Tool
revsocks
- First Reported
- Jul 16, 2026
- Latest Reported
- Jul 16, 2026
Reported Context (1)
- rundll32.exe and comsvcs.dll. For covert command-and-control, the operator ran a reverse-SOCKS proxy (revsocks) to an external IP on port 443 and additionally exposed local RDP externally through a renamed New Spirals Ransomware Used in Double-Extortion Attack on South Asian IT Company
Malware (1)
MITRE ATT&CK (22)
Vendors (1)
Products (16)
Tools (5)
Industries (1)
Note: Related entities, including threat actors, malware, CVEs, MITRE ATT&CK techniques, vendors, products, tools, countries, and industries, are shown when they appear in the same reporting. Their presence does not necessarily mean they were targeted, compromised, vulnerable, responsible for the activity, or directly involved in the incident.