← Threat Actors & APT Groups

FishMonger

Every article that identifies FishMonger as responsible for or connected to reported activity.

MalwareInfosecurity Magazine·2 months ago

SprySOCKS Backdoor Expands From Linux to Windows

A previously Linux-focused backdoor attributed to Chinese threat actors now has Windows variants, expanding its operational reach across multiple platforms. The updated SprySOCKS malware supports over 30 command-and-control commands, enabling attackers to execute diverse post-compromise objectives while maintaining stealth on infected systems.

MalwareWeLiveSecurity·2 months ago

FishMonger’s arsenal upgraded: SprySOCKS for Windows

ESET researchers have identified SprySOCKS for Windows, an upgraded backdoor in FishMonger's toolkit that leverages a kernel driver to achieve enhanced stealth capabilities. The use of kernel-level access represents a significant evolution in the malware's evasion techniques, making detection and removal more challenging for traditional security tools.