news.mlab.sh
Back to the feed
threat-intel

China-Linked SprySOCKS Backdoor Expands to Windows with Driver-Based Stealth

High
Image: The Hacker News
Summary

Researchers have identified new Windows variants of the SprySOCKS backdoor, initially linked to the Chinese state-sponsored threat actor Earth Lusca (also known as Aquatic Panda). These variants, designated WIN_DRV and WIN_PLUS, utilize kernel drivers and stealth techniques to conceal network connections and operations, mirroring the functionality of the original Linux-based backdoor. The discovery highlights an ongoing espionage campaign targeting government organizations in multiple countries, including Honduras, Taiwan, Thailand, and Pakistan, and potentially leveraging a UEFI bootkit vulnerability.

Read the full article at The Hacker News

Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data

Report an error
Confirmed errors are fixed and listed on /corrections.