{"id":1333,"date":"2026-06-16T13:15:03","date_gmt":"2026-06-16T13:15:03","guid":{"rendered":"https:\/\/thedigitalfortress.us\/?p=1333"},"modified":"2026-06-16T13:15:03","modified_gmt":"2026-06-16T13:15:03","slug":"china-linked-sprysocks-backdoor-expands-to-windows-with-driver-based-stealth","status":"publish","type":"post","link":"https:\/\/thedigitalfortress.us\/?p=1333","title":{"rendered":"China-Linked SprySOCKS Backdoor Expands to Windows with Driver-Based Stealth"},"content":{"rendered":"<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjxym2hiE83TbiNOrIeH3s4QCF0wQ_BYcSYPKlC3m9LGSuJnH7UNicbkgIk4kQTbpPiLRul9dSxQ180XW656_9NPtlqWoTGivTamDVl24ZfUQFPgUleakZq6aZI5kZqszNz3GpVyJQnPiXis_kjlMqAxKBxGKZsDdAvb-rX20fxszdd0pCKRO9GqK3CSu-p\/s1700-e365\/chinese-proxy.png\" style=\"clear: left; display: block; float: left;  text-align: center;\"><\/a><\/div>\n<p>Cybersecurity researchers have flagged two previously undocumented Windows variants of what was believed to be a Linux-only backdoor called <b>SprySOCKS<\/b>.<\/p>\n<p>\u00abThe Windows variants discovered are internally marked as WIN_DRV and WIN_PLUS,\u00bb ESET <a href=\"https:\/\/www.welivesecurity.com\/en\/eset-research\/fishmongers-arsenal-upgraded-sprysocks-windows\/\">said<\/a> in a report shared with The Hacker News. \u00abBoth come with a hard-coded C&amp;C [command-and-control] configuration and support communication over TCP, UDP, and WebSocket protocols.\u00bb<\/p>\n<p>Like its Linux counterpart, the Windows versions support more than 30 commands to facilitate system information collection, process enumeration, service management, and file system operations. WIN_DRV has also been found to utilize kernel drivers to conceal the malware&#8217;s network connections, processes, files, and registry keys.<\/p>\n<p>In addition, the variant enables TCP traffic diversion that allows the malware operators to send commands to the backdoor through a random TCP port on the victim&#8217;s device without exposing the backdoor&#8217;s actual listening port in the network traffic.<\/p>\n<p>SprySOCKS was first publicly documented by Trend Micro in September 2023, attributing its use to a China-nexus state-sponsored threat actor known as Earth Lusca, which is also tracked by the cybersecurity community under the monikers Aquatic Panda, Bronze University, Charcoal Typhoon, and RedHotel. The adversary is assessed to be active since at least 2021 and <a href=\"https:\/\/web-assets.esetstatic.com\/wls\/en\/papers\/threat-reports\/eset-apt-activity-report-q4-2023-q1-2024.pdf\">operated<\/a> by a Chinese contractor named i-Soon.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/ai-cant-stop-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjPEV6-530TOlxG6PjrmdlY623wpBwduZ7t1HV6flcmO5R4q4AmfixDUzW0CrhlvMVNWbhvOIso-UDNTka4W_W9Chrdj_dglwBZwi7DuePM2IMIl-hfUYVIqBXgfpr_2619K8Gptb4LzwJ6gUbi7lWl2M8AFQJsHEaw63Q7tZ6708YGruiHrr0Y2W9YYxLQ\/s728-e100\/ThreatLocker-d.png\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>The Slovakian cybersecurity vendor, which has assigned the name FishMonger to the threat cluster, has described it as a cyber espionage group that falls under the broader Winnti umbrella. In a report published in March 2025, the company linked the hacking group to a global campaign dubbed Operation FishMedley targeting seven organizations in Taiwan, Hungary, Turkey, Thailand, France, and the U.S. between January and October 2022.<\/p>\n<p><a name=\"more\"\/><\/p>\n<p>SprySOCKS is based on a Windows remote access trojan called Trochilus, and shares several common traits with <a href=\"https:\/\/blogs.jpcert.or.jp\/en\/2017\/04\/redleaves---malware-based-on-open-source-rat.html\">RedLeaves<\/a>, a backdoor that also exhibits extensive source code overlaps with Trochilus. What&#8217;s more, the use of Trochilus is linked to another Chinese threat actor known as Webworm, which, in turn, has tradecraft commonalities with both FishMonger and SixLittleMonkeys.