discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.
Featured

China-Linked SprySOCKS Backdoor Expands to Windows with Driver-Based Stealth

China-linked SprySOCKS backdoor expands to Windows with driver-based stealth, allowing for more sophisticated cyber espionage attacks.

By Ravie Lakshmanan·Jun 16·thehackernews.com·1 min read

Intelligence analysis by Llama 3.3 70B

China-Linked SprySOCKS Backdoor Expands to Windows with Driver-Based Stealth
Image: thehackernews.com

The Windows variants of SprySOCKS, a previously Linux-only backdoor, have been discovered, featuring advanced stealth capabilities and kernel driver usage.

Why it matters

The expansion of SprySOCKS to Windows poses a significant threat to organizations, as it enables more sophisticated cyber espionage attacks with improved stealth and evasion capabilities.

Imagine a secret door in a computer system that allows hackers to sneak in and steal information. The SprySOCKS backdoor is like that secret door, and it's now available for Windows computers, making it harder to detect and stop.

Analysis

Introduction to SprySOCKS

The SprySOCKS backdoor, initially discovered in 2023, has been linked to a China-nexus state-sponsored threat actor known as Earth Lusca. The backdoor was previously believed to be Linux-only, but recent discoveries have revealed Windows variants, expanding its capabilities and potential impact.

Technical Capabilities of SprySOCKS

The Windows variants of SprySOCKS, namely WIN_DRV and WIN_PLUS, feature advanced stealth capabilities, including the use of kernel drivers to conceal malware network connections, processes, files, and registry keys. The backdoor supports over 30 commands, facilitating system information collection, process enumeration, service management, and file system operations.

Attack Chain and Execution

The attack chain involves an initial access pathway, followed by a batch script that creates and executes a scheduled task, triggering a DLL side-loading chain that drops the SprySOCKS backdoor and driver components. The group has previously exploited N-day security flaws in public-facing instances to obtain a foothold. The WIN_DRV and WIN_PLUS variants have distinct execution schemes, with WIN_PLUS leveraging the Windows Print Spooler service to execute a first-stage loader.

Key points

  • China-linked SprySOCKS backdoor expands to Windows
  • Advanced stealth capabilities using kernel drivers
  • Supports over 30 commands for system information collection and file system operations
  • Distinct execution schemes for WIN_DRV and WIN_PLUS variants
The Upside

The discovery of the Windows variants of SprySOCKS may lead to improved cybersecurity measures, as organizations and individuals become more aware of the potential threats and take steps to protect themselves. Additionally, the expansion of SprySOCKS to Windows may prompt further research and development of more effective detection and mitigation techniques.

The Downside

The expansion of SprySOCKS to Windows poses a significant threat to organizations, as it enables more sophisticated cyber espionage attacks with improved stealth and evasion capabilities. This may lead to increased instances of data breaches and intellectual property theft, potentially causing significant financial and reputational damage.

Originally reported at

thehackernews.com

Discernion covers the story. Read the full piece at the source.

Tagscyber-espionagecybersecuritymalwarelinuxwindows

Author

Ravie Lakshmanan

Intelligence analysis by

Llama 3.3 70B

Published

Jun 16, 2026

Source

thehackernews.com

Share

Topics

cyber-espionagecybersecuritymalwarelinuxwindows

Related

More from this desk

Aug 14·schneier.com

Upcoming Speaking Engagements

Bruce Schneier shares his upcoming speaking engagements, including LAcon V in Anaheim, California, USA, a League of Women Voters event, Elevate Festival in Toronto, Canada, CanSecWest 2026 in Vancouver, Canada, and ATTENTION: Democracy, Rebuilt in Montreal, Canada.

Aug 14·bleepingcomputer.com

Hackers Exploit macOS Screen Sharing Flaw to Deploy Monero Miner

NCSC warns of active macOS vulnerability exploitation for cryptocurrency mining.

Aug 14·bleepingcomputer.com

The Modern Attack Chain: Rethinking Google Workspace Security in the Age of AI

The article discusses the evolving attack chain in Google Workspace security, where OAuth tokens become the entry point for attackers, and AI agents are increasingly used to exploit vulnerabilities. The author argues that security teams need to rethink their defenses to a…

Aug 14·bleepingcomputer.com

Max severity SAP Commerce Cloud flaw now targeted in attacks

A maximum-severity SAP Commerce Cloud remote code execution vulnerability patched three days ago is already being targeted in attacks, according to threat intelligence company Defused.