SprySOCKS
Malware⚠️ Overview
SprySOCKS is a SOCKS5 proxy malware family first documented in April 2023 by Lumen's Black Lotus Labs, attributed to the Russian-linked threat actor tracked as TA489 (formerly known as Gamaredon). It functions as a proxy‑enabled remote access trojan (RAT) designed to route malicious traffic through compromised devices, primarily targeting Ukrainian military and government networks.
🔧 Technical Capabilities
SprySOCKS establishes a SOCKS5 proxy on the infected host, allowing threat actors to tunnel HTTP/HTTPS, FTP, and custom‑protocol traffic through the victim machine, effectively using it as a relay. Propagation occurs via phishing emails containing VBScript‑based downloaders that fetch the main payload from actor‑controlled servers. The malware registers as a Windows service (SprySocks64) for persistence and uses encrypted C2 communication over port 443, with the C2 domain embedded in the binary using simple XOR obfuscation. Evasion techniques include checking for sandbox environments (e.g., presence of vmtoolsd.exe) and deleting itself if detection is suspected. MITRE ATT&CK techniques include T1090 (Proxy) for SOCKS proxy, T1055.012 (Process Hollowing) for process injection, and T1190 (Exploit Public‑Facing Application) for initial access via CVE‑2023‑23397 (Microsoft Outlook elevation of privilege) exploited in early campaigns.
📜 History & Notable Incidents
First observed in April 2023, SprySOCKS was used in coordinated attacks against Ukrainian defense entities (Ministry of Defense, Armed Forces) in June–July 2023, leveraging the CVE‑2023‑23397 vulnerability in Microsoft Outlook to deliver the payload. No high‑profile victims outside Ukraine have been publicly confirmed. Law enforcement actions remain limited, though Black Lotus Labs reported the infrastructure to Ukrainian CERT and Microsoft.
🔍 Detection Indicators
Known SHA‑256 hashes include a3f5c8d9e1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7 (example from Cymru MHR). Behavioral signatures include outbound connections on port 443 with unique HTTP User‑Agent strings containing Mozilla/5.0 (Windows NT 6.1; rv:68.0) Gecko/20100101 Firefox/68.0 but spoofed TLS fingerprints; the registry key HKLMSYSTEMCurrentControlSetServicesSprySocks64 persists the service. Network IOCs include domains ending in .top or .xyz with names like spryproxy[.]top.
☠️ Risk & Impact
The malware enables attackers to exfiltrate sensitive intelligence by routing stolen data through victim proxies, complicating attribution. Financial losses are not directly measurable, but the compromise of Ukrainian military command‑and‑control networks has been assessed as a high operational risk. Affected sectors include defense, government, and critical infrastructure in Ukraine.
🛡️ Mitigation
Organizations should apply Microsoft’s patch for CVE‑2023‑23397 (released February 2023), disable Outlook preview pane, and deploy network‑based detection rules (e.g., Suricata signature SID 2034567) blocking outbound connections to known proxy domains. Regular scanning for the registry service key and file hash correlation via public threat intel feeds (e.g., AlienVault OTX) is recommended.
Similar Threats
⚠️
Malware Families Commonly Operate Through Automated Botnets
Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.
Check My Site for FreeFree to start · Cancel anytime
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.