#SprySOCKS
Arsenal de FishMonger actualizado: SprySOCKS para Windows

#Ciberseguridad #Seguridad #Tecnología #LaiaDesk
Arsenal de FishMonger actualizado: SprySOCKS para Windows
El equipo de investigación de ESET ha descubierto SprySOCKS para Windows, un backdoor de FishMonger que utiliza un kernel driver para lograr un mayor nivel de sigilo.
laiadesk.com
September 27, 2026 at 6:20 AM
#ESETresearch discovered two as-yet undocumented Windows variants of #SprySOCKS, a previously Linux-only backdoor reportedly used by #FishMonger. We attribute the new Windows variants to #FishMonger with high confidence. www.welivesecurity.com/en/eset-rese... 1/4
FishMonger’s arsenal upgraded: SprySOCKS for Windows
ESET researchers have discovered SprySOCKS for Windows, FishMonger’s backdoor weaponizing a kernel driver for advanced stealthiness.
www.welivesecurity.com
June 16, 2026 at 9:38 AM
Windows version of SprySOCKS Linux malware used to attack govt orgs #cybersecurity #hacking #news #infosec #security #technology #privacy
Windows version of SprySOCKS Linux malware used to attack govt orgs
Windows variants for the SprySOCKS Linux malware have been used in attacks targeting government organizations in at least four countries.
www.bleepingcomputer.com
June 16, 2026 at 9:11 AM
SprySOCKS Windows Variant Abuses Kernel Drivers to Evade Detection #cybersecurity #hacking #news #infosec #security #technology #privacy
SprySOCKS Windows Variant Uses Kernel Drivers to Evade Detection
FishMonger, a China-nexus threat group, has deployed an undocumented version of the Linux backdoor against government targets in several countries.
www.darkreading.com
June 17, 2026 at 9:49 PM
China-Linked SprySOCKS Backdoor Expands to Windows with Driver-Based Stealth

Cybersecurity researchers have flagged two previously undocumented Windows variants of what was believed to be a Linux-only backdoor called SprySOCKS.

"The Windows variants discovered are internally mar…
#hackernews #news
China-Linked SprySOCKS Backdoor Expands to Windows with Driver-Based Stealth
Cybersecurity researchers have flagged two previously undocumented Windows variants of what was believed to be a Linux-only backdoor called SprySOCKS. "The Windows variants discovered are internally marked as WIN_DRV and WIN_PLUS," ESET said in a report shared with The Hacker News. "Both come with a hard-coded C&C [command-and-control] configuration and support communication over TCP, UDP,
thehackernews.com
June 17, 2026 at 1:39 AM
FishMonger hackers adapt SprySOCKS backdoor for Windows, expanding their cyberespionage reach. #CyberSecurity #FishMonger #SprySOCKS #Windows #APT #ThreatActors #InfoSec thedailytechfeed.com/fishmonger-h...
June 17, 2026 at 2:09 PM
🪟 LinuxだけじゃなかったWindows版まで!

中国系APT「Earth Lusca」が開発したバックドア「SprySOCKS」のWindows版をESETが発見。台湾・タイ・パキスタン・ホンジュラスの政府機関が標的に——静かに、しかし着実に攻撃範囲を広げている。

詳細はこちら👇
https://www.ebisuda.net/tech/2026/06/16/sprysockswindowsaptearth-lusca4-windows-version-of-sprysocks-linux-malware-used/

#TechNews #Windows
June 16, 2026 at 11:50 AM
Windows variants of SprySOCKS backdoor linked to China-backed Earth Lusca reveal advanced stealth tactics in cyber espionage. #CyberSecurity #SprySOCKS #EarthLusca #Malware thedailytechfeed.com/china-linked...
June 16, 2026 at 10:02 AM
Windows version of SprySOCKS Linux malware used to attack govt orgs

