EarthWorm is an open-source network tunneling and proxy utility written in C that is frequently deployed during post-exploitation. It supports SOCKS5 proxying, reverse SOCKS5 tunnels, and port forwarding, incorporating tunneling concepts from lcx/HTran. It runs on Windows, Linux, and macOS and has also been deployed on compromised enterprise firewalls. Its reverse tunnels expose internal systems to attacker-controlled infrastructure, allowing operators to relay command-and-control traffic, bypass network access restrictions, and support lateral movement.
EarthWorm has been used by multiple threat actors, including BackdoorDiplomacy, Volt Typhoon, Earth Estries, APT41, and UAT-8837. Observed deployments span intrusions affecting critical infrastructure, telecommunications, government organizations, and healthcare. Attackers have installed it after compromising Microsoft Exchange servers, Windows IIS servers, Sitecore applications, and PAN-OS firewalls; these compromises provide the foothold from which the tool operates rather than reflecting exploitation capabilities within EarthWorm itself. Earth Estries has used a VMProtect-packed version during post-exploitation, while other operators use EarthWorm alongside additional reverse-proxy and remote-access tools. EarthWorm is dual-use networking software rather than an inherently malicious implant, and its presence alone does not establish attribution to a particular threat actor.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Some of the tools we saw used in post-compromise activity in those impacted since March 2 include: ... EarthWorm tunnel tool
The Earthworm tool came as a more powerful replacement to the ageing lcx/Htran one. It incorporated lcx's core concepts ... and added SOCKS5 proxy and reverse SOCKS5 proxy functionalities.
Some of the tools we saw used in post-compromise activity in those impacted since March 2 include: ... EarthWorm tunnel tool
CVE-2025-53690 is a ViewState deserialization vulnerability that affects any version of Sitecore Experience Manager (XM), Experience Platform (XP), Experience Commerce (XC), and Managed Cloud deployed in the manner above. Successful exploitation of the vulnerability might lead to remote code execution and non-authorised access to information. | EARTHWORM (lfe.ico, ufp.exe, ufp.ico)
CVE-2026-0300 is an unauthenticated buffer overflow in the User-ID Authentication Portal (Captive Portal) service of PAN-OS. The vendor advisory states that exploitation yields arbitrary code execution with root privileges on PA-Series and VM-Series firewalls... exploitation has been observed since April 9, 2026, with successful remote code execution achieved by April 16, 2026. | Observed post-exploitation activity includes shellcode injection into the nginx worker process on the firewall, Active Directory enumeration using credentials extracted from the firewall, anti-forensic log cleanup, and deployment of network tunneling tools (EarthWorm, ReverseSocks5) for outbound command and control.
9 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
BackdoorDiplomacy has used EarthWorm for network tunneling with a SOCKS5 server and port transfer functionalities.
The actor has used Earthworm and a custom Fast Reverse Proxy (FRP) client with hardcoded C2 callbacks.
We observed Earth Estries using the following post-exploitation tools... A VMProtected version of EarthWorm, a SOCK5 network tunnel
The Earthworm tool came as a more powerful replacement to the ageing lcx/Htran one. It incorporated lcx's core concepts ... and added SOCKS5 proxy and reverse SOCKS5 proxy functionalities.
After exploiting the flaw, attackers deployed tunneling tools such as EarthWorm and ReverseSocks5, used stolen credentials to probe Active Directory, and deleted logs and other evidence to hide the intrusion.
12 distinct techniques documented for this family, organized by ATT&CK tactic.
Then they deployed EarthWorm and ReverseSocks5 tunnels for outbound C2
The actor has used Earthworm and a custom Fast Reverse Proxy (FRP) client with hardcoded C2 callbacks [T1090].
Some of the tools we saw used in post-compromise activity in those impacted since March 2 include: ... EarthWorm tunnel tool ... ReGeorg web shells ... Chisel
Then they deployed EarthWorm and ReverseSocks5 tunnels for outbound C2
Some of the tools we saw used in post-compromise activity in those impacted since March 2 include: ... Stowaway multi-hop proxy tool
Aria-body has the ability to use a reverse SOCKS proxy module... BADHATCH can use SOCKS4 and SOCKS5 proxies... GoBear implements SOCKS5 proxy functionality... Neo-reGeorg has the ability to establish a SOCKS5 proxy... Remcos uses the infected hosts as SOCKS5 proxies...
Adversaries may use a non-application layer protocol for communication between host and C2 server or among infected hosts within a network. Specific examples include use of network layer protocols, such as the Internet Control Message Protocol (ICMP), transport layer protocols, such as the User Datagram Protocol (UDP), session layer protocols, such as Socket Secure (SOCKS), as well as redirected/tunneled protocols, such as Serial over LAN (SOL).
3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
37 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
SOCKS5 tunneling tool used for post-exploitation network pivoting and access within compromised environments.
Инструмент для SOCKS5-туннелирования и проксирования трафика, используемый после эксплуатации для C2 и пивотирования во внутреннюю сеть.
A network tunneling tool used post-exploitation to pivot through compromised PAN-OS firewalls, reduce forensic footprint, and support covert command-and-control and internal movement.
EarthWorm is an open-source tunneling tool written in C that works across Windows, Linux, macOS, and ARM/MIPS platforms. It acts as a SOCKS5 proxy and port-forwarding utility, enabling covert communication channels, bypassing network restrictions, and lateral movement within compromised environments.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.