<\/p>\n<table cellpadding=\"0\" cellspacing=\"0\" class=\"tr-caption-container\" style=\"float: left;\">\n<tbody>\n<tr>\n<td style=\"text-align: center;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjNGJh5vyrWZbbA1Uj-J4LOMpOjlgr5rigNCQ6I9b5qYZnDu9GjSkX76_VARxp4kWDk_C89Y_tusbbujojmngcGOXr67NlJNhyphenhyphenhHQ3vuOmNC1VgolKB_fQyCR5ZtCNvI2i94JSN4PrqUHYZVIwghjBAiaATrGxvpKmUs0uhrlVwYfPG_8bq1xJudpsVdOu6\/s1700-e365\/1.png\" style=\"clear: left; display: block; margin-left: auto; margin-right: auto;  text-align: center;\"><img decoding=\"async\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjNGJh5vyrWZbbA1Uj-J4LOMpOjlgr5rigNCQ6I9b5qYZnDu9GjSkX76_VARxp4kWDk_C89Y_tusbbujojmngcGOXr67NlJNhyphenhyphenhHQ3vuOmNC1VgolKB_fQyCR5ZtCNvI2i94JSN4PrqUHYZVIwghjBAiaATrGxvpKmUs0uhrlVwYfPG_8bq1xJudpsVdOu6\/s1700-e365\/1.png\" alt=\"\" border=\"0\" data-original-height=\"2000\" data-original-width=\"1752\"\/><\/a><\/td>\n<\/tr>\n<tr>\n<td class=\"tr-caption\" style=\"text-align: center;\">WIN_DRV Execution Chain<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>The Windows variants are part of version 1.8 of SprySOCKS, with the <a href=\"https:\/\/www.virustotal.com\/gui\/file\/68aec5085599e8a272767f50da66c83a6582e4e16ed97c209f65f81538b0c028\/details\" target=\"_blank\">WIN_DRV sample<\/a> using a kernel driver referred to as RawWNPF (\u00abKW1B5206BDC1743FP.dat\u00bb) for advanced stealth, while retaining the functionality present in the Linux variant. The driver is loaded using another encrypted kernel driver named DriverLoader (\u00abKX1B5206BDC1743DD.dat\u00bb).<\/p>\n<p>The attack chain makes use of an as-yet-undetermined initial access pathway to drop a batch script, which then creates and executes a scheduled task responsible for triggering a DLL side-loading chain that drops the SprySOCKS backdoor and the driver components. However, it&#8217;s worth noting that the group has previously exploited N-day security flaws in public-facing Fortinet, GitLab, Microsoft Exchange Server, Progress Telerik UI, and Zimbra instances to obtain a foothold.<\/p>\n<p>\u00abThe Windows version retains most of the core architecture of its Linux predecessor \u2014 including the C&amp;C protocol, encryption used, and overall command handling logic \u2014 while substituting Windows-native mechanisms where required and improving the stealthiness of the backdoor by bringing the kernel drivers to the game,\u00bb ESET researcher Martin Smol\u00e1r said.<\/p>\n<table cellpadding=\"0\" cellspacing=\"0\" class=\"tr-caption-container\" style=\"float: left;\">\n<tbody>\n<tr>\n<td style=\"text-align: center;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEg9WxLLYKIRRW1GSKGeDp8sKMw3YI9-x7wSQ3OLYKmWpgzUIWOjnQcPutSriE9Cy0CUxFFqf81wGerg1ezD2IwqQw7f-vm6iOfHm01verxpItsN2e-cqrPA-O2TcJh1Sx0cjEiGki1btxigNmcQAOfc8YKd_bzgBFqLG28-xqueFUAePYUG7oLdkcdBSzsH\/s1700-e365\/2.png\" style=\"clear: left; display: block; margin-left: auto; margin-right: auto;  text-align: center;\"><img decoding=\"async\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEg9WxLLYKIRRW1GSKGeDp8sKMw3YI9-x7wSQ3OLYKmWpgzUIWOjnQcPutSriE9Cy0CUxFFqf81wGerg1ezD2IwqQw7f-vm6iOfHm01verxpItsN2e-cqrPA-O2TcJh1Sx0cjEiGki1btxigNmcQAOfc8YKd_bzgBFqLG28-xqueFUAePYUG7oLdkcdBSzsH\/s1700-e365\/2.png\" alt=\"\" border=\"0\" data-original-height=\"2000\" data-original-width=\"1406\"\/><\/a><\/td>\n<\/tr>\n<tr>\n<td class=\"tr-caption\" style=\"text-align: center;\">WIN_PLUS Execution Chain<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>\u00abThe most notable differences can be spotted in the way the final backdoor is loaded, in the improved stealthiness, and in the component names and paths used.