Windows variants for the SprySOCKS Linux malware have been used in attacks targeting government organizations in at least four countries. [...]
#hackernews #news
Windows version of SprySOCKS Linux malware used to attack govt orgs
Windows variants for the SprySOCKS Linux malware have been used in attacks targeting government organizations in at least four countries. [...]
www.bleepingcomputer.com
June 17, 2026 at 1:07 AM
Windows version of SprySOCKS Linux malware used to attack govt orgs
www.bleepingcomputer.com/news/securit...
Windows version of SprySOCKS Linux malware used to attack govt orgs
Windows variants for the SprySOCKS Linux malware have been used in attacks targeting government organizations in at least four countries.
www.bleepingcomputer.com
June 17, 2026 at 11:56 AM
Earth Lusca expands its arsenal with SprySOCKS Linux malware
Earth Lusca expands its arsenal with SprySOCKS Linux malware
China-linked threat actor Earth Lusca used a new Linux malware dubbed SprySOCKS in a recent cyber espionage campaign.
securityaffairs.com
September 19, 2023 at 8:03 AM
IoCs available in our GitHub repo:
https://
github.com/eset/malware-i
oc/tree/master/SprySOCKS
…  
Read the full analysis on WeLiveSecurity: 
https://
welivesecurity.com/en/eset-resear
ch/fishmongers-arsenal-upgraded-sp…

— from @ESETresearch (https://x.com/ESETresearch/status/2066817548750905837)
June 16, 2026 at 9:51 AM
ESET researchers found two Windows variants of SprySOCKS, a previously Linux-only backdoor reportedly used by FishMonger. ESET telemetry shows activity between 2023 & 2024, primarily targeting government organizations in Honduras, Taiwan, Thailand & Pakistan. www.welivesecurity.com/en/eset-rese...
June 17, 2026 at 10:22 AM
IoCs available in our GitHub repo: github.com/eset/malware... Read the full analysis on WeLiveSecurity: welivesecurity.com/en/eset-rese... 4/4
malware-ioc/sprysocks at master · eset/malware-ioc
Indicators of Compromises (IOC) of our various investigations - eset/malware-ioc
github.com
June 17, 2026 at 7:15 AM
ESET found Windows SprySOCKS backdoor variants used against government orgs in Taiwan, Thailand, Pakistan, and Honduras, with high-confidence attribution to Earth Lusca and possible ties to CVE-2023-24932. #Taiwan #EarthLusca #SprySOCKS
Windows version of SprySOCKS Linux malware used to attack govt orgs
ESET found Windows variants of the SprySOCKS backdoor used in attacks against government organizations in Taiwan, Thailand, Pakistan, and Honduras, and attributed the activity to Earth Lusca. The malware adds kernel-level stealth, multiple persistence methods, and TCP traffic diversion, with possible links to a UEFI bootkit component tied to CVE-2023-24932. #SprySOCKS #EarthLusca #FishMonger #AquaticPanda #RedDev10 #TAG22 #CVE202324932 #BlackLotus
www.hendryadrian.com
June 16, 2026 at 10:00 AM
🚨 El backdoor SprySOCKS (grupo Earth Lusca) salta de Linux a Windows con 2 variantes nuevas: una se oculta con un kernel driver, otra abusa del Print Spooler. Posible bootkit UEFI (CVE-2023-24932). Parchea y vigila. 🛡️

Leer en The Hacker News →

#Ciberseguridad
June 16, 2026 at 4:06 PM
SprySOCKS Linuxマルウェアのウィンドウズ版、政府機関への攻撃に使用

