logo

SprySOCKS Backdoor Expands From Linux to Windows

ID: ca181ed0-b648-5649-a8bd-45c8f1bd237b

STIX ID: report--ca181ed0-b648-5649-a8bd-45c8f1bd237b

Feed Name: Infosecurity Magazine (News)

Threat Score
85/100

Date Published: 2026-06-16

Date Updated: 2026-06-16

...
...

**ESET analysis found Windows variants of the SprySOCKS backdoor used by FishMonger (Earth Lusca/Aquatic Panda), including a kernel-mode rootkit (WIN_DRV) that hides files, processes, registry keys and network connections, plus a feature-rich backdoor (WIN_PLUS); active targeting of government organizations across Honduras, Taiwan, Thailand and Pakistan was observed, and persistence techniques include DLL side‑loading and potential UEFI bootkit implantation.**

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.