June 18, 2026
- SprySOCKS — ESET attributes two undocumented Windows variants (WIN_PLUS, WIN_DRV) of the previously Linux-only backdoor to China-nexus FishMonger (Earth Lusca). WIN_DRV weaponizes a kernel driver to redirect traffic to a hidden passive TCP backdoor, with possible UEFI bootkit involvement. IOCs published (WeLiveSecurity, The Hacker News). · Threat Activity & Ransomware