Analysis by: Leidryn Saludez

ALIASES:

a variant of WinGo/HackTool.Proxy.M trojan (NOD32)

 PLATFORM:

Windows

 OVERALL RISK RATING:
 DAMAGE POTENTIAL:
 DISTRIBUTION POTENTIAL:
 REPORTED INFECTION:
 SYSTEM IMPACT RATING:
 INFORMATION EXPOSURE:

  • Threat Type: Hacking Tool

  • Destructiveness: No

  • Encrypted: No

  • In the wild: Yes

  OVERVIEW

This Hacking Tool arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.

  TECHNICAL DETAILS

File Size: 8,071,680 bytes
File Type: DLL
Memory Resident: No
Initial Samples Received Date: 02 Mar 2026

Arrival Details

This Hacking Tool arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.

Other Details

This Hacking Tool does the following:

  • It accepts the following flags for the listen subcommand:
    • --on or -o → Specifies the listen address for relay connections (default: port 4080)
    • --proxy-address or -p → Specifies the local SOCKS5 proxy address (default: {BLOCKED}.{BLOCKED}.{BLOCKED}.{BLOCKED}:1080 )
    • --abort-on-disconnect → Terminates the listener when a relay disconnects
    • --key or -k → Specifies the base64-encoded connection key for mutual authentication
    • --insecure → Disables mutual TLS certificate validation
    • --no-color → Disables colored terminal output
  • It accepts the following flags for the relay subcommand:
    • --timeout → Specifies the connection timeout (default: 5 seconds)
    • --reconnect-after → Enables automatic reconnection with a configurable delay after disconnection
    • --key or -k → Specifies the base64-encoded connection key for mutual authentication
    • --insecure → Disables mutual TLS certificate validation
  • It implements a reverse SOCKS5 proxy that inverts the typical proxy direction, routing traffic from the attacker through the compromised host's network.
  • In listen mode, binds a TLS listener on a configurable address and starts a local SOCKS5 proxy server that bridges local SOCKS5 client connections to the relay via yamux streams.
  • In relay mode, initiates an outbound TLS connection to the attacker's listener that appears as standard TLS traffic from the victim network, then serves SOCKS5 requests received through yamux streams.
  • It supports automatic reconnection in relay mode with a user-defined delay when the connection to the listener is lost.
  • It dedicates the first accepted yamux stream as an error notification channel for propagating error messages back to the listener.

It accepts the following parameters:

  • listen → Starts a TLS listener to accept relay connections and runs a local SOCKS5 proxy server
  • relay → Connects back to a listener through the victim's network to establish a reverse proxy tunnel
  • generate → Generates a new random connection key
  • version → Displays the current version string

  SOLUTION

Minimum Scan Engine: 9.800
SSAPI PATTERN File: 2.923.00
SSAPI PATTERN Date: 05 Mar 2026

Step 1

Trend Micro Predictive Machine Learning detects and blocks malware at the first sign of its existence, before it executes on your system. When enabled, your Trend Micro product detects this malware under the following machine learning name:

    •  Troj.Win32.TRX.XXPE50FFF102

Step 2

Before doing any scans, Windows 7, Windows 8, Windows 8.1, and Windows 10 users must disable System Restore to allow full scanning of their computers.

Step 3

Scan your computer with your Trend Micro product to delete files detected as HackTool.Win64.RESOCKS.A. If the detected files have already been cleaned, deleted, or quarantined by your Trend Micro product, no further step is required. You may opt to simply delete the quarantined files. Please check the following Trend Micro Support pages for more information:


Did this description help? Tell us how we did.