SprySOCKS is a cross-platform backdoor associated with the China-aligned espionage cluster FishMonger, also tracked as Earth Lusca and linked by multiple vendors to the broader Winnti ecosystem. It was first documented as a Linux backdoor in 2023 and later expanded to Windows with variants known as WIN_DRV and WIN_PLUS. The malware has been used primarily in cyberespionage operations against government organizations, with observed activity in 2023 and 2024 affecting victims in Asia and Central America.
SprySOCKS is derived from the open-source Trochilus codebase but substantially adapted for operational use. On Linux, it has been observed providing remote shell access, system information gathering, file and directory operations, and SOCKS proxy functionality. The Windows variants preserve the family’s core command-and-control architecture, encryption, and multi-protocol communications while adding Windows-specific stealth and persistence mechanisms.
The Windows implants support more than 30 commands and can communicate over TCP, UDP, and WebSocket, operating in either client or server mode. Documented capabilities include system and network reconnaissance, process enumeration and termination, service creation and control, file listing, transfer, deletion, and execution, interactive command execution, SOCKS proxying, and optional surveillance features such as keylogging and clipboard capture. Some reporting also notes active-window collection in the Windows branch.
WIN_DRV is the more advanced Windows variant. It uses a kernel-mode component functioning as a rootkit to hide files, processes, registry artifacts, and network connections from userland tools, and can divert specially marked TCP traffic from arbitrary open ports to the hidden backdoor listener to conceal command-and-control activity. WIN_PLUS is a lighter Windows variant that omits the kernel rootkit but still emphasizes stealth through Windows-native persistence and covert execution techniques. Across the Windows branch, reported tradecraft includes DLL side-loading, process doppelganging, scheduled-task persistence, print-processor abuse, and firewall-rule modification to permit traffic.
SprySOCKS has been attributed with high confidence to FishMonger, a Chinese cyberespionage group believed to be operated by the contractor I-SOON. The malware has been used alongside other tooling associated with that cluster, including ShadowPad, Cobalt Strike, Spyder, FunnySwitch, and BIOPASS RAT. FishMonger has historically targeted government, foreign affairs, technology, and telecommunications entities, and has been reported to gain access through exploitation of unpatched public-facing servers. Limited, unconfirmed evidence has also suggested that some intrusions involving the Windows variants may have included a UEFI bootkit component exploiting CVE-2023-24932 for deeper persistence.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
ESET also noted limited, unconfirmed evidence of a possible UEFI bootkit component (CVE-2023-24932). | China-aligned FishMonger (Earth Lusca) has ported its SprySOCKS backdoor to Windows and bolted on a kernel driver, RawWNPF, that hides processes, files, connections and registry keys — and turns any open TCP port into a covert C2 channel.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
ESET identified two previously undocumented Windows versions of SprySOCKS, a backdoor it attributes to FishMonger... The stealthier of the two, WIN_DRV, leans on a kernel driver that acts as a rootkit, hiding the malware's files, processes, registry keys and network connections...
ESET identified two previously undocumented Windows versions of SprySOCKS, a backdoor it attributes to FishMonger... The stealthier of the two, WIN_DRV, leans on a kernel driver that acts as a rootkit, hiding the malware's files, processes, registry keys and network connections...
China-aligned FishMonger (Earth Lusca) has ported its SprySOCKS backdoor to Windows and bolted on a kernel driver, RawWNPF, that hides processes, files, connections and registry keys — and turns any open TCP port into a covert C2 channel.
Researchers found two new Windows variants of the SprySOCKS backdoor, previously known only on Linux. Linked to the Chinese group FishMonger (I-SOON), it active targeted government entities between 2023 and 2024. The variants, WIN_DRV and WIN_PLUS, support over 30 commands across TCP, UDP, and WebSockets. WIN_DRV uses kernel drivers to hide itself and divert network traffic to mask its listening port. Evidence suggests some attacks may have deployed a UEFI bootkit exploiting CVE-2023-24932.
31 distinct techniques documented for this family, organized by ATT&CK tactic.
A batch script stages components into %SystemRoot%\Fonts and creates a SYSTEM scheduled task (ApphostRagistreationVerifier) that DLL-side-loads the malicious tpsvcloc.dll via a renamed, signed Microsoft binary.
