Honeygain is a commercial proxyware application that allows users to monetize unused internet bandwidth by routing third-party traffic through enrolled devices. In intrusion and malware contexts, it has been repeatedly abused by financially motivated operators who silently install legitimate or modified Honeygain clients on compromised Windows systems and bind those installations to attacker-controlled accounts so the adversary, rather than the victim, receives the revenue. This abuse pattern is commonly described as proxyjacking.
Observed malicious use includes trojanized installers that bundle Honeygain with additional payloads such as cryptocurrency miners and information stealers, as well as botnet-style loaders that deploy patched Honeygain binaries with user-interface elements removed, persistence added, and embedded credentials or configuration changes that automate enrollment into attacker infrastructure. Operators have also modified local settings to suppress notifications and reduce user awareness. In multi-stage campaigns, Honeygain has been one monetization component alongside XMRig-based Monero mining and browser credential theft.
Honeygain has also appeared in broader proxyware distribution operations attributed to threat actors such as Larva-25012, which has delivered multiple proxyware families through deceptive software installers and malvertising tied to cracked or fake utility downloads. In these campaigns, Honeygain may be installed directly or used as part of a rotating set of proxyware payloads selected by the operator.
The primary security impact of Honeygain abuse is not intrinsic destructive behavior by the software itself, but the covert resale of victim bandwidth and the routing of third-party traffic through compromised endpoints. This can create privacy, legal, reputational, and operational risk for organizations because abusive or suspicious traffic may appear to originate from the victim network, potentially bypassing reputation-based controls and complicating attribution. In enterprise environments, unauthorized Honeygain presence on endpoints is therefore a strong indicator of policy violation, unwanted software, or malware-enabled monetization activity.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
9 distinct techniques documented for this family, organized by ATT&CK tactic.
Throughout each stage of the infection process, the malware transmits status updates by embedding the information into the User-Agent header of HTTP requests that are made.
On screen, it's a relaxing fish tank. Or a clock. Or solitaire. Or puppies. Under the hood, it is a residential proxy: software that can send other people's internet traffic out through your living room.
In the Massive sample, the proxy session parses a server-supplied `host:port` value and opens a `net.Socket` to it. In the Honeygain/Oxylabs sample, a server message with `messageType: "connect"` supplies `address.host` and `address.port`, and later chunk messages write bytes into that connection.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Commercial proxyware service abused in proxyjacking campaigns to monetize victim bandwidth when installed without consent.
A proxyware program used to monetize infected hosts by reselling their network bandwidth/resources; mentioned in the context of fake YouTube downloader sites distributing proxyware.
A legitimate proxyware client that attackers trojanize, patch, or silently install to monetize victim bandwidth and disguise malicious activity. The content describes modified clients with hardcoded credentials/API keys and disabled notifications.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.