ESET researchers discovered two undocumented Windows variants of the SprySOCKS backdoor, WINDRV and WINPLUS, attributed to the China-aligned FishMonger APT. These variants utilize advanced stealth techniques, including a custom kernel driver for hiding artifacts and diverting TCP traffic, as well as print processor abuse for persistence.
Kernel Driver
3 posts
FishMonger’s arsenal upgraded: SprySOCKS for Windows fast16 | Mystery ShadowBrokers Reference Reveals High-Precision Software Sabotage 5 Years Before Stuxnet SentinelLABS discovered fast16, a sophisticated 2005 cyber sabotage framework that uses a Lua-based carrier and a kernel driver to selectively patch high-precision calculation software in memory. The malware subtly corrupts floating-point arithmetic in engineering and simulation tools, representing an early, state-level capability for physical-world sabotage.
They Got In Through SonicWall. Then They Tried to Kill Every Security Tool Threat actors breached a network via compromised SonicWall SSLVPN credentials and deployed a sophisticated EDR killer to blind endpoint security prior to a planned ransomware deployment. The malware utilizes a Bring Your Own Vulnerable Driver (BYOVD) technique, dropping a revoked EnCase forensic driver encoded with a novel wordlist substitution cipher to terminate 59 different security processes directly from kernel mode.