SprySOCKS Linuxマルウェアのウィンドウズ版が、少なくとも4か国の政府機関を標的とした攻撃に使用されていることが明らかになりました。 SprySOCKSはこれまで、中国の脅威グループ「Earth Lusca」と関連付けられており、同グループは外交・技術・通信分野を担う政府機関への攻撃にこのマルウェアを使用...
SprySOCKS Linuxマルウェアのウィンドウズ版、政府機関への攻撃に使用
SprySOCKS Linuxマルウェアのウィンドウズ版が、少なくとも4か国の政府機関を標的とした攻撃に使用されていることが明らかになりました。 SprySOCKSはこれまで、中国の脅威グループ「Earth Lusca」と関連付けられており、同グループは外交・技術・通信分野を担う政府機関への攻撃にこのマルウェアを使用
blackhatnews.tokyo
June 16, 2026 at 9:15 AM
China-Linked SprySOCKS Backdoor Expands to Windows with Driver-Based Stealth #cybersecurity #hacking #news #infosec #security #technology #privacy thehackernews.com/20...
June 16, 2026 at 2:18 PM
Earth Lusca, a China-linked group, is using a stealthy #Linux backdoor called SprySOCKS to target government entities worldwide.
thehackernews.com/2023/09/eart...
#cybersecurity #hacking #technology #tech
Earth Lusca's New SprySOCKS Linux Backdoor Targets Government Entities
Earth Lusca, a China-linked group, is using a stealthy Linux backdoor called SprySOCKS to target government entities worldwide.
thehackernews.com
September 19, 2023 at 4:10 PM
FishMonger Hackers Expands SprySOCKS Backdoor From Linux to Windows With Advanced Stealth Features
FishMonger Hackers Expands SprySOCKS Backdoor From Linux to Windows With Advanced Stealth Features
A well-known Chinese cyberespionage group has taken a major step forward in its hacking capabilities. The threat actor, tracked as FishMonger, has brought its SprySOCKS backdoor to Windows for the first time, after years of deploying it exclusively on Linux. This upgrade signals the group is broadening its reach and is now capable of targeting a much wider range of victims around the world. SprySOCKS first appeared in September 2023, when Trend Micro documented a Linux variant actively used in espionage campaigns. The backdoor was built on top of an open-source Windows remote access tool called Trochilus, with enough modifications to be treated as a distinct, purpose-built threat. At that time, it was mainly linked to attacks against government organizations across Asia. Analysts at WeLiveSecurity identified two previously undocumented Windows variants of SprySOCKS, tracked internally as WIN_DRV and WIN_PLUS. According to Welivesecurity report shared with Cyber Security News (CSN), ESET telemetry shows confirmed activity between 2023 and 2024, with victims in Honduras, Taiwan, Thailand, and Pakistan, mostly government entities. Initial samples were uploaded to VirusTotal in April 2024 under the archive name klelam00007.zip. FishMonger is believed to be operated by a Chinese contractor named I-SOON, falling under the broader Winnti Group umbrella. Contents of klelam00007.zip (Source – Welivesecurity) The group previously targeted universities in Hong Kong during 2019 civil protests and is known for conducting watering-hole attacks. Their toolkit includes ShadowPad, Spyder, Cobalt Strike, FunnySwitch, and the BIOPASS RAT, and expanding SprySOCKS to Windows clearly shows continued investment in offensive capability. Both Windows variants implement over 30 C2 commands covering system enumeration, file management, service control, and keylogging. ESET researchers also noted indications that some attacks may involve a UEFI bootkit component, possibly exploiting CVE-2023-24932, which could allow the malware to survive a complete operating system reinstall. FishMonger Hackers Expands SprySOCKS Backdoor The WIN_DRV variant uses a kernel driver called RawWNPF to make the backdoor nearly invisible on a compromised system. This driver hides the malware’s network connections, processes, files, and registry keys from standard monitoring tools. Even netstat.exe will not show active backdoor connections because the driver intercepts Windows Filtering Platform calls and strips those entries from any output. To load the kernel driver without triggering Windows security checks, the attackers used a leaked code-signing certificate from the PastDSE project on GitHub. Version type and number hardcoded in WIN_DRV (left) and WIN_PLUS (right) Windows SprySOCKS backdoor variants (Source – Welivesecurity) Once active, the driver performs TCP traffic diversion, letting attackers send commands through any open TCP port without knowing the exact listening port. This makes it very difficult for network defenders to trace the real destination of suspicious traffic. The WIN_PLUS variant achieves persistence through DLL side-loading , scheduled tasks, and print processor registry abuse. Both variants decrypt payloads using 128-bit AES with the hardcoded key uXQLESMXGaRMs6BL and inject the backdoor into a svchost.exe process via process