China-Linked SprySOCKS Backdoor Expands to Windows with Driver-Based Stealth
Researchers have identified new Windows variants of the SprySOCKS backdoor, initially linked to the Chinese state-sponsored threat actor Earth Lusca (also known as Aquatic Panda). These variants, designated WIN_DRV and WIN_PLUS, utilize kernel drivers and stealth techniques to conceal network connections and operations, mirroring the functionality of the original Linux-based backdoor. The discovery highlights an ongoing espionage campaign targeting government organizations in multiple countries, including Honduras, Taiwan, Thailand, and Pakistan, and potentially leveraging a UEFI bootkit vulnerability.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
