China-Linked FishMonger Ports SprySOCKS to Windows With Kernel-Level Stealth and UEFI Bootkit Hints
ID: 37d05686-8a7d-52c6-8fd7-cee685ee0fee
STIX ID: report--37d05686-8a7d-52c6-8fd7-cee685ee0fee
Feed Name: Security Affairs
ESET researchers uncovered two Windows variants of the SprySOCKS backdoor (WIN_DRV and WIN_PLUS) used by China-linked FishMonger, featuring kernel drivers that hide network connections and system artifacts, Print Spooler-based loaders, a full command set (remote shell, file transfer, SOCKS proxy), and suspected use against government targets across multiple countries between 2023–2024; limited evidence also suggests a possible UEFI bootkit for persistent, reinstall-resistant compromise.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
