SprySOCKS Gains a Hidden Windows Control Channel

SprySOCKS is no longer just a Linux backdoor. Its Windows port changes the hunt from looking for an obvious listening port to looking for traffic that gets quietly rerouted into a hidden backdoor, and the driver layer can also hide the malware’s own traces from normal host checks. ESET says it found two previously undocumented Windows variants, WIN_DRV and WIN_PLUS, in intrusions against government organizations in Taiwan, Thailand, Pakistan, and Honduras during 2023 and 2024. WIN_DRV adds kernel-driver stealth that hides processes, files, registry keys, and network connections, while both variants support more than 30 commands over TCP, UDP, and WebSocket. The forward risk is broader than one family. A backdoor that can take commands through diverted traffic and erase its own visible footprint weakens port scans, netstat-style checks, and process-based hunts in Windows espionage cases.

Part of the PlainSec briefing for 2026-06-16

Sources