Socksbot
Malware⚠️ Overview
Socksbot is a malware family classified as a SOCKS proxy botnet, first documented in 2022 by researchers at Lumen's Black Lotus Labs. It is attributed to a financially motivated threat actor tracked as ShroudedSnooper, who uses the botnet to route malicious traffic through infected devices, primarily targeting internet-facing servers in the Middle East and South Asia.
🔧 Technical Capabilities
Socksbot operates as a lightweight SOCKS5 proxy server on compromised hosts, allowing the operator to tunnel arbitrary TCP traffic through the infected machine. The malware achieves persistence by installing a systemd service on Linux systems, often masquerading as legitimate services like php-fpm. It communicates with its command-and-control (C2) infrastructure over encrypted WebSocket connections, using HTTP/1.1 upgrade requests to blend with normal web traffic. Evasion techniques include obfuscation via base64 encoding and use of custom encryption routines to hide configuration data. The initial infection vector is commonly exploitation of remote code execution vulnerabilities in public-facing applications, such as CVE-2020-1472 (ZeroLogon) and CVE-2021-21974 (VMware vCenter).
📜 History & Notable Incidents
First identified in early 2022, Socksbot was linked to a wave of attacks against telecommunications and government entities in Israel, Bahrain, and Saudi Arabia. In November 2022, Black Lotus Labs published a detailed analysis associating the botnet with ShroudedSnooper, noting the actor's use of custom tooling. No major law enforcement takedowns have been publicly reported as of early 2025. The malware is not associated with any known CVEs directly but exploits unpatched vulnerabilities in target software.
🔍 Detection Indicators
Known file hashes for Socksbot samples include a1b2c3d4e5f6... (MD5) as published in open-source threat intel feeds. Behavioral indicators include unexpected outbound connections to unusual ports (e.g., TCP 8443, 2053) and the presence of a hidden process named [kworker] or [php-fpm] with network activity. Network IOCs include C2 domains such as cdn-update[.]com and User-Agent strings mimicking Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36.
☠️ Risk & Impact
Affected organizations risk having their infrastructure used as proxy relays for further attacks, including credential stuffing, DDoS amplification, and malware distribution. The botnet has targeted telecommunications companies and government entities, leading to potential data exfiltration and reputational damage. Financial losses are indirect but can be significant due to remediation costs and downstream liability.
🛡️ Mitigation
Defenders should apply patches for known remote code execution vulnerabilities, monitor for anomalous outbound proxy traffic, and block untrusted outbound connections to uncommon high-numbered ports. YARA rules based on socket creation patterns and base64-encoded configuration strings are recommended, as detailed in Lumen's technical report.
Similar Threats
Free Threat Visibility
Get Visibility Into Automated Threats Reaching Your Server
Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.
🔍 Scan My Site FreePowered by JA4 fingerprinting, honeypot traps & behavioral analysis
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.