Suo5 is an open-source HTTP proxy and tunneling tool used as post-exploitation infrastructure to relay attacker traffic through compromised systems. It is commonly deployed as a server-side web component or injected proxy agent that encapsulates TCP communications inside HTTP or HTTPS, allowing operators to establish SOCKS5-style access and pivot into internal networks reachable from the infected host. It has been described as a higher-performance alternative to reGeorg and Neo-reGeorg and supports multiple server-side implementations, including .NET and Java.
Operationally, Suo5 is used to create covert forwarding channels for remote access, internal pivoting, and traffic relaying. It can function as a webshell-style tunnel on internet-facing servers such as Microsoft Exchange, and it has also been observed injected into legitimate processes on compromised network appliances to provide in-memory forwarding capability. Reported implementations use long-lived HTTP connections and chunked transfer encoding to carry proxied traffic, and HTTPS deployments can be difficult to fingerprint because some variants use randomized TLS client behavior.
Suo5 has been observed in multiple intrusion sets and campaigns. It was used in intrusions involving exploitation of Ivanti Cloud Services Appliance vulnerabilities, including deployment on an internet-facing Exchange server to tunnel into internal systems. It was also observed in campaigns attributed to the Houken cluster, which ANSSI linked to UNC5174, where it was used after exploitation of Ivanti CSA devices and associated follow-on compromise of internal infrastructure. In 2026, Suo5 was repeatedly reported in attacks against SonicWall SMA 1000 appliances, where threat actors including UTA0533 and later INC Ransomware deployed or injected it alongside KNUCKLEBALL, ORANGETAIL, and ROOTRUN after chaining SonicWall zero-days to obtain root access. Additional reporting tied Suo5 to MS-SQL and IIS compromises in cryptomining-oriented activity, where it appeared among webshell tooling used for tunneling and persistence.
The tool is best characterized as a covert proxy component rather than a standalone destructive payload. Its primary role is to support post-compromise access, lateral movement, and concealment of operator traffic through trusted or strategically placed hosts, including enterprise servers and edge appliances.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The chain combines CVE-2026-15409 (CVSS 10.0), a maximum-severity pre-authentication wsproxy bypass, with CVE-2026-15410 (CVSS 7.2), a path-traversal flaw in the removehotfix process. The first issue opens a WebSocket tunnel to services that should only accept local connections. | With root access, the attacker deploys a durable backdoor (ROOTRUN), a covert forwarding tool (Suo5), and a memory-resident web shell (ORANGETAIL/KNUCKLEBALL loader), altering startup and routing settings for persistence.
The chain combines CVE-2026-15409 (CVSS 10.0), a maximum-severity pre-authentication wsproxy bypass, with CVE-2026-15410 (CVSS 7.2), a path-traversal flaw in the removehotfix process. The second can turn a low-privilege foothold into root control by causing a staged script to run with full system rights. | With root access, the attacker deploys a durable backdoor (ROOTRUN), a covert forwarding tool (Suo5), and a memory-resident web shell (ORANGETAIL/KNUCKLEBALL loader), altering startup and routing settings for persistence.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The attacks involve the deployment of a Python script named KNUCKLEBALL that's used to launch Suo5, an open-source HTTP proxy, and a Behinder-like custom Java web shell dubbed ORANGETAIL.
while the second type is Suo5, which supports tunneling functionality.
18 distinct techniques documented for this family, organized by ATT&CK tactic.
The suo5.aspx webshell was dropped on the Exchange Server at the location C:\Program Files\Microsoft\Exchange Server\V15\FrontEnd\HttpProxy\owa\auth\OutlookEN.aspx .
The latter injected two hidden Java components directly into a legitimate running SonicWall process, to keep the malware in memory.
The attacks are suspected to involve the exploitation of CVE-2026-15409 and CVE-2026-15410, which could be chained to facilitate arbitrary command execution and take over susceptible devices.
The attacker exploits CVE-2026-15410, a path-traversal flaw in the removehotfix process, causing a staged script to execute with full root privileges.
The latter injected two hidden Java components directly into a legitimate running SonicWall process, to keep the malware in memory.
port-forwarding/proxy tunneling tool used to relay traffic through compromised hosts
In one case, the attacker uploaded on an internet-facing Microsoft Exchange Server a file named OutlookEN.aspx... OutlookEN.aspx corresponds to the HTTP proxy tunnel tool called suo5... The following public tools were observed on the victims’ network: • Proxy and tunneling: – Iox; – FRP; – NPS (NPC); – EarthWorm; – GoHTran; – ReverseSocks5; – Suo5;
GlassFish : scripts Node.js déployant des WAR shells ... via SOCKS5 proxy local (127.0.0.1:1111)
They planted an HTTP proxy tunnel going by the name of suo5... The suo5.aspx webshell was dropped on the Exchange Server... a SOCKS5 proxy must be set up and the suo5 binary communicates with the server-side code to transmit TCP data encapsulated in the HTTP(S) communication.
36 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
18 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Open-source HTTP proxy launched during the attacks as part of post-exploitation activity.
An HTTP forwarding proxy agent deployed on compromised appliances to covertly forward traffic and support post-exploitation activity.
An HTTP forwarding proxy agent deployed on compromised appliances to covertly relay traffic.
A memory-injected HTTP forwarding proxy implanted into the Workplace JVM to provide covert tunneling, internal pivoting, reverse proxying, C2, and traffic forwarding through the compromised VPN appliance.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.