FishMonger Expands SprySOCKS Malware to Windows, Targeting Government Entities

FishMonger Expands SprySOCKS Malware to Windows, Targeting Government Entities

11h ago BleepingcomputerMarkets.BusinessinsiderInfosecurity-MagazineDarkreadingwww.welivesecurity.com+1 87% similarity 75.5
Share:

Article Content

Browse articles
ThreatCluster

ESET researchers have identified two new Windows variants of the SprySOCKS backdoor, known as WIN_DRV and WIN_PLUS, attributed to the Chinese cyberespionage group FishMonger. These variants were discovered in malware samples uploaded to VirusTotal in April 2024 and show activity targeting government organizations in Honduras, Taiwan, Thailand, and Pakistan between 2023 and 2024. The WIN_DRV variant features advanced kernel-level capabilities for stealth, allowing it to hide processes, files, and network connections, while both variants support over 30 command-and-control (C&C) commands. There are indications that some attack scenarios may involve a UEFI bootkit component exploiting CVE-2023-24932, a vulnerability published on May 9, 2023. ESET's findings highlight the group's ongoing evolution and the need for heightened vigilance among targeted organizations.

Key Points: • FishMonger has developed two Windows variants of SprySOCKS, targeting government entities. • The malware employs kernel-level techniques for stealth, hiding its presence from detection tools. • Limited indications suggest potential exploitation of CVE-2023-24932 in some attack scenarios.

ThreatCluster AI

Timeline

2023-05-09
CVE-2023-24932 published
A Secure Boot vulnerability was published, potentially exploitable by malware.
Infosecurity-Magazine
2024-04-01
Malware samples uploaded to VirusTotal
Samples of SprySOCKS variants were uploaded, leading to their discovery by ESET researchers.
Markets.Businessinsider
2026-06-16
ESET reports on SprySOCKS Windows variants
ESET publishes findings on the new Windows variants of SprySOCKS, detailing their capabilities and targets.
WeLiveSecurity

Community

Browse all →