SprySOCKS Windows backdoor activity against government organizations
Malware Activity
Summary
Hide ▲
Show ▼
SprySOCKS now has documented Windows variants, WIN_DRV and WIN_PLUS, expanding a toolset first known as a Linux-only backdoor. The activity is tied to government organizations in Taiwan, Thailand, Pakistan, and Honduras and uses TCP, UDP, and WebSocket communications with more than 30 commands for system data collection, process and service management, and file operations. WIN_DRV adds kernel drivers for stealth, hiding processes, files, network connections, and registry keys while also supporting TCP traffic diversion. ESET links the activity to Earth Lusca / FishMonger and notes limited indications of a UEFI bootkit path involving CVE-2023-24932.
Related Happenings
LabubaRAT Rust RAT masquerading as NVIDIA software on Windows
Malware Activity
H score24
First: 14.07.2026 19:52
Last: 14.07.2026 19:52
Sources 1
About this happening:
A newly documented Rust-based RAT, LabubaRAT, now gives operators Windows host control with file movement, screenshot capture, and traffic proxying. The malware masq...
LabubaRAT Rust RAT masquerading as NVIDIA software on Windows
Malware ActivityAbout this happening: A newly documented Rust-based RAT, LabubaRAT, now gives operators Windows host control with file movement, screenshot capture, and traffic proxying. The malware masq...
GigaWiper / BLUERABBIT destructive Windows backdoor activity
Malware Activity
H score31
First: 09.07.2026 21:08
Last: 09.07.2026 21:08
Sources 1
About this happening:
The GigaWiper / BLUERABBIT malware activity now combines disk wiping, fake ransomware, and spyware backdoor functions on Windows, increasing the chance that on...
GigaWiper / BLUERABBIT destructive Windows backdoor activity
Malware ActivityAbout this happening: The GigaWiper / BLUERABBIT malware activity now combines disk wiping, fake ransomware, and spyware backdoor functions on Windows, increasing the chance that on...
Millenium RAT Windows malware activity and native C++ rewrite
Malware Activity
H score62
First: 29.06.2026 17:30
Last: 29.06.2026 17:30
Sources 1
About this happening:
The Millenium RAT malware activity is spreading across Windows systems, with 60,000+ infections in 160+ countries and a newer native C++ build that helps it ev...
Millenium RAT Windows malware activity and native C++ rewrite
Malware ActivityAbout this happening: The Millenium RAT malware activity is spreading across Windows systems, with 60,000+ infections in 160+ countries and a newer native C++ build that helps it ev...
Gentlemen ransomware EDR-killer tooling
Malware Activity
H score35
First: 19.06.2026 01:31
Last: 19.06.2026 01:31
Sources 1
About this happening:
Gentlemen ransomware-as-a-service (RaaS) is actively maintaining a suite of EDR killers led by GentleKiller to disable endpoint defenses before encryption. ESET says t...
Gentlemen ransomware EDR-killer tooling
Malware ActivityAbout this happening: Gentlemen ransomware-as-a-service (RaaS) is actively maintaining a suite of EDR killers led by GentleKiller to disable endpoint defenses before encryption. ESET says t...
FishMonger multi-country government espionage campaign
Campaign
H score33
First: 16.06.2026 17:30
Last: 16.06.2026 17:30
Sources 1
How related:
ESET telemetry traced real activity to 2023 and 2024, mostly against government bodies in Honduras, Taiwan, Thailand and Pakistan.
About this happening:
FishMonger ran a multi-country espionage campaign against government bodies in Honduras, Taiwan, Thailand and Pakistan across 2023 and 2024. The activity point...
FishMonger multi-country government espionage campaign
CampaignHow related: ESET telemetry traced real activity to 2023 and 2024, mostly against government bodies in Honduras, Taiwan, Thailand and Pakistan.
About this happening: FishMonger ran a multi-country espionage campaign against government bodies in Honduras, Taiwan, Thailand and Pakistan across 2023 and 2024. The activity point...
Timeline
-
16.06.2026 12:00 4 articles · 29d ago
SprySOCKS Windows backdoor activity against government organizations
Initial DisclosureThe first observed deployment involved SprySOCKS Windows variants being used during 2023-2024 against government organizations in multiple countries. Those variants combined stealth, persistence, and remote command features to operate inside victim systems with reduced visibility.
Show sources
- Windows version of SprySOCKS Linux malware used to attack govt orgs — www.bleepingcomputer.com — 16.06.2026 12:00
- Windows version of SprySOCKS Linux malware used to attack govt orgs — www.bleepingcomputer.com — 16.06.2026 12:00
- China-Linked SprySOCKS Backdoor Expands to Windows with Driver-Based Stealth — thehackernews.com — 16.06.2026 12:44
- SprySOCKS Backdoor Expands From Linux to Windows — www.infosecurity-magazine.com — 16.06.2026 17:30