SprySOCKS Backdoor Expands From Linux to Windows
ID: ca181ed0-b648-5649-a8bd-45c8f1bd237b
STIX ID: report--ca181ed0-b648-5649-a8bd-45c8f1bd237b
Feed Name: Infosecurity Magazine (News)
Threat Score
**ESET analysis found Windows variants of the SprySOCKS backdoor used by FishMonger (Earth Lusca/Aquatic Panda), including a kernel-mode rootkit (WIN_DRV) that hides files, processes, registry keys and network connections, plus a feature-rich backdoor (WIN_PLUS); active targeting of government organizations across Honduras, Taiwan, Thailand and Pakistan was observed, and persistence techniques include DLL side‑loading and potential UEFI bootkit implantation.**
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
