news.mlab.sh
Back to the feed
threat-intel

SprySOCKS Windows Variant Abuses Kernel Drivers to Evade Detection

High
Image: Dark Reading
Summary

A new Windows variant of the SprySOCKS Linux backdoor, developed by the nation-state threat actor FishMonger (also known as Earth Lusca and Aquatic Panda), has been discovered targeting government organizations in Honduras, Taiwan, Thailand, and Pakistan. This variant utilizes malicious kernel drivers to evade detection, adding to the group's arsenal and highlighting the risks posed by kernel-level malware. The discovery underscores the ongoing sophistication of APT groups and the potential for nation-state actors to leverage advanced techniques like kernel drivers for espionage.

Read the full article at Dark Reading

Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data

Report an error
Confirmed errors are fixed and listed on /corrections.