All incidents

SprySOCKS backdoor gains Windows kernel stealth targeting governments

incidentclosedJun 16, 2026 — Jun 17, 2026
SprySOCKS backdoor gains Windows kernel stealth targeting governments

SPRYSOCKS, a backdoor previously seen only on Linux, has been ported to Windows by the China‑linked espionage group Earth Lusca, also known as FishMonger. The new Windows variants target government organisations in Honduras Taiwan Thailand and Pakistan. Details were published by ESET here.

ESET identified two versions named WIN_DRV and WIN_PLUS. WIN_DRV loads a kernel driver that masks network traffic and hides processes from standard monitoring tools. WIN_PLUS abuses the Windows Print Spooler service to inject malicious code and maintain persistence. Both variants allow operators to collect system information manipulate files and execute arbitrary commands. No CVEs have been assigned to these components.

Analysis shows the malware has been active since at least 2023 with initial access likely gained through exposed or misconfigured public‑facing applications. Researchers note hints of a UEFI bootkit component that could abuse a known Windows vulnerability to survive reboots and evade detection. This potential bootkit would add another layer of stealth beyond the kernel driver.

The campaign has been observed hitting ministries and agencies in the four named countries aligning with Earth Lusca’s historic focus on Southeast Asian and Latin American targets. The use of kernel‑level tricks makes the backdoor invisible to many endpoint detection products that rely on user‑mode monitoring. This development fits a broader trend where Chinese APT groups are expanding their toolkits to include deep‑system techniques.

Defenders should enforce strict driver signing policies and block unsigned or unknown kernel modules from loading. Monitoring the Print Spooler service for abnormal child processes or unexpected DLL loads can reveal the WIN_PLUS variant. Endpoint detection and response tools need to be configured to watch for kernel callbacks hidden hooks and irregular network traffic that does not appear in standard process lists.

Organisations are advised to apply the latest Windows patches consider disabling the Print Spooler service where it is not required and share the indicators of compromise released by ESET with their security teams. Network segmentation and least‑privilege access for administrative accounts will limit the impact if the backdoor manages to gain a foothold.

Intelligence briefing updated Jun 17, 2026

Earth Lusca
Root sourcewww.welivesecurity.com
Timeline Coverage

Swipe to explore timeline