news.mlab.sh
Back to the feed
threat-intel

FishMonger’s arsenal upgraded: SprySOCKS for Windows

High
Summary

ESET researchers have discovered two new, undocumented Windows variants of FishMonger's SprySOCKS backdoor, operated by the Chinese threat actor I-SOON (believed to be part of the Winnti Group). These variants, WIN_DRV and WIN_PLUS, are part of a larger campaign targeting government organizations in countries like Honduras, Taiwan, Thailand, and Pakistan. The Windows variants utilize a kernel driver (WIN_DRV) to redirect network traffic, effectively hiding the backdoor's activity. Both variants share core functionality with a previously identified Linux version of SprySOCKS, including C&C communication, commands, encryption, and a common networking library. The attackers use a DLL side-loading technique to install the backdoor, and a persistence mechanism to ensure it runs on system startup. The campaign is attributed to FishMonger, a group known for targeting public-facing servers and exploiting vulnerabilities.

Read the full article at WeLiveSecurity

Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data

Report an error
Confirmed errors are fixed and listed on /corrections.