Find notable cyber news and cases, enriched with sources, timelines, and signals.

ESET analysis of SprySOCKS Windows variants adds IOC-backed detection guidance

Technical Analysis
First reported
Last updated
Happening score
H score 34
3 unique sources, 3 articles

Summary

Hide ▲

ESET identified previously undocumented Windows variants of SprySOCKS, a backdoor attributed to FishMonger and linked to I-Soon. The WIN_DRV and WIN_PLUS variants add kernel-level stealth and retain TCP, UDP, and WebSocket command-and-control, plus 30+ espionage commands. ESET traced activity to 2023-2024 against government bodies in Honduras, Taiwan, Thailand, and Pakistan, and found signs the activity may extend into a UEFI bootkit chain.

Related Happenings

FishMonger multi-country government espionage campaign

Campaign
H score33 First: 16.06.2026 17:30 Last: 16.06.2026 17:30 Sources 1

How related: ESET telemetry traced real activity to 2023 and 2024, mostly against government bodies in Honduras, Taiwan, Thailand and Pakistan.

About this happening: FishMonger ran a multi-country espionage campaign against government bodies in Honduras, Taiwan, Thailand and Pakistan across 2023 and 2024. The activity point...

SprySOCKS Windows backdoor activity against government organizations

Malware Activity
H score23 First: 16.06.2026 12:00 Last: 16.06.2026 12:00 Sources 1

How related: Cybersecurity researchers have flagged two previously undocumented Windows variants of what was believed to be a Linux-only backdoor called SprySOCKS.

About this happening: SprySOCKS now has documented Windows variants, WIN_DRV and WIN_PLUS, expanding a toolset first known as a Linux-only backdoor. The activity is tied to govern...

GPU cryptomining malware using ScreenConnect and SEO poisoning

Malware Activity
H score16 First: 28.05.2026 00:31 Last: 28.05.2026 00:31 Sources 1

About this happening: A cryptojacking malware operation is spreading through SEO-poisoned download pages and, in some cases, AI chatbot recommendations, putting high-performance Windows s...

Microsoft Defender zero-days exploited in attacks (multiple vulnerabilities)

Vulnerability
H score39 First: 21.05.2026 10:49 Last: 21.05.2026 10:49 Sources 1

About this happening: Microsoft began rolling out fixes for CVE-2026-41091 and CVE-2026-45498, two actively exploited zero-days in Microsoft Defender components that affect unpatched Wi...

Linux kernel Dirty Frag and Copy Fail 2 privilege escalation (multiple vulnerabilities)

Vulnerability
H score31 First: 11.05.2026 11:15 Last: 11.05.2026 11:15 Sources 1

About this happening: A newly disclosed Linux kernel local privilege-escalation flaw, Dirty Frag and Copy Fail 2, can let an unprivileged user reach root on affected systems. The bug chains...

Timeline

  1. 16.06.2026 12:00 4 articles · 29d ago

    ESET exposes Windows SprySOCKS variants with kernel-level stealth and IOC guidance

    Technical Analysis Update

    ESET identified Windows variants of SprySOCKS used in attacks against government organizations in Taiwan, Thailand, Pakistan, and Honduras between 2023 and 2024, and attributed the activity with high confidence to Earth Lusca/FishMonger. The research describes WIN_DRV and WIN_PLUS, their TCP, UDP, and WebSocket C2, kernel-level stealth, driver loading, and persistence through scheduled tasks, IFEO, and Windows Print Processor registration, while also publishing indicators of compromise for defenders.

    Show sources