logo

China-Linked FishMonger Ports SprySOCKS to Windows With Kernel-Level Stealth and UEFI Bootkit Hints

ID: 37d05686-8a7d-52c6-8fd7-cee685ee0fee

STIX ID: report--37d05686-8a7d-52c6-8fd7-cee685ee0fee

Feed Name: Security Affairs

Threat Score
85/100

Date Published: 2026-06-17

Date Updated: 2026-06-17

Author: Pierluigi Paganini

...
...

ESET researchers uncovered two Windows variants of the SprySOCKS backdoor (WIN_DRV and WIN_PLUS) used by China-linked FishMonger, featuring kernel drivers that hide network connections and system artifacts, Print Spooler-based loaders, a full command set (remote shell, file transfer, SOCKS proxy), and suspected use against government targets across multiple countries between 2023–2024; limited evidence also suggests a possible UEFI bootkit for persistent, reinstall-resistant compromise.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.