China-linked SprySOCKS backdoor expands to Windows with kernel-level stealth (infosecurity-magazine.com)
0xBASE INTEL BRIEF
- Two new Windows variants of SprySOCKS discovered
- WIN_DRV uses kernel rootkit for stealth
- Over 30 C2 commands, keylogging, and SOCKS proxy
"ESET discovered two new Windows variants of the China-linked SprySOCKS backdoor. The WIN_DRV variant uses a kernel driver as a rootkit to hide files, processes, and network connections. The WIN_PLUS variant offers over 30 C2 commands. Targets included government bodies in Honduras, Taiwan, Thailand, and Pakistan. The FishMonger group (Earth Lusca) is linked to Chinese contractor I-Soon."
no comments yet.