typetechniqueconfidencehighcreated2026-08-18updated2026-08-18c2-protocolc2lateral-movementproxymitre-attckgo

SOCKS5 Proxy Pivoting

Malware embedding a SOCKS5 proxy server to pivot traffic through compromised hosts. Enables the attacker to route additional C2 traffic or external connections through the infected machine.

Detection / Fingerprint

  • Go type strings: main.p2pSocks, main.proxySocks, main.(*socks5Conn).Serve
  • Function names: main.forward, main.proxy, main.c2Server, main.copyConn
  • Standard SOCKS5 handshake sequence (0x05 0x01 0x00 auth negotiation)

Implementation Patterns

The AFK Stealer sibling bd6dead7 implements a full SOCKS5 server with:

  • main.p2pSocks — peer-to-peer SOCKS5 tunnel
  • main.proxySocks — standalone proxy listener
  • main.(*socks5Conn).handshake — SOCKS5 auth/handshake
  • main.(*socks5Conn).processRequest — CONNECT / BIND request handling
  • main.forward / main.copyConn — bidirectional traffic relay

Defensive Detection

  • Network: unexpected inbound TCP listeners on high ports from GUI-subsystem processes
  • Process: Go binaries opening listening sockets without being a known server application
  • Behavioral: process spawning both outbound WebSocket connections and inbound SOCKS5 listeners

Cross-References

  • Observed in: afk-stealer bd6dead7f5a0ec51
  • Related: raw-tcp-c2-socket — lower-level C2 transport alternative
  • Related: rat — concept page for remote-access tool capabilities