Chinese hackers who appear to be engaged in espionage and are being tracked as “Earth Lusca”, are targeting government agencies in multiple countries, using a new Linux backdoor called “SprySOCKS”.

According to Trend Micro and analysis , the new backdoor is derived from the open-source Windows malware Trochilus, with many of its functions adapted to work effectively on systems . However, the malware appears to be a mix of multiple malware, as the SprySOCKS command and control server (C2) communication protocol is similar to RedLeaves, another Windows backdoor. In contrast, other elements appear to come from Derusbi, a Linux malware.
See also: APT36 hackers: They use fake YouTube apps and infect devices with CapraRAT
Earth Lusca: Attacks with the SprySOCKS backdoor
Earth Lusca was particularly active throughout the first half of the year, targeting key government agencies focused on foreign affairs, technology , and telecommunications in Southeast Asia, Central Asia, the Balkans, and other regions around the world.
Trend Micro reports that it observed attempts to exploit multiple n-day vulnerabilities that allowed remote code execution, over a broad period from 2019 to 2022. These vulnerabilities affected endpoints that were exposed to the internet.
The vulnerabilities were used to install Cobalt Strike beacons , which allow remote access to the compromised network. This access is then used by hackers for lateral movement into the network and allows file extraction , account credentials theft , and the deployment of additional malicious payloads, such as ShadowPad.
See also: Hook: New Android banking trojan is based on ERMAC
Cobalt Strike beacons were also used to install the SprySOCKS loader, a variant of the Linux ELF injector called “mandibule.” This arrives on targeted machines in the form of a file named “libmonitor.so.2.”
The loader runs under the name “kworker/0:22” to avoid detection, decrypts the second-stage payload (SprySOCKS) and establishes persistence on the infected computer.

SprySOCKS backdoor capabilities
The SprySOCKS backdoor uses a high-performance networking framework called “HP-Socket” to operate. communications with the C2 are encrypted with AES-ECB.
The main functions of the backdoor include:
- Collect system information (operating system details, memory, IP address, group name, language, CPU),
- Starting an interactive shell that uses the PTY subsystem,
- Registering network connections,
- SOCKS proxy configuration management,
- Perform basic file operations (upload, download, write, delete, rename, and create directories.)
Trend Micro says it has tested two versions of SprySOCKS, v1.1 and v.1.3.6. This means the malware is under constant development.
See also: Rust Implant used in new malware campaign against Azerbaijan
Organizations should immediately apply new security to their systems to ensure there are no security gaps that hackers, like the Earth Lusca group, could exploit to attack.
Backdoor malware, such as SprySOCKS, is a serious threat to cybersecurity. This type of malware provides an attacker with access to a computer or network, bypassing standard security measures. Backdoor attacks can be extremely difficult to detect, as they often use advanced techniques and obfuscation methods to remain on a victim’s system. Staying informed about backdoor malware threats is important for developing effective security strategies.
Source: www.bleepingcomputer.com
