Gallery

Contacts

405 W. Greenlawn Ave Lansing, Michigan 48910

contact@techjacksolutions.com

+1-616-320-4064

ESET has identified two new Windows variants of the SprySOCKS backdoor, attributed to FishMonger, a Chinese state-sponsored group also tracked as Earth Lusca and Aquatic Panda. The variants deploy kernel-mode rootkit capabilities and abuse the Windows Print Spooler service to achieve deep, persistent access on government and enterprise targets, with forensic evidence suggesting possible pre-OS (UEFI) persistence via a Secure Boot bypass vulnerability. Government agencies and enterprises running unpatched Windows systems, particularly those involved in foreign policy, defense, or critical infrastructure, face a high risk of long-term, undetected compromise.

Author

Tech Jacks Solutions