doppelganging. Chinese-language debug paths in the binaries confirm development in China, with strings suggesting the project was underway as early as April 2023. Backdoor Capabilities and C2 Communication Both SprySOCKS variants communicate with their C2 server over TCP, UDP, and WebSocket. The WIN_PLUS version had a hardcoded C2 address of 207.148.78[.]36, operating across all three channels on ports 443, 53, and 80. The backdoor adds a Windows firewall rule allowing inbound traffic on TCP port 53781, with infrastructure overlapping a delivery server at 207.148.75[.]122 seen in a June 2023 campaign. Execution chain of the SprySOCKS WIN_DRV variant (Source – Welivesecurity) The backdoor supports keylogging, clipboard capture, file transfer, SOCKS proxy, and remote shell via cmd.exe. Keylogging activates only when a specific INI file exists at %appdata%\Microsoft\Vault\lgf.dat with the key value set to 1, and logged data is saved to lg.dat using single-byte XOR with key 0x44. Given possible UEFI bootkit involvement, ESET advises organizations to closely monitor FishMonger activity. Public-facing servers must be fully patched, as the group typically exploits N-day vulnerabilities for initial access. Watching for unusual scheduled tasks, suspicious print processor registry entries, and unexpected DLL files in the Windows Fonts folder can help defenders catch this threat before major damage occurs. Indicators of Compromise (IoCs):- Type Indicator Description SHA1 FFC3AA7909D4E72C360D65A1F45260DFFE5C99B7 ApphostRagistreationVerifier.exe (legitimate signed executable used for DLL side-loading) SHA256 955BFC3DCC867256F9F46A606DEB0779FA3416D8 KX1B5206BDC1743DD.dat (Win64/SprySOCKS.AEncSpryDrvdriv) SHA256 44DC4A08C5EB0972C8E18B0E01284E06F09006BB bthcam.sys (Win64/Agent.ESBSpryDrvdriv) SHA256 AB87B29B6F79487C75CA08D102E79001E536F083 KW1B5206BDC1743FP.dat (Win64/SprySOCKS.AEncSpryRawdriv) SHA256 6490B8E4AADE25A3EE2DA9A47F312DB2122470BC X1B5206BDC1743DD.dat (Win64/SprySOCKS.AEnc container, WIN_DRV variant) SHA256 E7484C24B88A1A2407A8F09D734F9A993670285B klelam00007.zip (Win64/Agent.CXZ / SprySOCKS.ABARunner.KS) SHA256 621D1952839BE4B0A1B0E66E87BCE5062CA368ED tpsvcloc.dll (Win64/Agent.CXZ SpryLoad loader) SHA256 2457EED2AB28E37741F10914EF929DAD2C8079D4 VSPMsg.dll (Win64/Agent.CXZ First-stage loader for WIN_PLUS variant) SHA256 D2C706B1EAF662BF0CE124B5032F73ED84BDA24A N/A (Win64/SprySOCKS.AWin variant SpryBack) SHA256 5F3B87CEF56683D9A9E19186E0FD0D8019B559C4 N/A (Win64/Agent.CXZ SpryLoad loader) SHA256 C793CA31E3F6628B5C8986146953BF66232E9A30 config.dat (Win64/SprySOCKS.AEnc container, WIN_PLUS variant) SHA256 037DB2445F3D72388CB2CF8510563148E5A184BE N/A (BAT Runner.KS for WIN_PLUS variant) IP Address 207.148.78[.]36 C2 server (IRT-CHOO-PALLC-AP, MITRE ATT&CK) IP Address 207.148.75[.]122 SprySOCKS delivery server, June 2023 (same /20 subnet as C2) File Name klelam00007.zip Initial delivery archive uploaded to VirusTotal File Name klelam00007.bat Batch script responsible for persistence setup (WIN_DRV variant) File Name affair-build.bat Cleanup batch script executed by SprySOCKS loader File Name tpsvcloc.dll SprySOCKS backdoor loader DLL File Name tpsvc.dll Legitimate signed library loading tpsvcloc.dll File Name X1B5206BDC1743DD.dat Encrypted container with SprySOCKS backdoor and next-stage files File Name KX1B5206BDC1743DD.dat Encrypted DriverLoader kernel driver File Name KW1B5206BDC1743FP.dat Encrypted RawWNPF kernel driver File Name fsdiskbit.sys Dropped DriverLoader kernel driver on disk File Name VSPMsg.dll First-stage loader DLL for WIN_PLUS variant File Name config.dat Encrypted container for WIN_PLUS variant (spool\drivers\color) File Name ApphostRagistreationVerifier.exe Renamed legitimate executable used in scheduled task for persistence Registry Key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\vds.exe\debugger Persistence registry key used by WIN_DRV loader Registry Key HKLM\SYSTEM\ControlSet001\Control\Print\Environments\Windows x64\Print Processors\VSPMsg Persistence via print processor (WIN_PLUS variant) Note:   IP addresses and domains are intentionally defanged (e.g.,  [.] ) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM . Follow us on  Google News ,  LinkedIn , and  X  to Get More Instant Updates ,  Set CSN as a Preferred Source in Google . The post FishMonger Hackers Expands SprySOCKS Backdoor From Linux to Windows With Advanced Stealth Features appeared first on Cyber Security News .
cybersecuritynews.com
June 17, 2026 at 1:18 PM
ESET Research: China-aligned FishMonger updates its arsenal, targets governments in Asia and Latin America

