MicroSocks is an open-source SOCKS5 proxy utility commonly abused by threat actors for pivoting, tunneling, and covert access through compromised systems. It is not a bespoke malware family in the traditional sense, but it is frequently deployed as an operational tool during intrusions to relay traffic into internal environments, establish proxy infrastructure, and reduce the need for additional implants on downstream hosts.
Observed abuse spans multiple environments, including Linux-based edge appliances, firewalls, routers, and telecom infrastructure. Threat actors have used MicroSocks on compromised SonicWall SMA devices to tunnel RDP traffic into internal networks, on FortiWeb and consumer routers to build proxy access, and in telecom intrusions to support covert lateral access and routing through compromised nodes. In router-focused campaigns, operators deployed MicroSocks after exploiting device vulnerabilities and used it to enroll compromised devices into residential proxy networks with persistence mechanisms. In other intrusions, its use enabled attackers to maintain access while minimizing on-host malware deployment inside victim networks.
MicroSocks has been associated with activity by several threat clusters as a supporting tool rather than a primary payload, including Head Mare and CL-STA-0969/Liminal Panda overlap reporting, as well as unidentified actors abusing edge devices and routers. Its role is typically post-compromise: providing SOCKS5 proxying for operator traffic, internal access, and stealthier follow-on operations. Because it is a legitimate open-source utility, its presence is best interpreted in context with exploitation, persistence, tunneling, and other intrusion artifacts.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
In December 2025, Ctrl-Alt-Intel identified an unknown threat actor leveraging the open-source tool microsocks, deployed to compromised FortiWeb firewalls. We have been hunting for abuse of microsocks ever since.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Также в рамках атак мы зафиксировали инструмент MicroSocks — реализацию SOCKS5-прокси, полученную из открытого репозитория на GitHub.
...using a mix of custom and public tools such as Microsocks, FRP, FScan, and Responder...
17 distinct techniques documented for this family, organized by ATT&CK tactic.
Persistence on the TP-Link devices was achieved through three mechanisms... RC scripts -> modification of /etc/rc.local.
Using exec -a '[kworker/0:1]', the proxy binary masquerades as a kernel worker thread while starting a SOCKS5 listener.
tplink_stager.sh self-deletes original and cleans wget/curl temp files.
Subsequently, they utilized the microsocks proxy to gain access to the internal network by tunneling traffic through the compromised device.
T1090.001 Proxy: Internal Proxy PhantomCore использовали механизм проксирования трафика для организации связи между скомпрометированными узлами Rsocx, tsocks, wstunnel, microsocks, localtonet
Также в рамках атак мы зафиксировали инструмент MicroSocks — реализацию SOCKS5-прокси, полученную из открытого репозитория на GitHub.
3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Open-source SOCKS5 proxy tool deployed on compromised FortiWeb firewalls and TP-Link routers to enroll devices into a residential proxy network. In the TP-Link campaign it was downloaded by tplink_stager.sh, run under a masqueraded process name, and exposed on a random high port for proxying attacker traffic.
SOCKS5 proxy utility sourced from an open-source GitHub repository and used as part of post-exploitation tooling to organize network access.
A lightweight SOCKS5 proxy often used for tunneling traffic and establishing covert channels.
Open-source SOCKS5 proxy used for pivoting/tunneling within compromised telecom environments (also launched after establishing GTP tunnel via SGSN emulator script).
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.