China-Linked SprySOCKS Backdoor Expands to Windows with Driver-Based Stealth
ResearchSprySOCKSEarth LuscaTrochilusOur summary
Researchers report two new Windows builds of the SprySOCKS backdoor—tracked internally as WIN_DRV and WIN_PLUS—previously believed to target Linux. The Windows versions use hard-coded command-and-control with TCP, UDP, and WebSocket communications and expand capabilities for reconnaissance, service/process management, and file operations, with WIN_DRV leveraging kernel drivers and WIN_PLUS using the Windows Print Spooler to load the payload more covertly. Evidence suggests UEFI-boot persistence may be involved, potentially exploiting CVE-2023-24932, a Windows Boot Manager security bypass that Microsoft fixed in May 2023.
The Hacker News publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.