www.welivesecurity.com FishMonger Expands SprySOCKS Malware to Windows with Kernel-Level Stealth
Article Content
- •FishMonger has developed Windows variants of the SprySOCKS backdoor, targeting government entities.
- •The WIN_DRV variant utilizes kernel drivers for stealth, hiding processes and network activity.
- •ESET telemetry indicates the malware was active in 2023 and 2024, with potential UEFI bootkit involvement.
ESET researchers have identified two new Windows variants of the SprySOCKS backdoor, previously exclusive to Linux, attributed to the Chinese cyberespionage group FishMonger. The variants, labeled WIN_DRV and WIN_PLUS, were active between 2023 and 2024 and targeted government organizations in Honduras, Taiwan, Thailand, and Pakistan. The WIN_DRV variant employs kernel drivers for advanced stealth, allowing it to conceal its presence by hiding network connections, processes, and files. Both variants support over 30 command-and-control (C&C) commands and can communicate via TCP, UDP, and WebSocket protocols. There are indications that some attacks may involve a UEFI bootkit component, potentially exploiting CVE-2023-24932. The discovery highlights the evolving capabilities of FishMonger, which has previously targeted various sectors, including education and government. ESET advises organizations to monitor for signs of these new threats.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (12)
Following this threat?
Track Earth Lusca, BlackLotus and CVE-2023-24932 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Citrix NetScaler Critical Vulnerabilities Exploited: Urgent Patching Required Citrix NetScaler ADC and Gateway products are affected by critical vulnerabilities CVE-2026-88771 and CVE-2026-88772, both assigned a CVSS score of 9.5. The Cybersecurity and Infrastructure Security Agency (CISA) added these CVEs to its Known Exploited Vulnerabilities catalog on September 27, 2026, and mandated…
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited Citrix disclosed two critical zero-day vulnerabilities, CVE-2026-88771 and CVE-2026-88772, affecting NetScaler ADC and Gateway systems, which are being actively exploited. Both vulnerabilities have a CVSS score of 9.5 and allow unauthenticated attackers to execute arbitrary commands remotely. CVE-2026-88771 arises…