China-Linked SprySOCKS Backdoor Expands to Windows with Driver-Based Stealth
ID: f20ae93b-a364-571a-9000-353bf3ffb11b
STIX ID: report--f20ae93b-a364-571a-9000-353bf3ffb11b
Feed Name: The Hacker News
Threat Score
ESET researchers identified two Windows variants of the SprySOCKS backdoor (WIN_DRV and WIN_PLUS) that extend a previously Linux-only implant with Windows-native loading techniques, kernel drivers for stealth and TCP/UDP/WebSocket C2 channels; these variants have been tied to the China-linked FishMonger/Earth Lusca cluster and were observed in deployments against government organizations during 2023–2024.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
