FishMonger Expands SprySOCKS Malware to Windows with Kernel-Level Stealth
ID: 9023e5f0-059c-52ea-9ac3-c770cb5d23e4
STIX ID: report--9023e5f0-059c-52ea-9ac3-c770cb5d23e4
Feed Name: ThreatCluster
Threat Score
ESET identified two Windows variants of the SprySOCKS backdoor attributed to the Chinese APT FishMonger: WIN_DRV (which uses kernel drivers to hide processes, files, and network activity) and WIN_PLUS. Both support 30+ C2 commands over TCP/UDP/WebSocket, were active in 2023–2024 against government targets in Honduras, Taiwan, Thailand, and Pakistan, and may be linked to a UEFI bootkit exploiting CVE-2023-24932.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
