ESET discovers Windows SprySOCKS variant with rootkit capabilities
ESET researchers have uncovered two previously undocumented Windows variants of SprySOCKS, a backdoor previously known only as a Linux threat and linked to the China-aligned cyberespionage group FishMonger. The newly discovered malware variants significantly expand the group's capabilities by introducing Windows-native persistence mechanisms and, in one version, a kernel-level rootkit designed to conceal malicious activity … The post ESET discovers Windows SprySOCKS variant with rootkit capabilities appeared first on CyberInsider.
ESET has discovered two variants of the SprySOCKS backdoor, WIN_DRV and WIN_PLUS, with rootkit capabilities, attributed to the China-aligned cyberespionage group FishMonger, targeting government organizations in Honduras, Taiwan, Thailand, and Pakistan.
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:HRead the full article
This is a curated summary. The complete article is available at Cyber Insider.
