Suo5 is an open-source HTTP tunneling and proxy tool used by attackers as a server-side tunneling webshell on compromised web servers and remote-access appliances. Its client exposes a SOCKS5 proxy and exchanges encapsulated TCP traffic with server-side code over HTTP or HTTPS, enabling access to internal systems and otherwise inaccessible subnets through the compromised host. Server implementations include .NET and Java, with experimental PHP support.
Suo5 uses HTTP/1.1 chunked transfer encoding to keep connections open for tunneled traffic. Its .NET implementation operates in half-duplex mode because of HTTP request-processing limitations. Server-side code checks a configurable User-Agent value before accepting client communications. The client uses the uTLS library to randomize TLS ClientHello characteristics, complicating network fingerprinting.
Observed deployments include ASP.NET tunneling webshells on Microsoft Exchange servers following Ivanti Cloud Services Appliance compromises, and a modified Java proxy implant on SonicWall SMA 1000 appliances. In the SonicWall intrusions attributed to UTA0533, the KNUCKLEBALL loader injected Suo5 into a legitimate Java process alongside the separate ORANGETAIL webshell. Attackers altered application routing and startup configuration to conceal and maintain access to these implants. Suo5 provided covert traffic forwarding and internal-network pivoting rather than the command-execution functionality supplied by ORANGETAIL. The tool has also been used by Houken in intrusions affecting French government, telecommunications, media, finance, and transport organizations. Its availability as public tooling means its presence alone does not establish threat-actor attribution.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
“CVE-2026-15410 — CVSS 7.2. A path-traversal flaw in the remove_hotfix workflow of ctrl-service, abused to escalate from a low-privilege service account to root.” Investigators reportedly recovered an encoded exploit at /tmp/hypdate.b64 on compromised appliances.
“CVE-2026-15409 — CVSS 10.0. A pre-authentication /wsproxy bypass allowing an unauthenticated external attacker to open a WebSocket tunnel to services intended to be accessible only from localhost.” The report states that UTA0533 chained this vulnerability with CVE-2026-15410 beginning June 22, 2026, before disclosure.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Suo5 is a modified version of the open-source HTTP forwarding proxy designed to provide covert tunneling through the compromised appliance.
while the second type is Suo5, which supports tunneling functionality.
19 distinct techniques documented for this family, organized by ATT&CK tactic.
SonicWall has disclosed two vulnerabilities affecting SMA 1000 Series secure remote access appliances... which can be chained by an unauthenticated remote attacker to achieve root-level remote code execution. SonicWall has confirmed both vulnerabilities were actively exploited in the wild as zero-days before a patch existed.
Godzilla ASPX, r57, suo5... several webshell and tunnel relays running Godzilla ASPX, suo5, r57, reGeorg, and Neo-reGeorg.
The latter injected two hidden Java components directly into a legitimate running SonicWall process, to keep the malware in memory.
The attacks are suspected to involve the exploitation of CVE-2026-15409 and CVE-2026-15410, which could be chained to facilitate arbitrary command execution and take over susceptible devices.
The attacker exploits CVE-2026-15410, a path-traversal flaw in the removehotfix process, causing a staged script to execute with full root privileges.
The latter injected two hidden Java components directly into a legitimate running SonicWall process, to keep the malware in memory.
port-forwarding/proxy tunneling tool used to relay traffic through compromised hosts
GlassFish : scripts Node.js déployant des WAR shells ... via SOCKS5 proxy local (127.0.0.1:1111)
They planted an HTTP proxy tunnel going by the name of suo5... The suo5.aspx webshell was dropped on the Exchange Server... a SOCKS5 proxy must be set up and the suo5 binary communicates with the server-side code to transmit TCP data encapsulated in the HTTP(S) communication.
36 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
22 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A tunneling and proxying tool used to relay traffic through compromised systems and support covert access or exfiltration.
SOCKS tunneling tool used to proxy attacker traffic through the compromised environment.
Open-source HTTP proxy launched during the attacks as part of post-exploitation activity.
An HTTP forwarding proxy agent deployed on compromised appliances to covertly forward traffic and support post-exploitation activity.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.