securityaffairs.com 6/17/2026, 8:29:12 AM · external

China-Linked FishMonger Ports SprySOCKS to Windows With Kernel-Level Stealth and UEFI Bootkit Hints

China-Linked FishMonger Ports SprySOCKS to Windows With Kernel-Level Stealth and UEFI Bootkit Hints
Developing story incident 4 articles tracked
SprySOCKS backdoor gains Windows kernel stealth targeting governments
CyberSIXT Evidence Panel
Primary Source welivesecurity.com
Threat Actor
🇨🇳 Earth Lusca

ESET researchers have identified two new Windows variants of the SprySOCKS backdoor, previously linked only to Linux, associated with the China-linked actor FishMonger. The variants, WIN_DRV and WIN_PLUS, leverage kernel drivers and the Print Spooler service to evade detection and target government organizations in Honduras, Taiwan, Thailand, and Pakistan. WIN_DRV employs a kernel driver to mask network connections, while WIN_PLUS uses the Print Spooler to inject malicious code.

Both variants enable commands such as system information collection and file manipulation. Additionally, there's speculation of a UEFI bootkit component exploiting a known Windows vulnerability, further complicating detection efforts for cybersecurity defenses.

View Primary Source Via securityaffairs.com

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline