RSOCX
rsocx is an open-source reverse SOCKS proxy / SOCKS5 proxy tool used to establish reverse connections and tunnel traffic within compromised environments. The provided content describes it being used for covert tunneling, internal pivoting, and remote access, including reverse-connect operation over non-standard port 8008. It has been observed in multiple intrusion contexts rather than as a bespoke malware family. In the 2025 Poland wiper intrusions, adversaries used rsocx (including filenames r.exe and rsocx.exe) to create a reverse SOCKS proxy inside internal infrastructure; ESET reported attempted reverse-connect use to 31.172.71[.]5:8008 prior to DynoWiper deployment. In that incident, rsocx activity was associated with a broader multi-stage intrusion involving credential theft, reconnaissance, and eventual destructive malware deployment, and ESET noted the IP was likely a compromised host associated with progamevl[.]ru and hosted by Fornex Hosting S.L. The content also states PhantomCore stored or staged rsocx samples on compromised legitimate servers and used the utility alongside MeshAgent and other tools. Mandiant observed UNC3944 / Scattered Spider using covert tunneling tools including rsocx, and specifically reported Scattered Spider installing the open-source rsocx reverse proxy tool on a targeted ESXi appliance during activity cluster C0027. Across the cited reporting, rsocx is associated with Sandworm-linked destructive activity in Poland, PhantomCore operations, and Scattered Spider / UNC3944 intrusions, where it supports proxying, tunneling, and access to devices without relying on normal VPN or MFA pathways.
Hunt this family in your stack
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
Groups observed using it
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
PhantomCore gains access to servers of legitimate sites and later uses them to store samples of MeshAgent, PhantomTaskShell, and Rsocx.
Scattered Spider installed the open-source rsocx reverse proxy tool on a targeted ESXi appliance.
Techniques & procedures
8 distinct techniques documented for this family, organized by ATT&CK tactic.
Resource Development
3 techniques
Resource Development
PhantomCore gains access to servers of legitimate sites and later uses them to store samples of MeshAgent, PhantomTaskShell, and Rsocx
Command and Control
5 techniques
Command and Control
During the 2025 Poland Wiper Attacks, the adversaries utilized the rsocx tool identified as r.exe and rsocx.exe to tunnel within the internal infrastructure using a Reverse SOCKS Proxy.
T1090.001 Proxy: Internal Proxy PhantomCore использовали механизм проксирования трафика для организации связи между скомпрометированными узлами Rsocx, tsocks, wstunnel, microsocks, localtonet
Several entries mention use of proxy and tunneling tools including PLINK, Venom proxy, GOST reverse proxy, Ligolo, Cloudflared, rsocx reverse proxy, Iox proxy tool, NPS tunneling tool, and AirVPN.
Recent activity
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Proxy/tunneling tool used to create a reverse SOCKS proxy for internal network traversal and communications over a non-standard port.
SOCKS5 proxy tool used to establish reverse connections to external servers, supporting attacker remote access and pivoting.
RSocx is used by PhantomCore as an external proxy/tunneling tool to relay traffic from infected hosts and support command-and-control communications.
Reverse proxy tool used to proxy/tunnel traffic and support access into segmented environments (including from compromised ESXi systems).
The version that knows your environment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.