ESET reported that the China-linked espionage group FishMonger—also tracked as Earth Lusca, Aquatic Panda, Red Dev 10, and TAG-22—used two previously undocumented Windows variants of the SprySOCKS backdoor to target government organizations in Taiwan, Thailand, Pakistan, and Honduras during 2023 and 2024. The malware is described as a Windows evolution of a backdoor previously thought to be Linux-only and has also been linked to the Chengdu-based contractor iSoon. Researchers said the implants retained the Linux version’s command-and-control design and encryption while adding Windows-native capabilities and support for TCP, UDP, and WebSocket communications.
The two variants, WIN_DRV and WIN_PLUS, provide more than 30 command-and-control functions, including file and process management, SOCKS proxying, and keylogging. ESET said WIN_DRV uses malicious drivers such as RawWNPF and DriverLoader to hide processes, files, registry keys, and network connections, and to redirect TCP traffic through random ports to mask the real listening port, while WIN_PLUS is a simpler backdoor. Investigators also found signs that some intrusions may have involved a UEFI bootkit and possible exploitation of CVE-2023-24932, a Windows Boot Manager Secure Boot bypass flaw, although the evidence was not strong enough to tie that component to BlackLotus.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
ESET disclosed two previously undocumented Windows backdoor variants, WIN_DRV and WIN_PLUS, linked to FishMonger/Earth Lusca and described them as a Windows evolution of SprySOCKS. The researchers also noted indications that some attacks may have involved a UEFI bootkit and possible exploitation of CVE-2023-24932.
ESET reported that China-linked FishMonger/Earth Lusca used previously undocumented Windows variants of the SprySOCKS backdoor in attacks against government organizations in Taiwan, Thailand, Pakistan, and Honduras during 2023 and 2024. The malware added Windows-native capabilities, including kernel-level stealth and extensive command-and-control functions, to the previously known Linux malware family.
Trend Micro disclosed that the China-linked espionage group Earth Lusca was targeting government entities with a previously unseen Linux backdoor called SprySOCKS. The report said the campaign expanded in the first half of 2023 and used exploitation of internet-facing servers, web shells, and Cobalt Strike to support long-term espionage.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
14 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcesecurityaffairs.com
Open sourcecommunity.gurucul.com
Open sourcescworld.com
Open sourcethehackernews.com
Open sourceattack.mitre.org
Open sourceattack.mitre.org
Open sourceblogs.jpcert.or.jp
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.