Threats · 90 days ago
SprySOCKS is no longer just a Linux backdoor. Its Windows port changes the hunt from looking for an obvious listening port to looking for traffic that gets quietly rerouted into a hidden backdoor, and the driver layer can also hide the malware’s own traces from normal host checks.
ESET says it found two previously undocumented Windows variants, WIN_DRV and WIN_PLUS, in intrusions against government organizations in Taiwan, Thailand, Pakistan, and Honduras during 2023 and 2024. WIN_DRV adds kernel-driver stealth that hides processes, files, registry keys, and network connections, while both variants support more than 30 commands over TCP, UDP, and WebSocket.
The forward risk is broader than one family. A backdoor that can take commands through diverted traffic and erase its own visible footprint weakens port scans, netstat-style checks, and process-based hunts in Windows espionage cases.
5 sources covering this story
SprySOCKS Windows Variant Uses Kernel Drivers to Evade Detection
FishMonger, a China-nexus threat group, has deployed an undocumented version of the Linux backdoor against government targets in several countries.
China-Linked SprySOCKS Backdoor Expands to Windows with Driver-Based Stealth
ESET found two Windows SprySOCKS variants with 30+ commands, C2 over TCP, UDP, and WebSocket, and government targets in 4 countries.
SprySOCKS Backdoor Expands From Linux to Windows
China-linked SprySOCKS backdoor gains stealthy Windows variants and 30-plus C2 commands
FishMonger’s arsenal upgraded: SprySOCKS for Windows
ESET researchers have discovered SprySOCKS for Windows, FishMonger’s backdoor weaponizing a kernel driver for advanced stealthiness.
Windows version of SprySOCKS Linux malware used to attack govt orgs
Windows variants for the SprySOCKS Linux malware have been used in attacks targeting government organizations in at least four countries.
Part of the PlainSec briefing for 2026-06-16