HomeSecuritySprySOCKS backdoor: Expands to Windows with kernel drivers

SprySOCKS backdoor: Expands to Windows with kernel drivers

The SprySOCKS backdoor, previously thought to be exclusively for Linux, is now expanding to Windows with two new, previously unknown variants. According to new research by ESET, these variants are internally named WIN_DRV and WIN_PLUS, and use advanced obfuscation techniques via kernel drivers to remain invisible to target systems. This discovery significantly upgrades the estimated threat posed by the Chinese group FishMonger, also known as Earth Lusca.

SprySOCKS backdoor

The two new SprySOCKS variants are part of version 1.8 of the malware and retain the same basic architecture as the Linux version, including the command-and-control (C&C) server communication protocol , encryption, and command handling logic. Both variants support communication over TCP , UDP , and WebSocket protocols , and feature a hardcoded C&C configuration. In total, they support more than 30 commands for collecting system information, enumerating processes, managing services, and performing file system operations.

The WIN_DRV variant is notable for using a kernel driver referred to as RawWNPF (file KW1B5206BDC1743FP.dat ), which hides the malware 's network connections, processes, files, and registry keys . The driver is loaded via another encrypted kernel driver called DriverLoader ( KX1B5206BDC1743DD.dat ). In addition, this variant enables TCP traffic redirection , allowing SprySOCKS operators to send commands over a random TCP port without revealing the backdoor's actual listening port in network traffic — a highly sophisticated evasion technique.

See also: How to detect suspicious activity in Windows

SprySOCKS: Technical details and attack chain

At this time, the method of initial access is unknown, but what we do know is that a batch script. This creates and executes a scheduled taskthattriggers a DLL side-loading, which ultimately installs the backdoor and driver components. It is worth noting that the group has previously exploited known vulnerabilities (N-day flaws) in publicly exposed services such as Fortinet, GitLab, Microsoft Exchange Server, Progress Telerik UI , and Zimbra to gain initial access to target networks.

The WIN_PLUS takes a different approach: it leverages the Windows Print Spooler (spoolsv.exe) as a launching point to execute a first-stage loader that acts as a print processor. It then injects and executes a SprySOCKS into a newly created svchost.exe to launch the backdoor. Using legitimate Windows to hide malicious activity is a classic living-off-the-land that makes detection particularly difficult.

SprySOCKS backdoor: Expands to Windows with kernel drivers

SprySOCKS is based on Trochilus, a known Windows remote access trojan, and shares common features with RedLeaves, a backdoor that also exhibits extensive source code overlap with Trochilus. The use of Trochilus is linked to another Chinese threat actor, known as Webworm, which exhibits similarities to both FishMonger and SixLittleMonkeys. These connections reveal an extensive ecosystem of Chinese cyberespionage with common tools and infrastructure.

See also: How to take screenshots in Windows 11

The FishMonger group — which falls under the broader Winnti umbrella — is believed to have been active since at least 2021 and operates through a Chinese contractor called i-Soon . In a report published by ESET in March 2025 , the company linked the group to a global cyberespionage campaign codenamed Operation FishMedley , which targeted seven organizations in Taiwan , Hungary , Turkey , Thailand , France , and the United States between January and October 2022. The group’s geographic reach suggests that European organizations — including possibly Greek ones — are within its scope.

ESET researcher Martin Smolár noted that “ the Windows retains most of the core architecture of its Linux predecessor — including the C&C protocol, encryption, and overall command-handling logic — while replacing mechanisms with Windows-native ones where needed and improving the stealth of the backdoor by introducing kernel drivers version .” This development marks a significant upgrade in the team’s capabilities and dramatically expands the attack surface, as Windows is the dominant operating system in corporate environments worldwide.

See also: FlutterShell Backdoor Spreads on macOS via Malicious Google and YouTube Ads

SprySOCKS backdoor: Expands to Windows with kernel drivers

To protect against SprySOCKS-type threats, organizations should promptly apply security updates to publicly exposed services, monitor suspicious activity in processes such as spoolsv.exe and svchost.exe, use EDR that can detect kernel-level rootkits, and implement zero-trust for network access. According to The Hacker News, ESET research reveals that SprySOCKS is actively evolving, making monitoring this threat a top priority for cybersecurity teams worldwide.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS