# SprySOCKS Windows Variant Weaponizes Kernel Drivers to Target Government Networks Across Asia-Pacific and Latin America
A sophisticated nation-state threat group has significantly expanded its cyber-espionage arsenal by weaponizing a previously undocumented Windows variant of the SprySOCKS backdoor, using kernel-level drivers to evade detection systems and maintain persistent access to high-value government targets. Security researchers at ESET have documented the deployment of this advanced malware against government organizations across Honduras, Taiwan, Thailand, and Pakistan—marking a troubling escalation in the operational capabilities of FishMonger, a China-linked advanced persistent threat (APT) group.
## The Threat
FishMonger, also known by its aliases Earth Lusca and Aquatic Panda, has demonstrated a pattern of continuous capability expansion. The group initially gained notoriety for its Linux-based SprySOCKS backdoor, which was first observed in 2023 targeting government and critical infrastructure organizations. Now, the discovery of a full Windows port of this malware—complete with kernel-driver evasion capabilities—reveals a sophisticated actor capable of maintaining operational flexibility across multiple platforms.
The Windows variants discovered by ESET come in two distinct flavors:
What makes this discovery particularly concerning is the *retroactive* nature of the finding. Forensic analysis and telemetry from VirusTotal samples indicate that these Windows variants were deployed in active operations during 2023 and 2024—meaning the backdoor may have resided undetected on victim networks for over a year before its public identification.
## Background and Context
FishMonger gained significant attention in 2024 when security researchers linked the group directly to i-Soon, a Chinese technology company that openly marketed offensive cyber operations services to government clients. This attribution marked a rare instance of direct connection between a major nation-state-sponsored threat group and a commercial entity operating with what appeared to be official sanction.
The group's targeting patterns suggest state-level interest in specific geopolitical regions:
| Target Region | Government Sector | Strategic Significance |
|---------------|------------------|----------------------|
| Taiwan | Government agencies | Regional geopolitical tension |
| Honduras | Government agencies | Latin American influence |
| Thailand | Government agencies | Southeast Asian alignment |
| Pakistan | Government agencies | South Asian strategic position |
SprySOCKS itself represents a mid-tier backdoor in terms of raw functionality, but its true danger lies in its deployment model. Rather than being a flashy, high-signature attack tool, it is designed for sustained, low-noise presence—precisely the attributes required for long-term espionage operations. The addition of Windows support exponentially increases the potential victim base, as Windows remains the dominant operating system in most government and corporate environments.
## Technical Details: The Kernel Driver Evasion Architecture
The WIN_DRV variant employs a sophisticated two-stage kernel driver architecture designed to hide malicious activity at the operating system level:
### Stage One: Driver Loader (fsdiskbit.sys)
The initial encrypted kernel driver, which ESET researchers internally designated as "DriverLoader," serves a single, elegant purpose: to load the second kernel driver directly into kernel memory without leaving detectable traces in the filesystem. This driver is delivered via the SprySOCKS loader component and executes with full kernel privileges.
Key characteristics:
### Stage Two: RawWNPF (Network Activity Concealment)
The second kernel driver, named RawWNPF, performs the critical evasion function. Once loaded into memory, it actively obscures the backdoor's network communication and system activities from:
The driver supports custom configuration options, allowing operators to fine-tune which activities remain hidden based on operational requirements and target environment specifics.
### The Exploitation Chain
1. Initial Compromise (via phishing, supply chain, etc.)
↓
2. SprySOCKS Loader Execution
↓
3. DriverLoader (fsdiskbit.sys) Injection
↓
4. RawWNPF Kernel Driver Load into Memory
↓
5. Backdoor Activity Becomes Invisible to Security ToolsThis architecture represents a privileged-level attack on the security monitoring stack itself. By operating at the kernel level, the malware can intercept and filter security-relevant system calls and network events before they reach userspace logging and detection tools.
