logo

Windows version of SprySOCKS Linux malware used to attack govt orgs

ID: 3399f9a8-c22a-566f-807b-163c3748a564

STIX ID: report--3399f9a8-c22a-566f-807b-163c3748a564

Feed Name: Bleeping Computer

Threat Score
85/100

Date Published: 2026-06-16

Date Updated: 2026-06-16

Author: Bill Toulas

...
...

ESET researchers report Windows variants of the SprySOCKS malware used by the Earth Lusca (FishMonger) threat actor in 2023–2024 against government organizations in Taiwan, Thailand, Pakistan, and Honduras. Two variants were observed: WIN_DRV, which loads a kernel driver (RawWNPF) via a signed DriverLoader to provide rootkit-like hiding of processes, files, registry entries and network connections plus TCP traffic diversion to conceal the backdoor’s real listening port; and WIN_PLUS, a more limited backdoor. Both support TCP/UDP/WebSocket, >30 C2 commands, file and process management, SOCKS proxying, keylogging, and persistence via scheduled tasks/IFEO or as a print processor; ESET also notes possible UEFI bootkit activity tied to CVE-2023-24932 and provides IoCs and technical analysis to aid detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.