Darktrace GhostSocks Malware: A Growing Threat Utilizing Residential Proxies
Article Content
- •GhostSocks malware turns compromised devices into residential proxies, evading detection.
- •It has been linked to the Lumma Stealer, enhancing its operational capabilities.
- •Darktrace has observed a significant increase in GhostSocks incidents since late 2025.
GhostSocks is a malware that transforms compromised devices into residential proxies, enabling attackers to bypass IP detection tools. Originally marketed as Malware-as-a-Service on a Russian underground forum, it gained notoriety for its ability to blend malicious traffic with normal activity. The malware operates using the SOCKS5 proxy protocol and employs TLS encryption to conceal its communications. Its partnership with Lumma Stealer in 2024 significantly increased its adoption among threat actors. Darktrace has reported a rise in GhostSocks activity since late 2025, with multiple incidents detected across various sectors, including education. The malware also has backdoor capabilities, allowing attackers to execute commands and deploy additional payloads. Notably, ransomware group Black Basta has utilized GhostSocks for maintaining long-term access to victim networks. The current status indicates ongoing activity and a persistent threat to organizations.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (4)
Following this threat?
Track Black Basta, GhostSocks and Education in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Node.js Exploited in Ransomware Attacks Using EtherHiding Technique Since February 2026, threat actors have been exploiting the trusted Node.js runtime to deploy malicious payloads in targeted attacks against government departments, technology companies, and hotels. The technique leverages node.exe, a legitimate and signed developer tool, allowing attackers to run interpreted scripts…
Qilin Ransomware Targets Retelit, Major Telecom Provider in Italy The Qilin ransomware group has reportedly targeted Retelit SpA, a leading telecommunications operator in Italy. This attack is part of a broader campaign that has seen a significant increase in ransomware incidents attributed to Qilin since the start of 2026. The group exploits known vulnerabilities, particularly in…