<\/p>\n<p>The WIN_PLUS execution scheme, in contrast, adopts a different approach. It leverages the Windows Print Spooler service (\u00abspoolsv.exe\u00bb) as a starting point to execute a first-stage loader that runs as a <a href=\"https:\/\/learn.microsoft.com\/en-us\/windows-hardware\/drivers\/print\/introduction-to-print-processors\">print processor<\/a>. It&#8217;s designed to inject and run a SprySOCKS loader into a newly created \u00absvchost.exe\u00bb process to launch the backdoor.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/vpn-threat-report-m\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhFlTC7RrRZGiFAgASS0noWSL0qsQGFVp8-Hvuw9yp3X3VKRuTcb5SsPX09wJzrdIM6pu1_5lS4EeZp7Sx4iYBpNJkrGnpr08yyaS1HQ5_5TxaCsP6O0OtHNuOkesn6CbNjao1GPulCJk-uljYMSfMZfBYNrngpe669t7jlRn1FqiEnXhsFD1WVkpaYIVgh\/s728-e100\/ai-d.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>Both WIN_DRV and WIN_PLUS variants of SprySOCKS are DLLs that support three channels for C2 communications over TCP, UDP, and WebSocket and run commands issued by the operator on the compromised host. This includes collecting system information, launching an interactive console, enumerating processes, getting C2 communication details, listing all services, initialising a SOCKS proxySOCKS proxy, uploading\/downloading files, and running existing files.<\/p>\n<p>Evidence indicates that the artifacts may have been deployed between 2023 and 2024 in attacks targeting government organizations in Honduras, Taiwan, Thailand, and Pakistan. The WIN_PLUS version was first detected in July 2024 on a victim device geolocated to Pakistan.<\/p>\n<p>What&#8217;s more, there are \u00ablimited indications\u00bb suggesting the involvement of a UEFI bootkit, likely exploiting CVE-2023-24932 (CVSS score: 6.7), a security feature bypass vulnerability in the Windows Boot Manager that\u2019s famously associated with the BlackLotus UEFI bootkit. The security flaw was addressed by Microsoft in May 2023.<\/p>\n<p>\u00abThe discovery of a Windows variant of SprySOCKS, previously known as Linux-only backdoor, represents a meaningful expansion of FishMonger&#8217;s cross-platform capabilities,\u00bb ESET said.<\/p>\n<p>\u00abThe Windows port retains most of the core architecture of its Linux predecessor \u2013 including the C&amp;C protocol, encryption used, and overall command handling logic \u2013 while substituting Windows-native mechanisms where required and improving the stealthiness of the backdoor by bringing the kernel drivers to the game.\u00bb<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>Cybersecurity researchers have flagged two previously undocumented Windows variants of what was believed to be a Linux-only backdoor called SprySOCKS. \u00abThe Windows variants discovered are internally marked as WIN_DRV and&hellip;<\/p>\n","protected":false},"author":1,"featured_media":1334,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[179,479,2065,206,2064,570,307],"class_list":["post-1333","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-backdoor","tag-chinalinked","tag-driverbased","tag-expands","tag-sprysocks","tag-stealth","tag-windows"],"_links":{"self":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/1333","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1333"}],"version-history":[{"count":0,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/1333\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/media\/1334"}],"wp:attachment":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1333"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1333"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1333"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}