ESET: SprySOCKS backdoor now found in Windows variants

ESET has published new research on two previously undocumented Windows variants of SprySOCKS, a backdoor associated with FishMonger, a group believed to be operated by the Chinese contractor I-SOON. ESET telemetry shows activity in 2023 and 2024, mostly against government organisations in Honduras, Taiwan, Thailand and Pakistan. The variants WIN_DRV and WIN_PLUS retain the backdoor's C2 protocol and command model while adding Windows-native loading and stealth. WIN_DRV uses kernel drivers to hide processes, files, registry keys and network connections, and can divert TCP traffic so operators reach the hidden backdoor without exposing its real listening port. ESET also notes limited indications that some scenarios may involve a UEFI bootkit component, possibly tied to CVE-2023-24932.

What this means for your organisation

This is state-aligned espionage rather than crime chasing a quick return. The targets are government organisations, but suppliers and subcontractors serving them are equally relevant. What sets this backdoor apart from ordinary malware is that it hides at kernel level, making it invisible to tools that ask the operating system what is running. If the UEFI component is in play, it also survives a Windows reinstall.

Berigo recommends

  • Load ESET's indicators of compromise into your detection tooling and search retrospectively.
  • Enable and enforce Secure Boot and vulnerable driver blocking across your Windows estate.
  • Monitor kernel driver loading as its own event type, not merely as part of general endpoint telemetry.
  • Assess whether your organisation is a viable stepping stone into public sector customers, and mirror their requirements in your own controls.

Source

Related services

Security that is understood, governed and works.

Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.

Get in touch