Threats Tagged 'socks proxy'
View all threats tagged with 'socks proxy'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'socks proxy'
Click on any threat for detailed analysis and mitigation recommendations
Between late July and mid-August 2026, multiple organizations were compromised by a sophisticated modular RAT disguised as a legitimate Exodus cryptocurrency wallet. Victims were tricked through fake PDFs or software updates delivered via JavaScript files that downloaded a tampered Windows Installer package. The installer deploys genuine Exodus wallet version 24.33.4 with three modified files that prevent the user interface from displaying while establishing persistent access. The payload includes six modules providing hidden VNC, SOCKS proxy, browser credential theft, file management, remote shell, and script execution capabilities. Communication occurs via Azure Table Storage as a dead drop mechanism, avoiding traditional command and control domains. The RAT maintains persistence through scheduled tasks executing hourly and includes mechanisms to bypass corporate proxy configurations. Join the discussion | AlienVault OTX General | 09/01/2026, 18:13:21 UTC Added: 09/02/2026, 11:52:17 UTC |
Since January 2026, a threat actor likely functioning as an initial access broker for ransomware operations has been targeting organizations through Microsoft Teams vishing attacks. Attackers impersonate IT helpdesk staff to convince victims to initiate Quick Assist remote sessions. Following initial compromise, PowerShell scripts deploy a Go-based backdoor called GoGRPC, which exists in four distinct variants: Lep, Giver, Pet, and Kind. These variants communicate with command-and-control infrastructure using gRPC over HTTP/2, an uncommon approach that helps blend malicious traffic with legitimate communications. Additional tools observed include BlindDoor backdoor, RevSocket and PyGRPC SOCKS proxies, S3Siphon data exfiltration utility, and RSOX Rust-based proxy relay. Recent campaigns show increased sophistication and selectivity, with heightened focus on corporate environments through enhanced PowerShell scripts capable of antivirus detection, domain controller fingerprinting, and system reconnaissance b... Join the discussion | AlienVault OTX General | 07/27/2026, 16:45:15 UTC Added: 07/28/2026, 10:22:27 UTC |
Google Threat Intelligence Group (GTIG) is tracking BRICKSTORM malware activity, which is being used to maintain persistent access to victim organizations in the United States. Since March 2025, Mandiant Consulting has responded to intrusions across a range of industry verticals, most notably legal services, Software as a Service (SaaS) providers, Business Process Outsourcers (BPOs), and Technology. The value of these targets extends beyond typical espionage missions, potentially providing data to feed development of zero-days and establishing pivot points for broader access to downstream victims. Join the discussion | AlienVault OTX General | 10/08/2025, 15:21:42 UTC Added: 10/08/2025, 15:30:51 UTC |
Showing 1 to 3 of 3 results