## Why Kernel Drivers Represent an Asymmetric Threat
Traditional endpoint security operates at the userspace layer—the unprivileged privilege level where applications normally run. Kernel drivers operate at a higher privilege level and can monitor, intercept, or suppress activity before userspace security software sees it. This creates a fundamental arms race:
Security vendors must:
Adversaries can:
This is why kernel driver abuse has become an increasing focus for advanced threat actors—it provides a near-unbeatable position once successfully deployed.
## Implications for Organizations
### Government and Defense Sectors
Organizations in the targeted regions face an immediate threat assessment requirement. Any government agency that may have been compromised should assume:
### Broader Enterprise Risk
While this campaign primarily targets government entities, the general techniques are applicable to any high-value target:
### The Kernel Driver Problem
This incident demonstrates that kernel driver abuse is not theoretical—it is an active operational reality for advanced threat actors. Organizations relying on endpoint security software cannot assume their tools can detect compromised kernel-level adversaries.
## Recommendations
### For Government and Critical Infrastructure Organizations
1. Conduct Kernel-Level Audits
- Review all loaded kernel drivers and kernel modules for unauthorized additions
- Implement driver code signing verification
- Deploy Secure Boot and UEFI security to restrict unsigned driver loading
2. Assume Breach Posture
- Assume APT actors may have kernel-level access
- Implement detection at network perimeter rather than relying solely on host-based agents
- Deploy network segmentation to contain potential lateral movement
3. Behavioral Analysis
- Monitor for suspicious network communication that a simple EDR might miss
- Use external network monitoring and threat intelligence
- Implement DNS filtering and proxy inspection for encrypted traffic where legally permissible
### For All Organizations
4. Kernel Driver Hygiene
- Maintain whitelist of approved kernel drivers
- Regularly audit loaded drivers on critical systems
- Implement driver certificate pinning where possible
5. Defense in Depth
- Do not rely on a single security vendor's userspace tools
- Implement multiple detection layers (network, endpoint, behavioral, anomaly-based)
- Use threat intelligence to identify known SprySOCKS command-and-control infrastructure
6. Incident Response Preparation
- Develop forensic procedures for kernel-level compromise detection
- Train incident response teams on kernel rootkit analysis
- Maintain offline backups and clean system images for recovery
---
## HackWire Analysis
Why This Matters Now: The Kernel Driver Escalation
This discovery represents a critical inflection point in the cyber-espionage arms race. For nearly a decade, kernel drivers have represented a theoretical future threat. ESET's discovery of SprySOCKS WIN_DRV demonstrates that this future is now operational reality for advanced nation-state actors.
More troubling than the technical capability is the *operational validation*. FishMonger deployed this sophisticated evasion technique against real government targets over an 18-month window (2023-2024) without public detection. This suggests the malware worked reliably in production environments against actual security defenses. For defenders, this means the theoretical advantages of kernel-level evasion have been proven in the field.
The geographic targeting pattern—Honduras, Taiwan, Thailand, Pakistan—reveals strategic intent rather than opportunistic compromise. Each region represents distinct geopolitical interest for the PRC: Taiwan as a direct strategic competitor, Thailand and Pakistan as regional influence zones, and Honduras as a foothold in Latin America. This is not financial cybercrime; this is state-sponsored persistent espionage infrastructure.
The most concerning implication is that government organizations may still be compromised *right now* with no awareness. The malware was active in 2023-2024; the public disclosure is happening in June 2026. That two-year latency suggests organizations may have this backdoor active in their networks with full kernel-level access to system activities and communications.
For enterprise defenders outside the government sector, the critical lesson is this: if FishMonger can maintain an invisible kernel-driver-based backdoor against government security implementations, standard endpoint security alone is insufficient for any high-value target. Organizations must implement kernel-level detection, network-based behavioral analysis, and assume that dedicated adversaries can operate undetected within userspace security tools.
— HackWire Editorial
---
## Related Coverage