Windows variants for the SprySOCKS Linux malware have been used in attacks targeting government organizations in at least four countries.

Windows variants for the SprySOCKS Linux malware have been used in attacks targeting government organizations in at least four countries.

ESET found two Windows SprySOCKS variants with 30+ commands, C2 over TCP, UDP, and WebSocket, and government targets in 4 countries.

FishMonger, a China-nexus threat group, has deployed an undocumented version of the Linux backdoor against government targets in several countries.