FishMonger’s arsenal upgraded: SprySOCKS for Windows

Imported from official source

Cybersecurity Classified by Officially

ESET researchers have discovered two as-yet undocumented Windows variants of SprySOCKS, a previously Linux-only backdoor reportedly used by FishMonger, the group believed to be operated by a Chinese contractor named I‑SOON. While we initially discovered the malware samples on VirusTotal, ESET telemetry shows real activity between 2023 and 2024, with several victims in Honduras, Taiwan, Thailand, and Pakistan, targeting mostly government organizations.

The Windows variants discovered are internally marked as WIN_DRV and WIN_PLUS. Both come with a hardcoded C&C configuration and support communication over TCP, UDP, and WebSocket protocols. The core backdoor functionality for both includes support for over 30 C&C commands, covering various functionalities including system information collection, process enumeration, as well as service management and file management functions such as listing, creating, deleting, and transferring files.

In addition to the core backdoor functionality, the WIN_DRV version utilizes kernel drivers to hide the malware’s network connections, processes, files, and registry keys, and enables TCP traffic diversion allowing the malware operators to send commands to the backdoor through a random TCP port on the victim’s device without exposing the backdoor's real listening port in the network traffic.

Based on ESET telemetry, there are limited indications that some SprySOCKS attack scenarios may involve a UEFI bootkit component, possibly exploiting CVE‑2023‑24932.

The analysis provided in this report leads us to attribute these new, Windows variants to FishMonger with high confidence.

  • We discovered two previously undocumented Windows variants of FishMonger’s SprySOCKS backdoor.
  • ESET telemetry shows activity between 2023 and 2024, primarily targeting government organizations in Honduras, Taiwan, Thailand, and Pakistan.
  • Both Windows variants support communication over TCP, UDP, and WebSocket protocols, and implement over 30 commands.
  • This is an extract. The publication continues at the source.

    Read the original at the source: https://www.welivesecurity.com/en/eset-research/fishmongers-arsenal-upgraded-sprysocks-windows/

    Officially imported this from ESET’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.

    Provenance

    Organization
    ESET — imported from official source
    Official source
    https://www.welivesecurity.com/en/rss/feed/ RSS
    Imported
    September 18, 2026 11:35
    Versions
    1 recorded
    Identity
    https://www.welivesecurity.com/en/eset-research/fishmongers-arsenal-upgraded-sprysocks-...

    Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.