logo

FishMonger Expands SprySOCKS Malware to Windows with Kernel-Level Stealth

ID: 9023e5f0-059c-52ea-9ac3-c770cb5d23e4

STIX ID: report--9023e5f0-059c-52ea-9ac3-c770cb5d23e4

Feed Name: ThreatCluster

Threat Score
90/100

Date Published: 2026-06-16

Date Updated: 2026-06-22

...
...

ESET identified two Windows variants of the SprySOCKS backdoor attributed to the Chinese APT FishMonger: WIN_DRV (which uses kernel drivers to hide processes, files, and network activity) and WIN_PLUS. Both support 30+ C2 commands over TCP/UDP/WebSocket, were active in 2023–2024 against government targets in Honduras, Taiwan, Thailand, and Pakistan, and may be linked to a UEFI bootkit exploiting CVE-2023-24932.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.