SprySOCKS Windows Variant Abuses Kernel Drivers to Evade Detection
A new Windows variant of the SprySOCKS Linux backdoor, developed by the nation-state threat actor FishMonger (also known as Earth Lusca and Aquatic Panda), has been discovered targeting government organizations in Honduras, Taiwan, Thailand, and Pakistan. This variant utilizes malicious kernel drivers to evade detection, adding to the group's arsenal and highlighting the risks posed by kernel-level malware. The discovery underscores the ongoing sophistication of APT groups and the potential for nation-state actors to leverage advanced techniques like kernel drivers for espionage.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
