Find notable cyber news and cases, enriched with sources, timelines, and signals.

SprySOCKS Windows backdoor activity against government organizations

Malware Activity
First reported
Last updated
Happening score
H score 23
3 unique sources, 3 articles

Summary

Hide ▲

SprySOCKS now has documented Windows variants, WIN_DRV and WIN_PLUS, expanding a toolset first known as a Linux-only backdoor. The activity is tied to government organizations in Taiwan, Thailand, Pakistan, and Honduras and uses TCP, UDP, and WebSocket communications with more than 30 commands for system data collection, process and service management, and file operations. WIN_DRV adds kernel drivers for stealth, hiding processes, files, network connections, and registry keys while also supporting TCP traffic diversion. ESET links the activity to Earth Lusca / FishMonger and notes limited indications of a UEFI bootkit path involving CVE-2023-24932.

Related Happenings

LabubaRAT Rust RAT masquerading as NVIDIA software on Windows

Malware Activity
H score24 First: 14.07.2026 19:52 Last: 14.07.2026 19:52 Sources 1

About this happening: A newly documented Rust-based RAT, LabubaRAT, now gives operators Windows host control with file movement, screenshot capture, and traffic proxying. The malware masq...

GigaWiper / BLUERABBIT destructive Windows backdoor activity

Malware Activity
H score31 First: 09.07.2026 21:08 Last: 09.07.2026 21:08 Sources 1

About this happening: The GigaWiper / BLUERABBIT malware activity now combines disk wiping, fake ransomware, and spyware backdoor functions on Windows, increasing the chance that on...

Millenium RAT Windows malware activity and native C++ rewrite

Malware Activity
H score62 First: 29.06.2026 17:30 Last: 29.06.2026 17:30 Sources 1

About this happening: The Millenium RAT malware activity is spreading across Windows systems, with 60,000+ infections in 160+ countries and a newer native C++ build that helps it ev...

Gentlemen ransomware EDR-killer tooling

Malware Activity
H score35 First: 19.06.2026 01:31 Last: 19.06.2026 01:31 Sources 1

About this happening: Gentlemen ransomware-as-a-service (RaaS) is actively maintaining a suite of EDR killers led by GentleKiller to disable endpoint defenses before encryption. ESET says t...

FishMonger multi-country government espionage campaign

Campaign
H score33 First: 16.06.2026 17:30 Last: 16.06.2026 17:30 Sources 1

How related: ESET telemetry traced real activity to 2023 and 2024, mostly against government bodies in Honduras, Taiwan, Thailand and Pakistan.

About this happening: FishMonger ran a multi-country espionage campaign against government bodies in Honduras, Taiwan, Thailand and Pakistan across 2023 and 2024. The activity point...

Timeline

  1. 16.06.2026 12:00 4 articles · 29d ago

    SprySOCKS Windows backdoor activity against government organizations

    Initial Disclosure

    The first observed deployment involved SprySOCKS Windows variants being used during 2023-2024 against government organizations in multiple countries. Those variants combined stealth, persistence, and remote command features to operate inside victim systems with reduced visibility.

    Show sources