Skip to content
GhostSocks Malware: A Growing Threat Utilizing Residential Proxies

GhostSocks Malware: A Growing Threat Utilizing Residential Proxies

First seen 27 Mar 2026, 08:16 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster March 28, 2026 at 08:14 UTC
  • GhostSocks malware turns compromised devices into residential proxies, evading detection.
  • It has been linked to the Lumma Stealer, enhancing its operational capabilities.
  • Darktrace has observed a significant increase in GhostSocks incidents since late 2025.

GhostSocks is a malware that transforms compromised devices into residential proxies, enabling attackers to bypass IP detection tools. Originally marketed as Malware-as-a-Service on a Russian underground forum, it gained notoriety for its ability to blend malicious traffic with normal activity. The malware operates using the SOCKS5 proxy protocol and employs TLS encryption to conceal its communications. Its partnership with Lumma Stealer in 2024 significantly increased its adoption among threat actors. Darktrace has reported a rise in GhostSocks activity since late 2025, with multiple incidents detected across various sectors, including education. The malware also has backdoor capabilities, allowing attackers to execute commands and deploy additional payloads. Notably, ransomware group Black Basta has utilized GhostSocks for maintaining long-term access to victim networks. The current status indicates ongoing activity and a persistent threat to organizations.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 166d ago How this analysis works

Timeline

2024-01-01
Partnership with Lumma Stealer announced
2025-01-01
Steady increase in GhostSocks activity reported by Darktrace
2025-12-01
Darktrace detects GhostSocks activity in education sector
2026-03-26
Darktrace publishes analysis of GhostSocks malware

More articles in this cluster (4)

Following this threat?

Track Black Basta, GhostSocks and Education in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed