China-linked Earth Lusca used new Windows SprySOCKS malware variants against government organizations in four countries

Researchers say a China-linked hacking group used new Windows versions of the SprySOCKS backdoor to attack government organizations in Taiwan, Thailand, Pakistan, and Honduras. ESET attributes the activity to Earth Lusca, also tracked as FishMonger, and says the malware includes two Windows variants, WIN_DRV and WIN_PLUS, with capabilities such as file theft, keylogging, process control, SOCKS proxying, and stealth features through a kernel driver. The more advanced variant also used a driver signed with a leaked certificate from the PastDSE project, and ESET saw signs of a possible UEFI bootkit component linked to CVE-2023-24932, though that part was not confirmed.
Why it matters: This matters because it shows a state-linked espionage group expanding from Linux to Windows with stealthier tools for long-term access to government networks. Government, foreign-affairs, technology, and telecom defenders should hunt for the published indicators of compromise, review persistence mechanisms such as scheduled tasks and print processors, and check for Secure Boot-related abuse.

Sources

China-Linked SprySOCKS Backdoor Expands to Windows with Driver-Based Stealth
info@thehackernews.com (The Hacker News) 2026.06.16 97% relevant
The article appears to cover the same underlying event: reporting that the China-linked Earth Lusca campaign expanded SprySOCKS to Windows and used driver-based stealth against government targets in multiple countries, adding technical detail on the Windows backdoor variant.
Windows version of SprySOCKS Linux malware used to attack govt orgs
Bill Toulas 2026.06.16 100% relevant
This article appears to be the first tracked item centered on Earth Lusca's newly reported Windows SprySOCKS variants and their use against government targets in four countries.
← Back to all stories