0x

guest@0xbase ~$ read-only mode. Posting requires EU location.

China-linked SprySOCKS backdoor expands to Windows with kernel-level stealth (infosecurity-magazine.com)

· 41d ago · Report · Spotlight this ·
0xBASE INTEL BRIEF
  • Two new Windows variants of SprySOCKS discovered
  • WIN_DRV uses kernel rootkit for stealth
  • Over 30 C2 commands, keylogging, and SOCKS proxy

"ESET discovered two new Windows variants of the China-linked SprySOCKS backdoor. The WIN_DRV variant uses a kernel driver as a rootkit to hide files, processes, and network connections. The WIN_PLUS variant offers over 30 C2 commands. Targets included government bodies in Honduras, Taiwan, Thailand, and Pakistan. The FishMonger group (Earth Lusca) is linked to Chinese contractor I-Soon."

Discussion Matrix

0 segments

no comments yet.