemetry showed spikes of infected devices in South Korea, Taiwan, and Japan. In October 2022, Akamai reported Kitiy-Socks5 used in a residential proxy network to bypass geofencing for credential stuffing campaigns against e-commerce platforms. No specific CVEs are exploited—instead, weak credentials are the primary vector. Law enforcement actions have not been documented as of early 2025.

🔍 Detection Indicators

Known file hashes include SHA-256 f8d3c1a2b4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0 (sample from Trend Micro). Behavioral signatures include unexpected SOCKS5 listener on ports 1080/1081, high outbound traffic on non-standard ports, and connections to IPs in ASN 37963 (ChinaNet). Mutex names observed: kitty_proxy_42. User-Agent strings used during brute-force attempts mimic curl/7.58.0.

☠️ Risk & Impact

Infected devices become part of a proxy botnet that can relay up to 100 Mbps of malicious traffic, enabling credential theft, ad fraud, and access to region-locked services. The primary impact is reputational and bandwidth cost for IoT owners; financial losses stem from downstream fraud facilitated by the proxy network. Affected sectors include smart home devices, IP cameras, and small office routers.

🛡️ Mitigation

Change default credentials on all IoT devices and disable Telnet. Use network segmentation to isolate IoT subnets, deploy IDS/IPS rules to detect SOCKS5 proxy traffic on non-standard ports, and apply Sigma rules from the Trend Micro report (e.g., proxy_listener_creation). Regular patching of known vulnerabilities in IoT firmware is recommended.

Free Threat Visibility

Get Visibility Into Automated Threats Reaching Your Server

Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.

🔍 Scan My Site Free

Powered by JA4 fingerprinting, honeypot traps & behavioral analysis

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.