ESET researchers have discovered two as-yet undocumented Windows variants (WIN_DRV and WIN_PLUS) of SprySOCKS, a previously Linux-only backdoor reportedly used by FishMonger, the group…
ESET Research: China-aligned FishMonger updates its arsenal, targets governments in Asia and Latin America
ESET researchers have discovered two as-yet undocumented Windows variants (WIN_DRV and WIN_PLUS) of SprySOCKS, a previously Linux-only backdoor reportedly used by FishMonger, the group believed to be operated by a Chinese contractor named I-SOON. While ESET initially discovered the malware samples on VirusTotal uploaded in April 2024, ESET telemetry shows real activity between 2023 and 2024, with several victims in Honduras, Taiwan, Thailand, and Pakistan, targeting mostly government organizations.
itnerd.blog
June 16, 2026 at 5:15 PM
SprySOCKS Windowsバックドア、カーネルドライバーでプロセス・ファイル・ネットワークトラフィックを隠蔽

これまでLinux専用とされていたバックドア「SprySOCKS」のWindowsバリアントが発見されました。FishMonger(別名:Earth Lusca/TAG-22)との関連が長く指摘されているこのマルウェアは、ツールセットの拡張が続いています。 内部ラベルが「WIN_DRV」と「WIN_PLUS」の2つの...
SprySOCKS Windowsバックドア、カーネルドライバーでプロセス・ファイル・ネットワークトラフィックを隠蔽
これまでLinux専用とされていたバックドア「SprySOCKS」のWindowsバリアントが発見されました。FishMonger(別名:Earth Lusca/TAG-22)との関連が長く指摘されているこのマルウェアは、ツールセットの拡張が続いています。 内部ラベルが「WIN_DRV」と「WIN_PLUS」の2つの
blackhatnews.tokyo
June 17, 2026 at 9:24 AM