ESET Research: China-aligned FishMonger updates its arsenal, targets governments in Asia and Latin America
· eset, llc
Source Summary
BRATISLAVA, June 16, 2026 (GLOBE NEWSWIRE) -- ESET researchers have discovered two as-yet undocumented Windows variants (WIN_DRV and WIN_PLUS) of SprySOCKS, a previously Linux-only backdoor reportedly used by FishMonger, the group believed to be operated by a Chinese contractor named I-SOON. While ESET initially discovered the malware samples on VirusTotal uploaded in April 2024, ESET telemetry shows real activity between 2023 and 2024, with several victims in Honduras, Taiwan, Thailand, and Pakistan, targeting mostly government organizations.
Advertisement