China-Linked SprySOCKS Backdoor Expands to Windows with Driver-Based Stealth
China-linked SprySOCKS backdoor expands to Windows with driver-based stealth, allowing for more sophisticated cyber espionage attacks.
Intelligence analysis by Llama 3.3 70B

The Windows variants of SprySOCKS, a previously Linux-only backdoor, have been discovered, featuring advanced stealth capabilities and kernel driver usage.
Imagine a secret door in a computer system that allows hackers to sneak in and steal information. The SprySOCKS backdoor is like that secret door, and it's now available for Windows computers, making it harder to detect and stop.
Analysis
Introduction to SprySOCKS
The SprySOCKS backdoor, initially discovered in 2023, has been linked to a China-nexus state-sponsored threat actor known as Earth Lusca. The backdoor was previously believed to be Linux-only, but recent discoveries have revealed Windows variants, expanding its capabilities and potential impact.
Technical Capabilities of SprySOCKS
The Windows variants of SprySOCKS, namely WIN_DRV and WIN_PLUS, feature advanced stealth capabilities, including the use of kernel drivers to conceal malware network connections, processes, files, and registry keys. The backdoor supports over 30 commands, facilitating system information collection, process enumeration, service management, and file system operations.
Attack Chain and Execution
The attack chain involves an initial access pathway, followed by a batch script that creates and executes a scheduled task, triggering a DLL side-loading chain that drops the SprySOCKS backdoor and driver components. The group has previously exploited N-day security flaws in public-facing instances to obtain a foothold. The WIN_DRV and WIN_PLUS variants have distinct execution schemes, with WIN_PLUS leveraging the Windows Print Spooler service to execute a first-stage loader.
Key points
- China-linked SprySOCKS backdoor expands to Windows
- Advanced stealth capabilities using kernel drivers
- Supports over 30 commands for system information collection and file system operations
- Distinct execution schemes for WIN_DRV and WIN_PLUS variants
The discovery of the Windows variants of SprySOCKS may lead to improved cybersecurity measures, as organizations and individuals become more aware of the potential threats and take steps to protect themselves. Additionally, the expansion of SprySOCKS to Windows may prompt further research and development of more effective detection and mitigation techniques.
The expansion of SprySOCKS to Windows poses a significant threat to organizations, as it enables more sophisticated cyber espionage attacks with improved stealth and evasion capabilities. This may lead to increased instances of data breaches and intellectual property theft, potentially causing significant financial and reputational damage.


