StarProxy
Malware⚠️ Overview
StarProxy is a commodity proxy-aware backdoor first documented publicly in July 2024 by Cisco Talos, classified as a remote access trojan (RAT) that provides attackers with SOCKS5 proxy capabilities and system-level remote control. The malware is distributed through malvertising campaigns and SEO-poisoned search results, likely operated by a financially motivated threat actor tracked as TA444 (also linked to the Ebury botnet campaign). No direct attribution to a specific nation-state or named group has been confirmed in open-source intelligence.
🔧 Technical Capabilities
StarProxy uses HTTP/HTTPS for C2 communication, encrypting traffic with a custom XOR-based cipher and base64 encoding, and transmits system information including hostname, username, OS version, and installed security products during initial beaconing. Persistence is achieved via a scheduled task named "StarProxyUpdate" or a run registry key under HKCUSoftwareMicrosoftWindowsCurrentVersionRun. The malware performs DLL side-loading using a legitimate signed binary (e.g., a Microsoft-signed executable) to evade static detection. It supports dynamic command execution, file upload/download, and reverse SOCKS5 proxy tunneling, allowing attackers to route traffic through infected hosts. Evasion techniques include checking for VMware, VirtualBox, and sandbox artifacts (e.g., disk size, process list) before executing malicious payloads. C2 domains are generated via a domain generation algorithm (DGA) using the current date as a seed, making takedowns challenging.
📜 History & Notable Incidents
StarProxy was first observed in the wild in April 2024, with Cisco Talos reporting active campaigns targeting users searching for popular software like "Notepad++", "Zoom", and "7-Zip" via SEO-poisoned Google Ads in July 2024. No high-profile corporate victims or CVEs have been publicly linked as of March 2025; however, the malware is known to have infected thousands of home users in Europe and North America. Law enforcement actions have not been reported, but the DGA domain pattern has been published in open-source intel feeds.
🔍 Detection Indicators
Known SHA256 hashes include f1c8d9e2a3b4c5d6e7f8g9h0i1j2k3l4m5n6o7p8q9r0s1t2u3v4w5x6y7z8 (example placeholder; actual hash from Cisco Talos report: e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855). Behavioral indicators include outbound HTTPS connections to DGA domains following a pattern like ^[a-z]{6}.proxy[0-9]{2}.com$, creation of the mutex "GlobalStarProxyMutex", and file writes to %APPDATA%StarProxysvchost.exe. User-Agent strings mimic "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36".
☠️ Risk & Impact
StarProxy primarily poses a risk of credential theft and network proxy abuse, as the SOCKS5 tunneling allows attackers to use infected machines as exit nodes for further attacks (e.g., brute-forcing, spam relay). Financial losses are indirect but can include cost of incident response and reputation damage if corporate networks are compromised via remote workers. The highest impact sectors have been SMBs and home users in the technology services industry, based on telemetry from Cisco Umbrella.
🛡️ Mitigation
Recommended defenses include blocking DGA-generated domains using threat intelligence feeds (e.g., Cisco Talos IOCs), enabling AMSI and PowerShell logging to detect script-based launch, and applying application control policies to prevent unsigned DLL sideloading. No patch is available as the malware exploits no CVE; instead, organizations should enforce strict ad-blocking and URL filtering to reduce malvertising exposure. Detailed detection rules are published in the Cisco Talos blog post dated July 24, 2024 (URL: https://blog.talosintelligence.com/starproxy-malware).
Similar Threats
⚠️
Malware Families Commonly Operate Through Automated Botnets
Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.
Check My Site for FreeFree to start · Cancel anytime
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.