Stowaway is an open-source, Go-based remote-access and multi-hop proxy tool used in malicious operations on Windows and Linux systems. It supports SOCKS5 proxying, port forwarding, reverse tunneling, SSH-based tunneling, remote shell access, and file transfer. These functions allow operators to route traffic through compromised hosts, reach internal network resources, and deploy additional tools. Observed implementations support TCP, HTTP, and WebSocket communication with AES-256-GCM or TLS protection, as well as inbound TCP connections.
Stowaway is predominantly deployed after an initial compromise, including through existing backdoors and compromised public-facing servers. Operators have launched it through DLL sideloading, extracted it from encoded second-stage payloads, disguised it under alternative executable names, and incorporated it into stitched DLLs containing legitimate system-library code. Startup-folder execution has been used to relaunch it persistently. Its proxy tunnels provide continuing remote access and facilitate reconnaissance and lateral movement without exposing internal systems directly to the internet.
Stowaway has been used by multiple unrelated threat actors, including Earth Lamia, CL-STA-0048, ToddyCat, and UAT-8302, as well as in BlackCat-affiliated and Fog ransomware intrusions. Observed victim environments include government and diplomatic organizations, telecommunications providers, and financial institutions. It has also delivered follow-on components such as TmcLoader and the legitimate employee-monitoring application Syteca. Its public availability and use across espionage and financially motivated operations make its presence insufficient for attribution to a particular actor.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Some of the tools we saw used in post-compromise activity in those impacted since March 2 include: ... Stowaway multi-hop proxy tool
Some of the tools we saw used in post-compromise activity in those impacted since March 2 include: ... Stowaway multi-hop proxy tool
8 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
From further analysis of TA413 activity, we also identified evidence that the group is likely using the open-source proxy tool Stowaway.
Establishing proxy tunnels to the Victims' network with tools such as "rakshasa" and "Stowaway".
The proxy/tunneling/scanning section lists https://github.com/ph4ntonn/Stowaway among projects used in the operation.
The Cobalt Strike beacon was injected into an SQL server process, enabling C2 communication to deliver additional malware such as `Stowaway` and `iox` to tunnel network traffic through compromised systems.
Another example from this incident demonstrates the use of the PowerShell cmdlet Start-BitsTransfer. In this case, the second-stage Stowaway implant is extracted as follows.
A new Go-based RAT named Stowaway took the lead. It adds reverse tunneling and SSH-based tunneling on top of the proxy features.
26 distinct techniques documented for this family, organized by ATT&CK tactic.
Snippets showing both the listening and connecting executions of Stowaway, using a service installed on the machine... Windows event log ID 7045, showing the creation of the service which executes ‘vga.exe’... service named ‘RoHesJayPv’... remotely creating a service named ‘HkBnPoqLAj’.
Snippets showing both the listening and connecting executions of Stowaway, using a service installed on the machine... Windows event log ID 7045, showing the creation of the service which executes ‘vga.exe’... service named ‘RoHesJayPv’... remotely creating a service named ‘HkBnPoqLAj’.
Obfuscated Files or Information T1027 Basic description To bypass security solutions, attackers employ obfuscation.
the threat actor created a malicious file named ‘C:\Intel\svchost.exe’... attempting to mask the malware as benign activity... Additional executions of the Stowaway tunneling tool were also observed during this phase using the names ‘svchost.exe’, ‘tomcat.exe’, and ‘tomcat7.exe’.
The actors use SSH endpoints and chained relays to enable interactive remote access.
Day 3: The threat actor successfully connected over RDP from the DESKTOP-PSGDD89 host to a server in the victim’s network... Phase 2: Lateral Movement... through RDP and tunneled connections.
The actors open non-standard SSH and HTTP ports and use separate C2 channels within high-traffic nodes.
The attacker used various tools for different purposes: collecting information for infiltration, port forwarding for establishing an external connection...
The group leverages STOWAWAY to build chained relays and enable interactive remote access.
The backdoor connects to command-and-control servers using ChaCha20 encryption for communications... Communications are transported over TCP...
Technical details | Command and Control TA0011 | Ingress Tool Transfer T1105
The primary weapon in this campaign is the GoSerpent backdoor... Stowaway is a proxy and remote access tool... McMx is a basic Go-based proxy and remote access tool.
The malware accepted inbound TCP network connections via port 7475. VSOCKpuppet accepts connections via the VSOCK interface (including port 6667).
52 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Go-based remote access trojan introduced in the later phase of the campaign that provides reverse tunneling and SSH-based tunneling, and is used to deliver exfiltration components.
A customized proxy and remote access tool based on an open-source framework, supporting chained proxy paths, SOCKS5, port forwarding, reverse tunneling, remote shell, file transfer, and SSH-based tunneling over TCP, HTTP, or WebSocket with AES-256-GCM or TLS protection.
Go-based RAT/proxy compiled from an open-source framework and customized for stealth, supporting chained proxy paths, SOCKS5, port forwarding, reverse tunneling, remote shell, file transfer, and SSH-based tunneling over TCP, HTTP, or WebSocket with AES-256-GCM or TLS protection.
Proxy tunneling tool used to maintain persistent access by routing external traffic into infected enterprise hosts.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.