FeedMalwareESET discovers Windows SprySOCKS variant with rootkit capabi...
MalwareCyber Insider
6.7HIGH

ESET discovers Windows SprySOCKS variant with rootkit capabilities

📅 16 June 2026 at 09:00 UTC📰 Cyber InsiderView original source ↗
ESET discovers Windows SprySOCKS variant with rootkit capabilities

ESET researchers have uncovered two previously undocumented Windows variants of SprySOCKS, a backdoor previously known only as a Linux threat and linked to the China-aligned cyberespionage group FishMonger. The newly discovered malware variants significantly expand the group's capabilities by introducing Windows-native persistence mechanisms and, in one version, a kernel-level rootkit designed to conceal malicious activity … The post ESET discovers Windows SprySOCKS variant with rootkit capabilities appeared first on CyberInsider.

🤖 AI BriefingAuto-generated threat analysis
🔍Threat Overview

ESET has discovered two variants of the SprySOCKS backdoor, WIN_DRV and WIN_PLUS, with rootkit capabilities, attributed to the China-aligned cyberespionage group FishMonger, targeting government organizations in Honduras, Taiwan, Thailand, and Pakistan.

⚙️Technical Details
CVEs
CVE-2023-24932
Attack Vectors
LOCAL
💥Impact Assessment
Severity: MEDIUM
Who Is at Risk
Government organizations in Honduras, Taiwan, Thailand, and Pakistan
🛡️Recommended Actions
1Implement regular security updates for Microsoft Windows 10
2Monitor system logs for suspicious activity related to network connections and processes
3Conduct thorough vulnerability assessments for Secure Boot Security Feature Bypass Vulnerability (CVE-2023-24932)
📦Affected Products
Microsoft Windows 10 1507Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 20H2Microsoft Windows 10 21H2Microsoft Windows 10 22H2Microsoft Windows 11 21H2Microsoft Windows 11 22H2Microsoft Windows Server 2008Microsoft Windows Server 2012
🔐NVD Verified DataVERIFIED
CVE-2023-24932CVSS 6.7MEDIUM
Attack Vector
LOCAL
Complexity
LOW
Vector String
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-863
Affected Products (CPE)
Microsoft Windows 10 1507Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 20H2Microsoft Windows 10 21H2

Read the full article

This is a curated summary. The complete article is available at Cyber Insider.

Read on Cyber Insider
← Back to feed