The backdoor supports keylogging, clipboard capture, file transfer, SOCKS proxy, and remote shell via cmd.exe.
A batch script stages components into %SystemRoot%\Fonts and creates a SYSTEM scheduled task (ApphostRagistreationVerifier) that DLL-side-loads the malicious tpsvcloc.dll via a renamed, signed Microsoft binary.
This driver hides the malware’s network connections, processes, files, and registry keys from standard monitoring tools.
Using Windows Filtering Platform filters it inspects IPv4 traffic and diverts TCP received on ANY open port to the backdoor’s hidden local port — but only when specially crafted magic data is present.
Most concerning, ESET found limited signs that some attacks may reach even deeper, into a UEFI bootkit that loads before Windows itself.
Evidence suggests some attacks may have deployed a UEFI bootkit exploiting CVE-2023-24932.
Between them, they support more than 30 commands, spanning: Service creation, control and deletion
persistence is reinforced by registering that binary as an Image File Execution Options debugger for vds.exe.
A batch script stages components into %SystemRoot%\Fonts and creates a SYSTEM scheduled task (ApphostRagistreationVerifier) that DLL-side-loads the malicious tpsvcloc.dll via a renamed, signed Microsoft binary.
The loader decrypts its payload container ... injects the backdoor shellcode into svchost.exe via process doppelganging using a token stolen from spoolsv.exe.
Evidence suggests some attacks may have deployed a UEFI bootkit exploiting CVE-2023-24932.
Between them, they support more than 30 commands, spanning: Service creation, control and deletion
persistence is reinforced by registering that binary as an Image File Execution Options debugger for vds.exe.
The stealthier of the two, WIN_DRV, leans on a kernel driver that acts as a rootkit, hiding the malware's files, processes, registry keys and network connections so they never show up in tools like netstat.
The loader decrypts its payload container ... injects the backdoor shellcode into svchost.exe via process doppelganging using a token stolen from spoolsv.exe.
Using Windows Filtering Platform filters it inspects IPv4 traffic and diverts TCP received on ANY open port to the backdoor’s hidden local port — but only when specially crafted magic data is present.
This driver hides the malware’s network connections, processes, files, and registry keys from standard monitoring tools.
Both variants reach their operators over three channels, TCP, UDP or WebSocket, and act as client or server.
The variants, WIN_DRV and WIN_PLUS, support over 30 commands across TCP, UDP, and WebSockets.
It also lets operators reach the backdoor without giving themselves away, quietly rerouting traffic from any open port to the backdoor's hidden one when a specific marker appears in the packet and keeping the real destination out of sight.
The backdoor supports keylogging, clipboard capture, file transfer, SOCKS proxy, and remote shell via cmd.exe.
Both SprySOCKS variants communicate with their C2 server over TCP, UDP, and WebSocket.
15 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
18 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware used to enhance stealth and persistence in intrusions against government organizations.
A backdoor originally seen on Linux and now ported to Windows in two variants. It provides remote execution, reconnaissance, process/service control, file operations, and optional surveillance including keylogging and clipboard capture. The WIN_DRV variant adds a stealthy kernel-level rootkit capability via RawWNPF to hide processes, files, registry keys, and network connections, and can covertly divert traffic from any open TCP port into a hidden C2 channel.
A purpose-built backdoor derived from the open-source Trochilus remote access tool and used in espionage campaigns. The Windows variants support over 30 C2 commands including system enumeration, file management, service control, keylogging, clipboard capture, file transfer, SOCKS proxy, and remote shell. WIN_DRV uses the RawWNPF kernel driver to hide network connections, processes, files, and registry keys, while WIN_PLUS uses DLL side-loading, scheduled tasks, and print processor registry abuse for persistence.
A cross-platform backdoor originally known as Linux-only, now observed in two Windows variants. It supports TCP, UDP, and WebSocket C2 communications and can collect system information, launch an interactive shell, enumerate processes and services, initialize a SOCKS proxy, upload/download files, and execute files. The Windows variants add stealth via kernel drivers and Print Spooler abuse.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.