logo

FishMonger’s arsenal upgraded: SprySOCKS for Windows

ID: 995eaa4c-476a-5b74-841a-54712699b99d

STIX ID: report--995eaa4c-476a-5b74-841a-54712699b99d

Feed Name: WeLiveSecurity (ESET Research)

Threat Score
88/100

Date Published: 2026-06-16

Date Updated: 2026-06-17

...
...

**ESET discovered two previously undocumented Windows variants of the SprySOCKS backdoor (WIN_DRV and WIN_PLUS) used by the FishMonger APT, describing loader chains, encrypted payloads, a kernel rootkit (RawWNPF) that hides files/processes/network connections and diverts TCP traffic, support for TCP/UDP/WebSocket C2 channels with >30 commands, observed victim telemetry across Honduras, Taiwan, Thailand and Pakistan, and provides IoCs and MITRE ATT&CK mappings.**

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.