Socksbot is a backdoor that abuses Socket Secure (SOCKS) proxies. [1]

ID: S0273
Platforms: Windows
Version: 1.1
Created: 17 October 2018
Last Modified: 30 March 2020

Techniques Used

Domain ID Name Use
Enterprise T1059 .001 Command and Scripting Interpreter: PowerShell

Socksbot can write and execute PowerShell scripts.[1]

Enterprise T1057 Process Discovery

Socksbot can list all running processes.[1]

Enterprise T1055 .001 Process Injection: Dynamic-link Library Injection

Socksbot creates a suspended svchost process and injects its DLL into it.[1]

Enterprise T1090 Proxy

Socksbot can start SOCKS proxy threads.[1]

Enterprise T1113 Screen Capture

Socksbot can take screenshots.[1]