THREAT ACTOR INTELLIGENCE REPORT

FishMonger Expands SprySOCKS Backdoor to Windows with Driver-Based Stealth

Analysis of a China-Linked Espionage Group Expanding Cross-Platform Malware Capabilities

Analyst
Rajkumar G
Date
16 June 2026
Classification
Public
Report Type
Threat Actor Intelligence

Executive Summary

ESET researchers identified previously undocumented Windows variants of the SprySOCKS malware family, a backdoor historically associated with the China-linked cyber espionage group FishMonger. The newly discovered variants, WIN_DRV and WIN_PLUS, introduce enhanced stealth capabilities through kernel drivers, process injection, DLL side-loading, and advanced command-and-control functionality. This development demonstrates a significant evolution in FishMonger’s operational toolkit and highlights the group's continued investment in long-term intelligence collection operations targeting government and strategic organizations.

Key Intelligence Overview

Threat Actor

FishMonger

Aliases

Earth Lusca

Malware

SprySOCKS

Severity

High

Motivation

Espionage

Confidence

High

Threat Actor Attribution

FishMonger is a China-linked cyber espionage group operating within the broader Winnti ecosystem. The actor has been associated with multiple aliases including Earth Lusca, Aquatic Panda, Bronze University, Charcoal Typhoon, and RedHotel. The group's historical targeting patterns indicate a focus on strategic intelligence collection against governments, public sector organizations, and institutions of geopolitical interest.

Known Aliases

Observed Targets

Victim organizations have been observed in Pakistan, Taiwan, Thailand, Honduras, France, Hungary, Turkey, and the United States.

Campaign Timeline

2021

FishMonger activity publicly tracked.

September 2023

SprySOCKS first documented as a Linux-based backdoor.

2023–2024

Deployment of Windows variants against government targets.

July 2024

WIN_PLUS variant detected on a victim system in Pakistan.

June 2026

ESET disclosed new Windows SprySOCKS variants.

Malware Capability Analysis

SprySOCKS Overview

SprySOCKS is a modular remote access backdoor supporting more than thirty commands including system reconnaissance, file management, service control, SOCKS proxy functionality, and remote command execution.

WIN_DRV

WIN_DRV introduces kernel driver support enabling concealment of files, processes, registry keys, and network communications while improving operational stealth.

WIN_PLUS

WIN_PLUS leverages Print Spooler abuse, DLL side-loading, and process injection techniques to establish persistence and execute malicious code.

Attack Chain Analysis

Initial Access

The exact entry vector remains unknown. Historical FishMonger activity includes exploitation of vulnerable Fortinet, GitLab, Microsoft Exchange, Telerik, and Zimbra systems.

Execution

Execution relies on scheduled tasks, scripts, DLL side-loading, and malicious loaders.

Persistence

Persistence mechanisms include driver-based execution chains, scheduled tasks, and service abuse.

Defense Evasion

Kernel drivers are used to hide malicious activity from monitoring tools and security products.

Command and Control

Communications are conducted through TCP, UDP, and WebSocket channels using hardcoded command-and-control infrastructure.

MITRE ATT&CK Mapping

Tactic Observed Activity
Execution DLL Side-Loading
Persistence Scheduled Tasks
Persistence Driver-Based Execution
Defense Evasion Rootkit Functionality
Discovery Process Enumeration
Discovery System Information Collection
Command and Control WebSocket Communication
Command and Control SOCKS Proxy Support

Indicators of Interest

Detection Opportunities

Defensive Recommendations

  1. Patch internet-facing applications.
  2. Monitor kernel driver installation.
  3. Enable EDR visibility.
  4. Review scheduled task creation logs.
  5. Investigate anomalous service activity.
  6. Conduct proactive threat hunting.

Analyst Assessment

The Windows adaptation of SprySOCKS represents a significant capability enhancement for FishMonger. By incorporating kernel-level stealth and Windows-native persistence mechanisms, the actor has increased both survivability and operational effectiveness. Organizations supporting government and strategic functions should prioritize monitoring for driver-based persistence and covert command-and-control communications.

References

Share Report