logo

FishMonger Uses TCP, UDP, and WebSocket C2 Channels in SprySOCKS Windows Attacks

ID: f1e32630-5c27-5f0e-9297-ca4ad4fe0298

STIX ID: report--f1e32630-5c27-5f0e-9297-ca4ad4fe0298

Feed Name: Cyber Press

Threat Score
90/100

Date Published: 2026-06-17

Date Updated: 2026-06-17

Author: Varshini

...
...

FishMonger (linked to I-SOON) has developed two previously undocumented Windows variants of the SprySOCKS backdoor—WIN_DRV (uses a custom kernel driver to hide activity) and WIN_PLUS (uses a print-processor loader)—with multi-protocol C2 and extensive remote-control commands; telemetry from 2023–2024 shows targeting of government organizations in Honduras, Taiwan, Thailand, and Pakistan, likely via exploitation of unpatched public-facing servers, and the report includes IOCs (SHA-1 hashes) and notes potential UEFI bootkit persistence (CVE-2023-24932).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.