SOCKS5 Proxy Pivoting
Malware embedding a SOCKS5 proxy server to pivot traffic through compromised hosts. Enables the attacker to route additional C2 traffic or external connections through the infected machine.
Detection / Fingerprint
- Go type strings:
main.p2pSocks,main.proxySocks,main.(*socks5Conn).Serve - Function names:
main.forward,main.proxy,main.c2Server,main.copyConn - Standard SOCKS5 handshake sequence (
0x05 0x01 0x00auth negotiation)
Implementation Patterns
The AFK Stealer sibling bd6dead7 implements a full SOCKS5 server with:
main.p2pSocks— peer-to-peer SOCKS5 tunnelmain.proxySocks— standalone proxy listenermain.(*socks5Conn).handshake— SOCKS5 auth/handshakemain.(*socks5Conn).processRequest— CONNECT / BIND request handlingmain.forward/main.copyConn— bidirectional traffic relay
Defensive Detection
- Network: unexpected inbound TCP listeners on high ports from GUI-subsystem processes
- Process: Go binaries opening listening sockets without being a known server application
- Behavioral: process spawning both outbound WebSocket connections and inbound SOCKS5 listeners
Cross-References
- Observed in: afk-stealer
bd6dead7f5a0ec51 - Related: raw-tcp-c2-socket — lower-level C2 transport alternative
- Related: rat — concept page for remote-access tool capabilities