ESET analysis of SprySOCKS Windows variants adds IOC-backed detection guidance
Technical Analysis
Summary
Hide ▲
Show ▼
ESET identified previously undocumented Windows variants of SprySOCKS, a backdoor attributed to FishMonger and linked to I-Soon. The WIN_DRV and WIN_PLUS variants add kernel-level stealth and retain TCP, UDP, and WebSocket command-and-control, plus 30+ espionage commands. ESET traced activity to 2023-2024 against government bodies in Honduras, Taiwan, Thailand, and Pakistan, and found signs the activity may extend into a UEFI bootkit chain.
Related Happenings
FishMonger multi-country government espionage campaign
Campaign
H score33
First: 16.06.2026 17:30
Last: 16.06.2026 17:30
Sources 1
How related:
ESET telemetry traced real activity to 2023 and 2024, mostly against government bodies in Honduras, Taiwan, Thailand and Pakistan.
About this happening:
FishMonger ran a multi-country espionage campaign against government bodies in Honduras, Taiwan, Thailand and Pakistan across 2023 and 2024. The activity point...
FishMonger multi-country government espionage campaign
CampaignHow related: ESET telemetry traced real activity to 2023 and 2024, mostly against government bodies in Honduras, Taiwan, Thailand and Pakistan.
About this happening: FishMonger ran a multi-country espionage campaign against government bodies in Honduras, Taiwan, Thailand and Pakistan across 2023 and 2024. The activity point...
SprySOCKS Windows backdoor activity against government organizations
Malware Activity
H score23
First: 16.06.2026 12:00
Last: 16.06.2026 12:00
Sources 1
How related:
Cybersecurity researchers have flagged two previously undocumented Windows variants of what was believed to be a Linux-only backdoor called SprySOCKS.
About this happening:
SprySOCKS now has documented Windows variants, WIN_DRV and WIN_PLUS, expanding a toolset first known as a Linux-only backdoor. The activity is tied to govern...
SprySOCKS Windows backdoor activity against government organizations
Malware ActivityHow related: Cybersecurity researchers have flagged two previously undocumented Windows variants of what was believed to be a Linux-only backdoor called SprySOCKS.
About this happening: SprySOCKS now has documented Windows variants, WIN_DRV and WIN_PLUS, expanding a toolset first known as a Linux-only backdoor. The activity is tied to govern...
GPU cryptomining malware using ScreenConnect and SEO poisoning
Malware Activity
H score16
First: 28.05.2026 00:31
Last: 28.05.2026 00:31
Sources 1
About this happening:
A cryptojacking malware operation is spreading through SEO-poisoned download pages and, in some cases, AI chatbot recommendations, putting high-performance Windows s...
GPU cryptomining malware using ScreenConnect and SEO poisoning
Malware ActivityAbout this happening: A cryptojacking malware operation is spreading through SEO-poisoned download pages and, in some cases, AI chatbot recommendations, putting high-performance Windows s...
Microsoft Defender zero-days exploited in attacks (multiple vulnerabilities)
Vulnerability
H score39
First: 21.05.2026 10:49
Last: 21.05.2026 10:49
Sources 1
About this happening:
Microsoft began rolling out fixes for CVE-2026-41091 and CVE-2026-45498, two actively exploited zero-days in Microsoft Defender components that affect unpatched Wi...
Microsoft Defender zero-days exploited in attacks (multiple vulnerabilities)
VulnerabilityAbout this happening: Microsoft began rolling out fixes for CVE-2026-41091 and CVE-2026-45498, two actively exploited zero-days in Microsoft Defender components that affect unpatched Wi...
Linux kernel Dirty Frag and Copy Fail 2 privilege escalation (multiple vulnerabilities)
Vulnerability
H score31
First: 11.05.2026 11:15
Last: 11.05.2026 11:15
Sources 1
About this happening:
A newly disclosed Linux kernel local privilege-escalation flaw, Dirty Frag and Copy Fail 2, can let an unprivileged user reach root on affected systems. The bug chains...
Linux kernel Dirty Frag and Copy Fail 2 privilege escalation (multiple vulnerabilities)
VulnerabilityAbout this happening: A newly disclosed Linux kernel local privilege-escalation flaw, Dirty Frag and Copy Fail 2, can let an unprivileged user reach root on affected systems. The bug chains...
Timeline
-
16.06.2026 12:00 4 articles · 29d ago
ESET exposes Windows SprySOCKS variants with kernel-level stealth and IOC guidance
Technical Analysis UpdateESET identified Windows variants of SprySOCKS used in attacks against government organizations in Taiwan, Thailand, Pakistan, and Honduras between 2023 and 2024, and attributed the activity with high confidence to Earth Lusca/FishMonger. The research describes WIN_DRV and WIN_PLUS, their TCP, UDP, and WebSocket C2, kernel-level stealth, driver loading, and persistence through scheduled tasks, IFEO, and Windows Print Processor registration, while also publishing indicators of compromise for defenders.
Show sources
- Windows version of SprySOCKS Linux malware used to attack govt orgs — www.bleepingcomputer.com — 16.06.2026 12:00
- Windows version of SprySOCKS Linux malware used to attack govt orgs — www.bleepingcomputer.com — 16.06.2026 12:00
- China-Linked SprySOCKS Backdoor Expands to Windows with Driver-Based Stealth — thehackernews.com — 16.06.2026 12:44
- SprySOCKS Backdoor Expands From Linux to Windows — www.infosecurity-magazine.com — 16.06.2026 17:30