logo

FishMonger Expands SprySOCKS Malware to Windows with Kernel-Level Stealth

ID: 39ba3633-6143-5079-bf62-f8e018f4e523

STIX ID: report--39ba3633-6143-5079-bf62-f8e018f4e523

Feed Name: ThreatCluster

Threat Score
85/100

Date Published: 2026-06-16

Date Updated: 2026-06-17

...
...

ESET researchers identified two Windows variants (WIN_DRV and WIN_PLUS) of the SprySOCKS backdoor used by the FishMonger APT, active in 2023–2024 and targeting government organizations in Honduras, Taiwan, Thailand, and Pakistan. WIN_DRV leverages kernel drivers to hide processes, network connections, and files, both variants implement 30+ C2 commands over TCP/UDP/WebSocket, and there are indications some intrusions involved a UEFI bootkit potentially exploiting CVE-2023-24932; organizations are advised to monitor for indicators and signs of compromise.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.