logo

FishMonger Expands SprySOCKS Malware to Windows, Targeting Government Entities

ID: 17427de6-3a6f-5773-b3b9-c1af7e533060

STIX ID: report--17427de6-3a6f-5773-b3b9-c1af7e533060

Feed Name: ThreatCluster

Threat Score
85/100

Date Published: 2026-06-16

Date Updated: 2026-06-21

...
...

ESET researchers identified two Windows variants of the SprySOCKS backdoor (WIN_DRV and WIN_PLUS) attributed to the FishMonger APT; WIN_DRV employs kernel-level techniques to hide processes, files, and network connections, both variants support 30+ C2 commands, and limited evidence suggests some attacks may have used a UEFI bootkit exploiting CVE-2023-24932. Activity was observed against government organizations in Honduras, Taiwan, Thailand, and Pakistan between 2023–2024.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.