Currently viewing ATT&CK v7.2 which was live between July 8, 2020 and October 26, 2020. Learn more about the versioning system or see the live site.
Register to stream the next session of ATT&CKcon Power Hour November 12

Socksbot

Socksbot is a backdoor that abuses Socket Secure (SOCKS) proxies. [1]

ID: S0273
Type: MALWARE
Platforms: Windows
Version: 1.1
Created: 17 October 2018
Last Modified: 30 March 2020

Techniques Used

Domain ID Name Use
Enterprise T1059 .001 Command and Scripting Interpreter: PowerShell

Socksbot can write and execute PowerShell scripts.[1]

Enterprise T1057 Process Discovery

Socksbot can list all running processes.[1]

Enterprise T1055 .001 Process Injection: Dynamic-link Library Injection

Socksbot creates a suspended svchost process and injects its DLL into it.[1]

Enterprise T1090 Proxy

Socksbot can start SOCKS proxy threads.[1]

Enterprise T1113 Screen Capture

Socksbot can take screenshots.[1]

References