www.welivesecurity.com FishMonger Expands SprySOCKS Malware to Windows with Kernel-Level Stealth
Article Content
- •FishMonger has developed Windows variants of the SprySOCKS backdoor, targeting government entities.
- •The WIN_DRV variant utilizes kernel drivers for stealth, hiding processes and network activity.
- •ESET telemetry indicates the malware was active in 2023 and 2024, with potential UEFI bootkit involvement.
ESET researchers have identified two new Windows variants of the SprySOCKS backdoor, previously exclusive to Linux, attributed to the Chinese cyberespionage group FishMonger. The variants, labeled WIN_DRV and WIN_PLUS, were active between 2023 and 2024 and targeted government organizations in Honduras, Taiwan, Thailand, and Pakistan. The WIN_DRV variant employs kernel drivers for advanced stealth, allowing it to conceal its presence by hiding network connections, processes, and files. Both variants support over 30 command-and-control (C&C) commands and can communicate via TCP, UDP, and WebSocket protocols. There are indications that some attacks may involve a UEFI bootkit component, potentially exploiting CVE-2023-24932. The discovery highlights the evolving capabilities of FishMonger, which has previously targeted various sectors, including education and government. ESET advises organizations to monitor for signs of these new threats.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (12)
Following this threat?
Track Earth Lusca, BlackLotus and CVE-2023-24932 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Authentication Bypass in Rejetto HFS Exploited Within 24 Hours Anthropic's Mythos model identified a critical authentication bypass in Rejetto HTTP File Server (HFS), tracked as CVE-2026-61500, allowing remote code execution. Discovered by Horizon3 researcher Zach Hanley, the flaw was revealed on September 27, 2026, and exploitation began within 24 hours, with attacks traced to…
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited In late September 2026, two critical zero-day vulnerabilities (CVE-2026-88771 and CVE-2026-88772) in Citrix NetScaler ADC and Gateway were actively exploited, allowing remote code execution. The Cybersecurity and Infrastructure Security Agency (CISA) added these CVEs to its Known Exploited Vulnerabilities catalog on…