📰 China-Linked SprySOCKS Backdoor Adds Windows Variants with Kernel-Level Stealth

🇨🇳 China-linked 'FishMonger' group upgrades SprySOCKS backdoor for Windows. New variant uses a kernel driver for advanced stealth, hiding files, processes, and network activity. 🕵️‍♂️ #SprySOCKS #FishMonger #Winnti #CyberEspionage #Malware

🌐 cyber[.]netsecops[.]io

🔗 https://cyber.netsecops.io/articles/china-linked-sprysocks-backdoor-evolves-with-new-windows-variants/?utm_source=mast…

China-Linked Backdoor Expands to Windows with Kernel Stealth

A China-linked espionage group has unleashed a stealthy backdoor that infiltrates Windows systems, targeting government bodies in Honduras, Taiwan, Thailand, and Pakistan. The malware, known as SprySOCKS, boasts advanced espionage features and kernel-level stealth, making it a formidable threat.

https://osintsights.com/china-linked-backdoor-expands-to-windows-with-kernel-stealth?utm_source=mastodon&utm_medium=social

#ChinalinkedBackdoor #Sprysocks #Fishmonger #KernelStealth #WindowsMalware

China-Linked Backdoor Expands to Windows with Kernel Stealth

Discover how China-linked backdoor SprySOCKS expands to Windows with kernel stealth, targeting gov bodies. Learn more about WIN_DRV and WIN_PLUS variants now.

OSINTSights

China-Linked SprySOCKS Backdoor Targets Windows with Driver-Based Stealth

ESET has uncovered a Windows variant of the SprySOCKS backdoor, previously thought to only affect Linux, marking a significant expansion of its capabilities. This new variant, version 1.8, uses driver-based stealth and can communicate through TCP, UDP, and WebSocket channels.

https://osintsights.com/china-linked-sprysocks-backdoor-targets-windows-with-driver-based-stealth?utm_source=mastodon&utm_medium=social

#China #SprysocksBackdoor #Windows #Eset #Fishmonger

China-Linked SprySOCKS Backdoor Targets Windows with Driver-Based Stealth

Discover how China-linked SprySOCKS backdoor targets Windows with driver-based stealth and learn how to protect your system from this threat now effectively.

OSINTSights
#ESETresearch discovered two as-yet undocumented Windows variants of #SprySOCKS, a previously Linux-only backdoor reportedly used by #FishMonger. We attribute the new Windows variants to #FishMonger with high confidence. https://www.welivesecurity.com/en/eset-research/fishmongers-arsenal-upgraded-sprysocks-windows/
Both newly discovered Windows variants, named WIN_PLUS and WIN_DRV by their authors, support communication over TCP, UDP, and WebSocket protocols, while WIN_DRV weaponizes a kernel driver for enhanced stealth.
The WIN_DRV variant creates a stealthy passive TCP backdoor and uses a kernel driver to redirect traffic to the backdoor’s hidden TCP port whenever specially crafted data is detected inside a received TCP packet.
IoCs available in our GitHub repo: https://github.com/eset/malware-ioc/tree/master/SprySOCKS
Read the full analysis on WeLiveSecurity: https://www.welivesecurity.com/en/eset-research/fishmongers-arsenal-upgraded-sprysocks-windows/

"What's the news?"

"I got crabs from cavorting with a fishmonger."

"I'm sorry to hear it."

"What?"

"You know. I'm sorry you got crabs from your tryst with a fishmonger."

"What are you sorry for? She thanked me with a basket of crabs."

#crabs #cavorting #tryst #fishmonger #microfiction

Giant swordfish caught at Los Angeles, ca. 1910 [ca. 1910]

1 photographic print.

Los Angeles (LA) is the most populous city in the U.S. state of California, and the commercial, financial, and cultural center of Southern California. With an estimated 3.88 million residents within the city limits as of 2024, it is the second-most populous city in the United States, behind New York City. Los Angeles has an ethnically and culturally diverse population, and is the principal city of a metropolitan area of 12.9 million people (2024). Greater Los Angeles, a combined statistical area that includes the Los Angeles and Riverside–San Bernardino metropolitan areas, is a sprawling metropolis of over 18.5 million residents.

#Swordfish #Photograph #Fishmonger #Market #Shark #giantswordfish #LosAngeles #man #news #photography
https://www.loc.gov/item/2002718099/

For my tea tonight - #fish stew, made with a bag of Random Fish Bits that the #fishmonger gave me for free. Also some onion fried in butter, leek, tater, parsnip, carrot, garlic, milk, stock, and lemon juice

#cooking

https://www.thetakeout.com/1888482/how-to-get-fresh-salmon-at-grocery-store/

"The One Question You Should Ask The Butcher To Get Fresh Salmon At The Grocery Store"

Is the question: "Do you know where the #Fishmonger is?"

Because a butcher and a fishmonger have very different jobs.

The One Question You Should Ask The Butcher To Get Fresh Salmon At The Grocery Store - The Takeout

The taste and texture of salmon depend on the quality of the fillet. Ask your butcher this one question to ensure you cook with high-quality salmon every time.

The Takeout