logo

GhostSocks Turns Victim Systems Into Residential Proxies for Evasive Cyberattacks

ID: ec444c06-1bf9-5030-b1fa-d1212f1f5c57

STIX ID: report--ec444c06-1bf9-5030-b1fa-d1212f1f5c57

Feed Name: cybersecurityNews.com

Threat Score
78/100

Date Published: 2026-03-31

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

GhostSocks is a GoLang-based Malware-as-a-Service that converts compromised home and office devices into TLS-wrapped SOCKS5 residential proxies to hide attacker traffic; it has been observed in partnership with Lumma Stealer and used by ransomware groups (e.g., Black Basta). The report documents detection events (Dec 2025), persistence mechanisms (Windows registry run keys), evasion techniques (TLS-wrapped tunnels, relay C2 architecture), and provides IOCs such as retreaw.click, www.lbfs.site, 159.89.46.92, 86.54.24.29, and filenames like Renewable.exe and Setup.exe.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.