New Windows Variants of SprySOCKS Malware Target Government Entities
ID: 9221558b-12c3-53b7-a5d4-5226b43c8a38
STIX ID: report--9221558b-12c3-53b7-a5d4-5226b43c8a38
Feed Name: ThreatCluster
Threat Score
ESET researchers identified two Windows variants of the SprySOCKS backdoor (WIN_DRV and WIN_PLUS) attributed to the FishMonger APT targeting government organizations in Honduras, Taiwan, Thailand, and Pakistan; WIN_DRV employs kernel-level stealth to hide processes, files, and network connections, both variants support over 30 C2 commands, and limited evidence suggests some attack scenarios may include a UEFI bootkit exploiting CVE-2023-24932.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
