FishMonger’s arsenal upgraded: SprySOCKS for Windows
ESET researchers have discovered two new, undocumented Windows variants of FishMonger's SprySOCKS backdoor, operated by the Chinese threat actor I-SOON (believed to be part of the Winnti Group). These variants, WIN_DRV and WIN_PLUS, are part of a larger campaign targeting government organizations in countries like Honduras, Taiwan, Thailand, and Pakistan. The Windows variants utilize a kernel driver (WIN_DRV) to redirect network traffic, effectively hiding the backdoor's activity. Both variants share core functionality with a previously identified Linux version of SprySOCKS, including C&C communication, commands, encryption, and a common networking library. The attackers use a DLL side-loading technique to install the backdoor, and a persistence mechanism to ensure it runs on system startup. The campaign is attributed to FishMonger, a group known for targeting public-facing servers and exploiting vulnerabilities.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data