logo

New Windows Variants of SprySOCKS Malware Target Government Entities

ID: 9221558b-12c3-53b7-a5d4-5226b43c8a38

STIX ID: report--9221558b-12c3-53b7-a5d4-5226b43c8a38

Feed Name: ThreatCluster

Threat Score
88/100

Date Published: 2026-06-16

Date Updated: 2026-06-16

...
...

ESET researchers identified two Windows variants of the SprySOCKS backdoor (WIN_DRV and WIN_PLUS) attributed to the FishMonger APT targeting government organizations in Honduras, Taiwan, Thailand, and Pakistan; WIN_DRV employs kernel-level stealth to hide processes, files, and network connections, both variants support over 30 C2 commands, and limited evidence suggests some attack scenarios may include a UEFI bootkit exploiting CVE-2023-24932.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.