GhostSocks Turns Victim Systems Into Residential Proxies for Evasive Cyberattacks
ID: ec444c06-1bf9-5030-b1fa-d1212f1f5c57
STIX ID: report--ec444c06-1bf9-5030-b1fa-d1212f1f5c57
Feed Name: cybersecurityNews.com
GhostSocks is a GoLang-based Malware-as-a-Service that converts compromised home and office devices into TLS-wrapped SOCKS5 residential proxies to hide attacker traffic; it has been observed in partnership with Lumma Stealer and used by ransomware groups (e.g., Black Basta). The report documents detection events (Dec 2025), persistence mechanisms (Windows registry run keys), evasion techniques (TLS-wrapped tunnels, relay C2 architecture), and provides IOCs such as retreaw.click, www.lbfs.site, 159.89.46.92, 86.54.24.29, and filenames like Renewable.exe and Setup.exe.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
