Cybersecurity researchers report that the China-linked SprySOCKS backdoor, previously believed to target Linux, has expanded to Windows. ESET says two previously undocumented Windows variants have been identified and are internally labeled “WIN_DRV” and “WIN_PLUS.” Both variants include hard-coded command-and-control (C2) settings and communicate over standard network protocols, according to ESET. The Windows builds also use driver-based or driver-adjacent techniques described as aimed at improving stealth and persistence, expanding the malware’s operational reach beyond earlier Linux-focused observations. In addition to the platform shift, Infosecurity Magazine reports that SprySOCKS now supports more C2 functionality, including 30-plus C2 commands, reflecting broader control over compromised systems. Across the reporting, researchers characterize SprySOCKS as a backdoor capable of establishing remote communication with attackers through C2 infrastructure, with the new Windows variants extending the malware’s deployment options. The findings highlight an ongoing adaptation of the malware and continued evolution of its tooling and command features on additional operating systems.
China-Linked SprySOCKS Backdoor Adds Windows Variants and New Commanding Capabilities
Cybersecurity researchers report that the China-linked SprySOCKS backdoor, previously believed to target Linux, has expanded to Windows. ESET says two previously undocumented Windows variants have bee...
- Researchers identify two new Windows variants of the SprySOCKS backdoor labeled “WIN_DRV” and “WIN_PLUS.”
- SprySOCKS is previously believed to have been Linux-focused, and it now targets Windows.
- The variants include hard-coded command-and-control (C2) configuration and support communications over TCP and UDP.
- Coverage reports that SprySOCKS uses driver-based or similar stealth approaches in the Windows variants.
- Reported C2 functionality expands, including support for 30-plus C2 commands.
China-linked SprySOCKS backdoor gains stealthy Windows variants and 30-plus C2 commands
2 months agoCybersecurity researchers have flagged two previously undocumented Windows variants of what was believed to be a Linux-only backdoor called SprySOCKS. "The Windows variants discovered are internally marked as WIN_DRV and WIN_PLUS," ESET said in a report shared with The Hacker News. "Both come with a hard-coded C&C [command-and-control] configuration and support communication over TCP, UDP,
2 months ago
Arsenal take on depleted Aston Villa as Tottenham look for return from £300m signings
Arsenal play Aston Villa at Villa Park looking to extend pressure on a depleted Villa squad. Multiple outlets describe V...
Phil Gore completes week-long nonstop running challenge after 168-hour bid
Phil Gore runs non-stop as part of “Project 168,” attempting to cover a 6.7-kilometre loop at the Armadale Soccer Club o...
Dangote Refinery cuts petrol gantry price, triggering depot and some pump price changes
Dangote Refinery announces a reduction in its ex-gantry price for Premium Motor Spirit (petrol), cutting the cost per li...