EarthWorm is a publicly available network tunneling utility used to create reverse SOCKS tunnels and port-forwarding channels, allowing attackers to proxy traffic through compromised systems and expose internal resources to external operator-controlled infrastructure. It is commonly used as a lightweight post-exploitation tool rather than as a standalone initial-access payload, and has been observed in intrusions where operators favored open-source or dual-use tooling over custom malware to reduce detection opportunities.
The tool has been used to establish covert outbound command-and-control paths, support lateral movement, and maintain access after compromise by relaying traffic from victim environments. Reported functionality includes SOCKS5 tunneling, reverse tunneling, and port transfer capabilities. EarthWorm has been deployed following exploitation of perimeter devices and servers, including PAN-OS firewalls and IIS servers, and has also appeared in broader enterprise intrusions to connect victim LANs to attacker infrastructure.
EarthWorm is strongly associated with multiple China-linked intrusion sets and espionage operations. It has been reported in activity involving Volt Typhoon, BackdoorDiplomacy, APT41-related reporting, Gelsemium-linked CL-STA-0046 activity, Jewelbug, and UAT-8837, among others. In these operations it was typically used alongside other tunneling, proxying, remote administration, credential access, and reconnaissance tools such as FRP, ReverseSocks5, DWAgent, Impacket, SharpHound, and Cobalt Strike.
EarthWorm supports multiple platforms and has been described as written in C with builds for Windows, Linux, macOS, and some ARM/MIPS environments. Its role in campaigns is primarily post-compromise network pivoting, proxying, and stealthy operator access rather than destructive impact.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
CVE-2025-53690 is a ViewState deserialization vulnerability that affects any version of Sitecore Experience Manager (XM), Experience Platform (XP), Experience Commerce (XC), and Managed Cloud deployed in the manner above. Successful exploitation of the vulnerability might lead to remote code execution and non-authorised access to information. | EARTHWORM (lfe.ico, ufp.exe, ufp.ico)
CVE-2026-0300 is an unauthenticated buffer overflow in the User-ID Authentication Portal (Captive Portal) service of PAN-OS. The vendor advisory states that exploitation yields arbitrary code execution with root privileges on PA-Series and VM-Series firewalls... exploitation has been observed since April 9, 2026, with successful remote code execution achieved by April 16, 2026. | Observed post-exploitation activity includes shellcode injection into the nginx worker process on the firewall, Active Directory enumeration using credentials extracted from the firewall, anti-forensic log cleanup, and deployment of network tunneling tools (EarthWorm, ReverseSocks5) for outbound command and control.
7 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
After exploiting the flaw, attackers deployed tunneling tools such as EarthWorm and ReverseSocks5, used stolen credentials to probe Active Directory, and deleted logs and other evidence to hide the intrusion.
After exploiting the flaw, attackers deployed tunneling tools such as EarthWorm and ReverseSocks5, used stolen credentials to probe Active Directory, and deleted logs and other evidence to hide the intrusion.
After exploiting the flaw, attackers deployed tunneling tools such as EarthWorm and ReverseSocks5, used stolen credentials to probe Active Directory, and deleted logs and other evidence to hide the intrusion.
They repeated CVE-2026-0300 exploitation on that device, achieved RCE again, and downloaded the EarthWorm and ReverseSocks5 network tunneling tools, likely to establish persistent tunneling and proxy capabilities for continued access.
EarthWorm, to create a reverse tunnel to attacker-controlled servers using SOCKS
10 distinct techniques documented for this family, organized by ATT&CK tactic.
Then they deployed EarthWorm and ReverseSocks5 tunnels for outbound C2
“Earthworm: A network tunneling tool used to ‘expose internal endpoints to attacker-owned remote infrastructure’.”
"APT41 used a tool called CLASSFON to covertly proxy network communications." / "BADCALL functions as a proxy server between the victim and C2 server." / "Sandworm Team's BCS-server tool can create an internal proxy server to redirect traffic..."
Then they deployed EarthWorm and ReverseSocks5 tunnels for outbound C2
Aria-body has the ability to use a reverse SOCKS proxy module... BADHATCH can use SOCKS4 and SOCKS5 proxies... GoBear implements SOCKS5 proxy functionality... Neo-reGeorg has the ability to establish a SOCKS5 proxy... Remcos uses the infected hosts as SOCKS5 proxies...
3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
29 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Инструмент для SOCKS5-туннелирования и проксирования трафика, используемый после эксплуатации для C2 и пивотирования во внутреннюю сеть.
A network tunneling tool used post-exploitation to pivot through compromised PAN-OS firewalls, reduce forensic footprint, and support covert command-and-control and internal movement.
EarthWorm is an open-source tunneling tool written in C that works across Windows, Linux, macOS, and ARM/MIPS platforms. It acts as a SOCKS5 proxy and port-forwarding utility, enabling covert communication channels, bypassing network restrictions, and lateral movement within compromised environments.
Network tunneling tool used post-compromise for outbound command and control.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.