logo

SprySOCKS Windows Backdoor Uses Kernel Driver to Hide Processes, Files, and Network Traffic

ID: 9b174e04-624a-5cab-ac3f-b98adb62347a

STIX ID: report--9b174e04-624a-5cab-ac3f-b98adb62347a

Feed Name: GBHackers

Threat Score
90/100

Date Published: 2026-06-17

Date Updated: 2026-06-17

Author: Mayura Kathir

...
...

**Executive summary:** ESET researchers identified two Windows ports of the Linux SprySOCKS backdoor (WIN_DRV and WIN_PLUS) attributed to the FishMonger APT; WIN_DRV includes a signed DriverLoader and a RawWNPF kernel-mode rootkit that hides processes, files, registry keys and network ports and can redirect TCP flows to a hidden listener, while WIN_PLUS uses a print-processor-style loader and svchost injection for persistence; telemetry links activity in 2023–2024 targeting government entities in Honduras, Taiwan, Thailand, and Pakistan, and the report provides C2 details, hardcoded crypto keys, over 30 backdoor commands, and a set of IOCs for hunting and response.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.