GhostSocks Malware — Analysis, Campaigns & Threat Activity

Threat entity extracted from intelligence sources

Frequency
9
occurrences
First Seen
March 4, 2026
Last Seen
June 9, 2026

GhostSocks is a malware family tracked across 5 threat clusters and 9 intelligence report mentions on ThreatCluster. First observed March 4, 2026; most recent activity June 9, 2026.

Related Threat Clusters

  • Evolution of Chinese-Nexus Cyber Operations: Strategic Long-Term Threats

    Recent research from Darktrace reveals the evolution of Chinese-nexus cyber operations over the past two decades, highlighting a shift from high-volume attacks to more strategic, identity-centric intrusions. This change…

    204 articles · Updated April 2, 2026
  • Mini Shai-Hulud Supply Chain Attack Targets SAP npm Packages

    A new supply chain attack, dubbed 'Mini Shai-Hulud', has compromised multiple npm packages related to SAP's Cloud Application Programming Model (CAP). This attack involves injecting malicious preinstall scripts into…

    697 articles · Updated April 29, 2026
  • GhostSocks Malware: A Growing Threat Utilizing Residential Proxies

    GhostSocks is a malware that transforms compromised devices into residential proxies, enabling attackers to bypass IP detection tools. Originally marketed as Malware-as-a-Service on a Russian underground forum, it…

    4 articles · Updated March 26, 2026
  • Rise of AI-Driven Scams Targeting UK SMEs

    UK small and medium-sized enterprises (SMEs) are increasingly vulnerable to sophisticated AI-driven scams, as highlighted by recent reports. The emergence of 'AI scams 2.0' combines traditional social engineering…

    746 articles · Updated March 12, 2026
  • OpenClaw Ecosystem Faces Ongoing Security Vulnerabilities

    The OpenClaw ecosystem, previously known as ClawdBot and Moltbot, is experiencing significant security vulnerabilities, including bot takeover and remote code execution (RCE) exploits. Security researchers, including…

    299 articles · Updated February 2, 2026

Recent Intelligence Reports

  • Threat Actors Exploit AI Brand Lures for Credential Theft | Let's Data Science — Letsdatascience · June 9, 2026
  • Malicious npm Package Exfiltrates Files From Claude User Directory | Let's Data Science — Letsdatascience · May 27, 2026
  • How Chinese-Nexus Cyber Operations Have Evolved — Darktrace · April 2, 2026
  • How Chinese-Nexus Cyber Operations Have Evolved — Darktrace · April 2, 2026
  • How Chinese-Nexus Cyber Operations Have Evolved — Darktrace · April 2, 2026
  • Tracking & Detecting GhostSocks Malware — Darktrace · March 26, 2026
  • Tracking & Detecting GhostSocks Malware — Darktrace · March 26, 2026
  • Malware-laced OpenClaw installers get Bing AI search boost — Theregister · March 4, 2026

CVSS v3.1 Breakdown