
ESET discovered two Windows variants of the Linux-only SprySOCKS backdoor, named WIN_DRV and WIN_PLUS. WIN_DRV uses kernel drivers to hide network connections, processes, files, and registry keys. The backdoor supports over 30 commands and is linked to China-nexus threat actor Earth Lusca.
Tap to vote and see what everyone thinks.
Summary by ByteBrief
Ransomware gang abuses Microsoft Teams relays to hide malicious traffic