Cybersecurity researchers report that the China-linked SprySOCKS backdoor, previously believed to target Linux, has expanded to Windows. ESET says two previously undocumented Windows variants have been identified and are internally labeled “WIN_DRV” and “WIN_PLUS.” Both variants include hard-coded command-and-control (C2) settings and communicate over standard network protocols, according to ESET. The Windows builds also use driver-based or driver-adjacent techniques described as aimed at improving stealth and persistence, expanding the malware’s operational reach beyond earlier Linux-focused observations. In addition to the platform shift, Infosecurity Magazine reports that SprySOCKS now supports more C2 functionality, including 30-plus C2 commands, reflecting broader control over compromised systems. Across the reporting, researchers characterize SprySOCKS as a backdoor capable of establishing remote communication with attackers through C2 infrastructure, with the new Windows variants extending the malware’s deployment options. The findings highlight an ongoing adaptation of the malware and continued evolution of its tooling and command features on additional operating systems.