Stowaway is an open-source proxy and remote access tool, commonly implemented as a Go-based implant, that has been used in post-compromise operations to maintain covert connectivity, pivot through victim networks, and support follow-on intrusion activity. It is best characterized as a tunneling and proxy-capable remote access tool that enables operators to route traffic through compromised hosts, including multi-hop proxying, SOCKS5-style forwarding, reverse tunneling, port forwarding, remote shell access, and file transfer. Reported variants and deployments also support SSH-based tunneling and communications over multiple transports such as TCP, HTTP, and WebSocket, with encrypted channels including TLS and AES-256-GCM in some observed implementations.
The tool has been repeatedly observed in espionage-oriented intrusions and broader post-exploitation workflows rather than as a standalone initial-access payload. It has been delivered through DLL side-loading chains using legitimate Windows binaries, extracted as a second-stage implant via PowerShell and BITS-based download activity, and deployed after exploitation of enterprise infrastructure. It has also been used as a proxy utility to deliver additional tooling, including legitimate monitoring software in at least one ransomware-linked intrusion.
Stowaway has been associated with multiple China-nexus or suspected China-linked intrusion sets and campaigns, including activity involving long-term access to government, diplomatic, telecommunications, and other high-value organizations in Southeast Asia, South Asia, South America, southeastern Europe, and elsewhere. It has been reported in operations linked or potentially linked to clusters such as ToddyCat, UAT-8302, CL-STA-0048, and campaigns with possible ties to TetrisPhantom, as well as in incidents involving exploitation of Microsoft Exchange vulnerabilities. It has also appeared in a Fog ransomware intrusion, where its use alongside surveillance-oriented tooling suggested objectives beyond straightforward encryption and extortion.
Operationally, Stowaway is used to preserve persistent backdoor access, tunnel external traffic into internal enterprise environments, conceal operator origin, and facilitate lateral movement and staging of additional payloads. Its repeated use as a multi-hop proxy and tunneling utility makes it particularly valuable for stealthy command-and-control extension and internal pivoting on compromised Windows networks.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Some of the tools we saw used in post-compromise activity in those impacted since March 2 include: ... Stowaway multi-hop proxy tool
Some of the tools we saw used in post-compromise activity in those impacted since March 2 include: ... Stowaway multi-hop proxy tool
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Another example from this incident demonstrates the use of the PowerShell cmdlet Start-BitsTransfer. In this case, the second-stage Stowaway implant is extracted as follows.
A new Go-based RAT named Stowaway took the lead. It adds reverse tunneling and SSH-based tunneling on top of the proxy features.
Several executions of the Stowaway proxy tool were observed in the network under different names, such as ‘vhd.exe’, ‘vga.exe’ and ‘hhd.exe’.
To maintain persistent backdoor access, the group deploys Stowaway, a proxy tunneling tool written in Simplified Chinese, routing outside traffic into infected hosts within the enterprise.
23 distinct techniques documented for this family, organized by ATT&CK tactic.
Snippets showing both the listening and connecting executions of Stowaway, using a service installed on the machine... Windows event log ID 7045, showing the creation of the service which executes ‘vga.exe’... service named ‘RoHesJayPv’... remotely creating a service named ‘HkBnPoqLAj’.
Snippets showing both the listening and connecting executions of Stowaway, using a service installed on the machine... Windows event log ID 7045, showing the creation of the service which executes ‘vga.exe’... service named ‘RoHesJayPv’... remotely creating a service named ‘HkBnPoqLAj’.
Obfuscated Files or Information T1027 Basic description To bypass security solutions, attackers employ obfuscation.
the threat actor created a malicious file named ‘C:\Intel\svchost.exe’... attempting to mask the malware as benign activity... Additional executions of the Stowaway tunneling tool were also observed during this phase using the names ‘svchost.exe’, ‘tomcat.exe’, and ‘tomcat7.exe’.
Day 3: The threat actor successfully connected over RDP from the DESKTOP-PSGDD89 host to a server in the victim’s network... Phase 2: Lateral Movement... through RDP and tunneled connections.
The backdoor connects to command-and-control servers using ChaCha20 encryption for communications... Communications are transported over TCP, HTTP, or WebSocket channels with protection using AES-256-GCM or TLS encryption.
Stowaway is a multi-level proxy tool written in the Go language... Users can use this program to proxy external traffic to the intranet through multiple nodes, break through intranet access restrictions, construct a tree-like node network
The attacker used various tools for different purposes: collecting information for infiltration, port forwarding for establishing an external connection...
Some of the tools we saw used in post-compromise activity in those impacted since March 2 include: ... Stowaway multi-hop proxy tool
The backdoor connects to command-and-control servers using ChaCha20 encryption for communications... Communications are transported over TCP...
Technical details | Command and Control TA0011 | Ingress Tool Transfer T1105
The primary weapon in this campaign is the GoSerpent backdoor... Stowaway is a proxy and remote access tool... McMx is a basic Go-based proxy and remote access tool.
46 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Go-based remote access trojan introduced in the later phase of the campaign that provides reverse tunneling and SSH-based tunneling, and is used to deliver exfiltration components.
A customized proxy and remote access tool based on an open-source framework, supporting chained proxy paths, SOCKS5, port forwarding, reverse tunneling, remote shell, file transfer, and SSH-based tunneling over TCP, HTTP, or WebSocket with AES-256-GCM or TLS protection.
Go-based RAT/proxy compiled from an open-source framework and customized for stealth, supporting chained proxy paths, SOCKS5, port forwarding, reverse tunneling, remote shell, file transfer, and SSH-based tunneling over TCP, HTTP, or WebSocket with AES-256-GCM or TLS protection.
Proxy tunneling tool used to maintain persistent access by routing external traffic into infected enterprise hosts.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.