logo

China-Linked SprySOCKS Backdoor Expands to Windows with Driver-Based Stealth

ID: f20ae93b-a364-571a-9000-353bf3ffb11b

STIX ID: report--f20ae93b-a364-571a-9000-353bf3ffb11b

Feed Name: The Hacker News

Threat Score
88/100

Date Published: 2026-06-16

Date Updated: 2026-06-16

Author: [email protected] (The Hacker News)

...
...

ESET researchers identified two Windows variants of the SprySOCKS backdoor (WIN_DRV and WIN_PLUS) that extend a previously Linux-only implant with Windows-native loading techniques, kernel drivers for stealth and TCP/UDP/WebSocket C2 channels; these variants have been tied to the China-linked FishMonger/Earth Lusca cluster and were observed in deployments against government organizations during 2023–2024.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.