Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
SprySOCKS Backdoor Expands to Windows with New Variants

SprySOCKS Backdoor Expands to Windows with New Variants

Posted on June 16, 2026 By CWS

In a significant development in the cybersecurity landscape, researchers have identified novel Windows versions of the SprySOCKS backdoor, originally thought to target only Linux systems. This expansion, noted by ESET, involves two previously undocumented variants named WIN_DRV and WIN_PLUS, which bring new levels of stealth to their operations.

Technical Breakdown of the New Variants

The Windows adaptations of SprySOCKS maintain many of the functionalities of their Linux predecessors, supporting over 30 commands for tasks such as system information gathering, process management, and file operations. Unique to the WIN_DRV variant is the use of kernel drivers to conceal various malware activities, enhancing its stealth capabilities significantly.

Further distinguishing the WIN_DRV variant is its ability to divert TCP traffic, enabling operators to communicate covertly with the backdoor through random ports, thereby masking its presence on infected networks.

Origins and Attribution of SprySOCKS

Initially documented by Trend Micro in September 2023, SprySOCKS has been linked to Earth Lusca, a state-sponsored threat group from China also known as Aquatic Panda and Bronze University. This group, believed to have been active since 2021, has been involved in cyber espionage activities worldwide under the FishMonger banner, targeting organizations across several countries.

SprySOCKS shares lineage with Trochilus, a Windows remote access trojan, and has code overlaps with RedLeaves, suggesting a common development framework with other Chinese threat actors like Webworm.

Execution Chains and Deployment

The WIN_DRV variant, part of SprySOCKS version 1.8, employs a kernel driver named RawWNPF for advanced stealth operations. This driver is activated through an encrypted loader, DriverLoader, which is part of a sophisticated attack chain that includes exploiting known vulnerabilities in widely-used software platforms.

Meanwhile, the WIN_PLUS variant adopts a different strategy, utilizing the Windows Print Spooler service to launch a loader that injects the SprySOCKS backdoor into a newly formed process, enhancing its execution stealth.

Implications and Future Outlook

The emergence of SprySOCKS on Windows platforms underscores the evolving tactics of cyber threat actors, emphasizing the need for robust cybersecurity measures. ESET’s discovery highlights the growing cross-platform capabilities of malware like SprySOCKS, which now presents a more versatile threat landscape.

As these developments unfold, cybersecurity experts stress the importance of continuous monitoring and updating of security protocols to safeguard against such sophisticated threats. The ongoing evolution of SprySOCKS suggests that threat actors will continue to innovate, challenging defenders to stay vigilant.

The Hacker News Tags:Cybersecurity, Earth Lusca, ESET, FishMonger, Malware, RedLeaves, SprySOCKS, Trochilus, Webworm, Windows backdoor

Post navigation

Previous Post: AI Enhances Russian and Chinese Influence Tactics
Next Post: Novo Nordisk Data Breach: Cybercrime Group Claims Responsibility

Related Posts

Android Trojan ‘Fantasy Hub’ Malware Service Turns Telegram Into a Hub for Hackers Android Trojan ‘Fantasy Hub’ Malware Service Turns Telegram Into a Hub for Hackers The Hacker News
SCMBANKER Malware Targets Mexican Banks with ClickFix Tactics SCMBANKER Malware Targets Mexican Banks with ClickFix Tactics The Hacker News
Essential Steps CISOs Must Take for SOC Efficiency Essential Steps CISOs Must Take for SOC Efficiency The Hacker News
Act Now: Prepare for Post-Quantum Cryptography Act Now: Prepare for Post-Quantum Cryptography The Hacker News
Critical Gitea Docker Flaw CVE-2026-20896 Under Attack Critical Gitea Docker Flaw CVE-2026-20896 Under Attack The Hacker News
CISA Flags VMware Zero-Day Exploited by China-Linked Hackers in Active Attacks CISA Flags VMware Zero-Day Exploited by China-Linked Hackers in Active Attacks The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • JetBrains Fixes Critical TeamCity Vulnerability
  • Minnesota Water Systems Targeted by Cyberattacks Amid Iranian Hacker Concerns
  • Google Chrome Updates Fix Over 1,400 Security Issues
  • Anthropic’s AI Models Breach Security in Tests
  • Chinese Hackers Use Telegram for Autonomous Cyber Attacks

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • JetBrains Fixes Critical TeamCity Vulnerability
  • Minnesota Water Systems Targeted by Cyberattacks Amid Iranian Hacker Concerns
  • Google Chrome Updates Fix Over 1,400 Security Issues
  • Anthropic’s AI Models Breach Security in Tests
  • Chinese Hackers Use Telegram for Autonomous Cyber Attacks

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark