# SprySOCKS Backdoor Expands to Windows: Chinese APT Earth Lusca Deploys Advanced Rootkit Variants Targeting Government Organizations Across Four Countries
Government organizations in Taiwan, Thailand, Pakistan, and Honduras are facing a significant new threat from a Chinese-linked threat actor. Researchers at ESET have discovered Windows variants of SprySOCKS, a sophisticated backdoor malware family previously known primarily for its Linux targeting, being wielded by the Earth Lusca APT group in attacks spanning 2023 to 2024. The Windows versions introduce advanced kernel-level stealth capabilities that dramatically increase the difficulty of detection and remediation—a critical evolution in this threat actor's capabilities and an indicator that government networks worldwide face an expanding and increasingly sophisticated attack surface.
## The Threat: SprySOCKS Evolves to Windows
SprySOCKS is not a new malware family. Its initial notoriety came from deployment by Earth Lusca—a Chinese state-sponsored threat group tracked under multiple identities including FishMonger, Aquatic Panda, Red Dev 10, and TAG-22—primarily targeting Linux systems. The malware functions as a full-featured remote access backdoor, providing operators with extensive command-and-control capabilities and system manipulation functions.
What makes the Windows variant discovery significant is not the existence of a port itself, but rather the sophistication of the implementation. Unlike the Linux version, the Windows variants of SprySOCKS introduce kernel-level rootkit-like functionality that fundamentally changes the threat landscape. ESET researchers identified two distinct Windows variants with increasing levels of functionality:
| Variant | Key Characteristic | Primary Persistence Method |
|---------|-------------------|---------------------------|
| WIN_PLUS | Streamlined backdoor with basic capabilities | Windows Print Processor (VSPMsg) |
| WIN_DRV | Advanced kernel driver with rootkit stealth | Scheduled tasks, IFEO via vds.exe |
Both variants support more than 30 command-and-control commands, enabling comprehensive system manipulation and intelligence gathering.
## Background and Context: A Known Threat Actor Expands Reach
Earth Lusca has a well-documented history of targeting government networks, with particular interest in organizations handling foreign affairs, technology policy, and telecommunications. The discovery of Windows variants suggests a calculated strategic expansion by the group—rather than developing entirely new malware, they adapted an existing proven tool to reach victims operating heterogeneous environments with both Linux and Windows systems.
The use of Windows variants between 2023 and 2024 indicates this activity has been unfolding for over two years without widespread public visibility. This gap between deployment and discovery is troubling: it suggests Windows-based victims may remain undetected or unaware of compromise.
The geographic targeting pattern—Taiwan, Thailand, Pakistan, and Honduras—aligns with Earth Lusca's historical focus on Asia-Pacific government entities and broader geopolitical interests. Each of these countries sits at strategically important intersections of technology policy, trade relationships, or regional influence.
## Technical Details: Advanced Stealth and Persistence
The Windows variants of SprySOCKS introduce several sophisticated technical capabilities that elevate the threat:
### Kernel-Level Stealth Capabilities
The WIN_DRV variant includes kernel drivers designed to operate at the operating system level—below the visibility of standard security tools and user-mode monitoring. The attack chain involves:
1. DriverLoader (fsdiskbit.sys): A signed kernel driver used to load the primary rootkit component
2. RawWNPF Driver: Loaded directly into kernel memory, providing core stealth functionality
3. Signed Certificate Abuse: The DriverLoader is signed using a leaked certificate from the GitHub PastDSE project, allowing it to load as a legitimate driver
Once loaded, these kernel components enable the malware to:
### Advanced Command-and-Control Architecture
Both variants support TCP, UDP, and WebSocket communication channels, offering flexibility in network environments. The TCP traffic redirection capability is particularly noteworthy: it allows Earth Lusca operators to send commands through traffic redirected from random TCP ports without exposing the actual listening port. This makes network-based detection significantly more challenging.
The 30+ supported C2 commands provide extensive operational capabilities:
### Persistence Mechanisms
The malware employs multiple persistence techniques to maintain footing after initial compromise:
Each method provides redundancy—if one persistence mechanism is discovered and removed, others remain active.
### Unconfirmed UEFI Bootkit Component
ESET telemetry indicated possible presence of a UEFI bootkit component, potentially exploiting CVE-2023-24932, a Secure Boot vulnerability previously weaponized by the BlackLotus UEFI malware. However, ESET noted insufficient evidence to definitively link SprySOCKS to this component. If confirmed, this would represent a critical escalation—UEFI-level persistence is extraordinarily difficult to detect and remove, requiring expertise and tools beyond standard endpoint security.
## Implications: A Government-Targeted Threat With Global Reach
The Windows variant discovery carries several immediate implications:
Detection Evasion: Organizations relying on user-mode endpoint detection and response (EDR) tools may find themselves blind to WIN_DRV activity. Kernel-level drivers operate below the visibility threshold of standard security tools.
Dwell Time Risk: The 2023-2024 deployment window suggests organizations may have been compromised for extended periods without detection. Government entities operating espionage-focused networks require assumption of potential breach.
Lateral Movement: The SOCKS proxy capabilities enable compromised systems to serve as springboards for deeper network penetration. A single Windows workstation can become a beachhead for targeting network infrastructure, databases, and communication systems.
Intelligence Collection: Keystroke logging, clipboard monitoring, and window title capture provide ongoing intelligence on sensitive communications, policy documents, and organizational communications.
Supply Chain Considerations: The use of a leaked certificate for driver signing suggests Earth Lusca maintains access to development artifacts or code-signing infrastructure, raising broader supply chain security concerns.
## Recommendations: Defensive Posture for Government Organizations
Government organizations, particularly those in targeted regions and sectors, should prioritize the following actions:
1. Kernel-Level Detection: Deploy endpoint solutions capable of kernel-level visibility and monitoring, not just user-mode detection
2. Hunt for Indicators of Compromise: ESET's report provides detailed indicators. Organizations should conduct immediate threat hunting using the IOCs against network logs, endpoint telemetry, and memory forensics
3. Credential Audit: Assume compromise and implement credential rotation protocols for systems that may have been exposed
4. Network Segmentation: Isolate critical systems and enforce microsegmentation to limit lateral movement capability
5. UEFI Audits: Check for evidence of bootkit exploitation; ensure firmware is patched against CVE-2023-24932
6. EDR Enhancement: Evaluate EDR solutions for kernel-level detection capabilities; traditional user-mode tools are insufficient against this threat
7. Incident Response Preparation: Develop and test incident response procedures specific to rootkit-level compromise, which requires forensic expertise beyond standard procedures
## HackWire Analysis
The SprySOCKS Windows variant discovery underscores a critical blind spot in government cybersecurity: the assumption that tool diversity (Windows, Linux, etc.) inherently provides security. In reality, it expands the attack surface and requires defenders to maintain parity across platforms. Earth Lusca's strategy of adapting proven Linux malware to Windows suggests a pragmatic, evolutionary approach rather than reckless innovation—they're exploiting what works.
What's particularly concerning is the timeline. These Windows variants operated for over 18 months before disclosure. This isn't unusual for advanced persistent threats targeting governments, but it reveals the gap between detection and deployment. Organizations running mixed Windows/Linux environments face a compounded problem: they must defend both, but breaches in either can compromise both. The kernel-level stealth capabilities raise the bar substantially—traditional EDR and endpoint monitoring are insufficient.
The leaked certificate used to sign the malware drivers warrants investigation. If Earth Lusca has sustained access to stolen code-signing infrastructure, this represents a broader supply chain vulnerability that extends beyond SprySOCKS to potential future campaigns. The possible UEFI bootkit component, while unconfirmed, hints at capabilities that would survive reinstallation of the operating system—a nightmare scenario for remediation.
For government organizations in targeted regions: treat this as a confirmed threat on your networks until proven otherwise. The specificity of targeting (Taiwan, Thailand, Pakistan, Honduras) suggests Earth Lusca's operations are precisely calibrated to geopolitical objectives. If your organization handles diplomatic, technology policy, or telecommunications matters, you are likely in scope.
— HackWire Editorial
## Related Coverage