Executive Summary
In 2023 and 2024, the China-linked cyber-espionage group FishMonger, also known as Earth Lusca and Aquatic Panda, deployed a Windows variant of the SprySOCKS backdoor against government organizations in Honduras, Taiwan, Thailand, and Pakistan. This variant utilizes malicious kernel drivers to evade detection, allowing the backdoor to conceal its processes and files by intercepting system calls and modifying outputs. The attackers likely gained initial access through exploiting vulnerabilities in public-facing servers.
The emergence of this Windows variant underscores the evolving tactics of nation-state actors in enhancing malware stealth capabilities. Organizations should be vigilant about the use of kernel drivers in malware, as they pose significant challenges to detection and mitigation efforts.
Why This Matters Now
The deployment of kernel-level malware by state-sponsored actors highlights the urgent need for organizations to implement advanced security measures capable of detecting and mitigating such sophisticated threats.
Attack Path Analysis
The FishMonger APT group exploited unpatched public-facing applications to gain initial access to government networks. They escalated privileges by deploying malicious kernel drivers, allowing them to conceal their activities. Utilizing these drivers, they moved laterally across systems undetected. The backdoor established command and control channels over TCP and UDP protocols. Sensitive data was exfiltrated through these covert channels. The attack resulted in significant data breaches and potential operational disruptions.
Kill Chain Progression
Initial Compromise
Description
Exploited unpatched public-facing applications to gain initial access.
Related CVEs
CVE-2026-34332
CVSS 8Use after free in Windows Kernel-Mode Drivers allows an authorized attacker to execute code over a network.
Affected Products:
Microsoft Windows Server 2025 – < 10.0.26100.32772
Exploit Status:
no public exploit
MITRE ATT&CK® Techniques
Kernel Modules and Extensions
Kernel Modules and Extensions
Bypass User Account Control
Masquerading
Token Impersonation/Theft
Windows Service
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Ensure all system components and software are protected from known vulnerabilities
Control ID: 6.2
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Risk Management Framework
Control ID: Article 5
CISA ZTMM 2.0 – Device Security
Control ID: Pillar 3: Devices
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Government Administration
FishMonger APT directly targeted government organizations in Honduras, Taiwan, Thailand, and Pakistan using kernel driver-enabled SprySOCKS backdoor for advanced persistent espionage operations.
Information Technology/IT
SprySOCKS Windows variant exploits N-day vulnerabilities on public-facing servers, requiring enhanced egress security, zero trust segmentation, and kernel-level threat detection capabilities.
Computer/Network Security
Malicious kernel drivers evade detection by hooking system calls and hiding processes, necessitating hypervisor-protected code integrity and advanced anomaly detection mechanisms.
Telecommunications
China-nexus threat group's encrypted traffic capabilities and command-and-control infrastructure pose significant risks to telecommunications networks requiring enhanced east-west traffic security monitoring.
Sources
- SprySOCKS Windows Variant Abuses Kernel Drivers to Evade Detectionhttps://www.darkreading.com/threat-intelligence/sprysocks-windows-variant-kernel-driversVerified
- ESET’s research into 'Bring Your Own Vulnerable Driver' details attacks on drivers in Windows’ corehttps://www.eset.com/uk/about/newsroom/press-releases/eset-research-into-bring-your-own-vulnerable-driver/Verified
- NVD - CVE-2026-34332https://nvd.nist.gov/vuln/detail/CVE-2026-34332Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF is pertinent to this incident as it could have constrained the FishMonger APT group's ability to exploit unpatched applications, escalate privileges, move laterally, establish command and control channels, and exfiltrate sensitive data, thereby reducing the attack's overall impact.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: The attacker's ability to exploit unpatched public-facing applications may have been constrained, reducing the likelihood of initial access.
Control: Zero Trust Segmentation
Mitigation: The attacker's ability to escalate privileges and conceal activities may have been constrained, reducing the scope of unauthorized access.
Control: East-West Traffic Security
Mitigation: The attacker's ability to move laterally across systems undetected may have been constrained, reducing the reach of the attack.
Control: Multicloud Visibility & Control
Mitigation: The attacker's ability to establish command and control channels over TCP and UDP protocols may have been constrained, reducing the effectiveness of remote control.
Control: Egress Security & Policy Enforcement
Mitigation: The attacker's ability to exfiltrate sensitive data through covert channels may have been constrained, reducing the volume of data loss.
The overall impact of the attack, including data breaches and operational disruptions, may have been constrained, reducing the severity of the incident.
Impact at a Glance
Affected Business Functions
- Government Communications
- National Security Operations
- Public Administration
Estimated downtime: 7 days
Estimated loss: $500,000
Classified government documents and communications
Recommended Actions
Key Takeaways & Next Steps
- • Implement regular patch management to address vulnerabilities in public-facing applications.
- • Deploy Zero Trust Segmentation to limit lateral movement within the network.
- • Utilize East-West Traffic Security to monitor and control internal traffic flows.
- • Establish Multicloud Visibility & Control to detect and respond to command and control activities.
- • Enforce Egress Security & Policy Enforcement to prevent unauthorized data exfiltration.



