Windows version of SprySOCKS Linux malware used to attack govt orgs
ID: 3399f9a8-c22a-566f-807b-163c3748a564
STIX ID: report--3399f9a8-c22a-566f-807b-163c3748a564
Feed Name: Bleeping Computer
ESET researchers report Windows variants of the SprySOCKS malware used by the Earth Lusca (FishMonger) threat actor in 2023–2024 against government organizations in Taiwan, Thailand, Pakistan, and Honduras. Two variants were observed: WIN_DRV, which loads a kernel driver (RawWNPF) via a signed DriverLoader to provide rootkit-like hiding of processes, files, registry entries and network connections plus TCP traffic diversion to conceal the backdoor’s real listening port; and WIN_PLUS, a more limited backdoor. Both support TCP/UDP/WebSocket, >30 C2 commands, file and process management, SOCKS proxying, keylogging, and persistence via scheduled tasks/IFEO or as a print processor; ESET also notes possible UEFI bootkit activity tied to CVE-2023-24932 and provides IoCs and technical analysis to aid detection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
