# China-Linked SprySOCKS Backdoor Breaks into Windows with Advanced Driver-Based Stealth Tactics
Cybersecurity researchers have uncovered a significant escalation in the capabilities of SprySOCKS, a backdoor previously believed to operate exclusively on Linux systems. Security vendor ESET has documented two previously unknown Windows variants of the malware—designated WIN_DRV and WIN_PLUS—marking a substantial expansion of the threat actor's operational scope. The discovery reveals that the adversary has invested considerable effort in porting this cyber espionage tool to Windows environments while enhancing its stealth mechanisms through kernel-level drivers and sophisticated injection chains.
The findings underscore a concerning trend: state-sponsored threat actors are systematically expanding their malware portfolios to target multiple platforms and environments, increasing the attack surface for organizations globally.
## The Threat: Windows Variants Unveiled
ESET's discovery identifies two distinct Windows implementations of SprySOCKS, part of version 1.8 of the malware family:
WIN_DRV (Driver-Based Variant)
WIN_PLUS (Print Spooler Variant)
Both variants retain core functionality from the Linux version, supporting more than 30 commands for:
## Background and Context: A Growing Threat
SprySOCKS was first publicly documented by Trend Micro in September 2023 and attributed to Earth Lusca, a China-nexus state-sponsored threat actor tracked under multiple aliases including:
Attribution and Operations
Earth Lusca has been active since at least 2021 and is believed to be operated by a Chinese contractor named i-Soon. ESET researchers have assigned the cluster the name FishMonger and classify it as a cyber espionage group operating under the broader Winnti umbrella—a designation for a family of Chinese state-sponsored threat actors with overlapping tools, tactics, and infrastructure.
The backdoor itself derives from Trochilus, a Windows remote access trojan with significant source code overlaps to RedLeaves, another espionage tool linked to the threat group Webworm. These shared artifacts suggest common development origins or tool-sharing practices within Chinese state-sponsored APT circles.
Operation FishMedley
In March 2025, ESET published research on Operation FishMedley, a global campaign attributed to FishMonger spanning January to October 2022. The operation targeted seven organizations across:
The campaign demonstrated the group's willingness to target geographically dispersed victims, suggesting broad intelligence collection mandates.
## Technical Details: Execution Chains and Stealth Mechanisms
### WIN_DRV Execution Chain
The WIN_DRV variant employs a multi-stage execution chain designed to evade detection:
1. Initial Access: An undetermined initial access vector delivers a batch script to the target system
2. Scheduled Task Creation: The batch script creates and executes a scheduled task
3. DLL Side-Loading: The scheduled task triggers a DLL side-loading chain
4. Backdoor Deployment: The chain drops both the SprySOCKS backdoor and associated driver components
The use of DLL side-loading—a technique that exploits legitimate application loading mechanisms—helps obscure the malware's presence in process listings and load order.
Kernel Driver Stealth (RawWNPF)
The introduction of kernel-level drivers represents a substantial escalation in sophistication. The RawWNPF driver ("KW1B5206BDC1743FP.dat") provides:
The driver is itself loaded through an encrypted driver loader ("DriverLoader" / "KX1B5206BDC1743DD.dat"), adding an additional obfuscation layer.
### WIN_PLUS Execution Chain
WIN_PLUS adopts an alternative approach using the Windows Print Spooler service as an initial execution point. By compromising the print spooler—a highly privileged system service—the malware gains early execution context and can maintain persistence through legitimate service mechanisms that defenders might overlook in routine security investigations.
### Command and Control Infrastructure
Both variants maintain hard-coded C&C configurations and support communication over multiple protocols (TCP, UDP, WebSocket), providing resilience if one communication channel is disrupted. This multi-protocol approach complicates detection by distributed denial of service (DDoS) mitigation or protocol-specific filtering.
## Historical Attack Vectors
While the Windows variants' initial access mechanism remains undetermined, Earth Lusca has a documented history of exploiting N-day security flaws in:
Organizations running unpatched instances of these widely deployed applications represent high-risk targets for initial compromise.
## Implications: Who's at Risk and Why This Matters
The expansion to Windows significantly broadens the threat landscape. While Linux systems have traditionally been considered lower-risk targets for APT activity, Windows dominates enterprise environments in government, finance, and critical infrastructure. The sophistication demonstrated in WIN_DRV—particularly kernel-level stealth—suggests Earth Lusca is preparing for long-term, difficult-to-detect operations in high-value Windows environments.
Organizations at elevated risk include:
| Sector | Risk Level | Rationale |
|--------|-----------|-----------|
| Government / Defense | Critical | State-sponsored espionage mandates |
| Technology / Software | Critical | IP theft and supply chain access |
| Financial Services | High | Economic espionage and intellectual property |
| Telecommunications | High | Network intelligence and infrastructure access |
| Energy / Critical Infrastructure | High | Strategic intelligence collection |
| Academia / Research | Medium | Research data and talent recruitment targeting |
The use of kernel drivers indicates a shift toward advanced persistent threats (APTs) rather than opportunistic malware. Kernel-level code execution grants defenders far fewer detection and removal options, as traditional user-mode security tools may be unable to observe or control kernel-space activity.
## Recommendations for Defense and Detection
### Immediate Actions
### Detection Strategies
### Long-Term Hardening
---
## HackWire Analysis
The emergence of WIN_DRV and WIN_PLUS represents a critical inflection point in state-sponsored malware evolution. For years, security researchers observed a clear division of labor: Windows backdoors belonged to financially motivated cybercriminals, while nation-states focused on Linux infrastructure and specialized espionage tools. This boundary is collapsing.
What makes this evolution particularly concerning is not merely that SprySOCKS now targets Windows—it's that Earth Lusca invested in kernel-level stealth. Developing stable kernel drivers is technically difficult and requires deep Windows internals expertise. This suggests the group has either recruited new talent with kernel driver experience or gained access to shared driver libraries within Chinese contractor networks. Either way, the bar for detection has been substantially raised.
The timing also matters. We've seen a 36-month pattern: Trend Micro documents a tool (September 2023), researchers identify its origins and operators, and then—after the initial publicity dies—the operators quietly expand it to new platforms with enhanced stealth. This compressed innovation cycle suggests Earth Lusca operates with significant engineering resources and suffers minimal consequences for detected operations. Attribution alone has never disrupted a state-sponsored group; only real consequences do.
For defenders, the hard truth is that kernel-level stealth cannot be reliably detected or removed by traditional endpoint security. Organizations can no longer rely on EDR tools as a primary defense; they must assume compromise and focus on detection through network traffic analysis, behavior anomalies, and network segmentation. Print spooler abuse and DLL side-loading are well-known techniques, but when deployed by an APT with kernel-level stealth capabilities, they become nearly invisible to conventional monitoring. The battleground has shifted from tools to workflows—defenders must focus on what normal looks like, then hunt relentlessly for the deviations.
— *HackWire Editorial*
---
## Related Coverage