[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fSqrvhK2Bb7EWYPjZrIb23HTPYevMbV8oV0mSjlJlQSo":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":23,"created_at":24,"published_at":25,"article":26,"tags":30,"podcasts":49},"3ff8c099-a4f1-4810-a765-15332084d805","sprysocks-backdoor-uses-kernel-drivers-to-hide-on-windows-systems","56ae72e4-3f77-437a-8b4b-1f7b267a8033","SprySOCKS Backdoor Uses Kernel Drivers to Hide on Windows Systems","Earth Lusca, a China-linked threat actor, has expanded its SprySOCKS backdoor to Windows environments using kernel-level drivers to conceal malicious processes, network connections, files, and registry keys — making traditional endpoint detection significantly harder. The malware abuses legitimate Windows components like the Print Spooler service as an execution vector, demonstrating how attackers exploit trusted system services to evade scrutiny. The use of rootkit-style kernel drivers means standard monitoring tools operating at user-space level may fail to detect active infections. This matters because organizations relying solely on signature-based or surface-level detection are likely blind to this threat class, leaving compromised systems undetected for extended periods.","**Immediate actions:**\n- Audit and restrict kernel driver loading policies using Windows Defender Application Control (WDAC) or Device Guard to block unauthorized drivers.\n- Disable or restrict the Windows Print Spooler service on systems that do not require printing functionality.\n- Deploy threat hunting queries targeting RawWNPF driver artifacts, anomalous TCP diversion, and SprySOCKS IOCs across your environment.\n\n**Detection measures:**\n- Implement kernel-level EDR solutions capable of detecting rootkit behaviors such as hidden processes, registry keys, and network connection cloaking.\n- Enable and centralize Windows Event Logs (System, Security, and Driver Load events) and alert on unsigned or low-prevalence driver installations.\n- Monitor for anomalous outbound TCP connections and unusual Print Spooler service child processes using a SIEM with behavioral analytics.\n\n**Long-term improvements:**\n- Enforce a strict allowlist for kernel drivers using code integrity policies and regularly audit the approved driver inventory.\n- Apply the principle of least privilege to all service accounts, particularly those associated with Windows core services like Print Spooler.\n- Conduct regular adversary simulation exercises targeting living-off-the-land and kernel-level evasion techniques to validate detection coverage.",[12,13,14,15,16,17,18,19,20,21,22],"CIS Control 2: Inventory and Control of Software Assets","CIS Control 10: Malware Defenses","CIS Control 13: Network Monitoring and Defense","NIST SP 800-53 SI-3: Malicious Code Protection","NIST SP 800-53 AU-12: Audit Record Generation","NIST SP 800-53 CM-7: Least Functionality","NIST SP 800-53 SC-7: Boundary Protection","MITRE ATT&CK T1543.003: Create or Modify System Process (Windows Service)","MITRE ATT&CK T1014: Rootkit","MITRE ATT&CK T1599: Network Boundary Bridging","Microsoft Security Baseline: Windows Defender Application Control (WDAC)","published","2026-06-16T19:20:56.801365+00:00","2026-06-16T19:20:56.73+00:00",{"id":7,"url":27,"slug":28,"title":29},"https:\u002F\u002Fthehackernews.com\u002F2026\u002F06\u002Fchina-linked-sprysocks-backdoor-expands.html","china-linked-sprysocks-backdoor-expands-to-windows-with-driver-based-stealth-b433f4","China-Linked SprySOCKS Backdoor Expands to Windows with Driver-Based Stealth",[31,37,43],{"id":32,"name":33,"slug":34,"description":35,"color":36},"05757c8d-6b93-4194-b35d-7359e7d33b0e","Vulnerability Management","vulnerability-management","Missing scans, no risk prioritization","#fb923c",{"id":38,"name":39,"slug":40,"description":41,"color":42},"1732a005-556e-411c-a9db-5edec3058571","Logging & Monitoring","logging-monitoring","Missing logs, no alerting, blind spots","#a855f7",{"id":44,"name":45,"slug":46,"description":47,"color":48},"859cf0ad-a7e9-42bb-a75d-bac6511fa5d5","Configuration Management","configuration-management","Misconfigs, default credentials, exposed services","#eab308",[50],{"id":51,"date":52,"edition":53,"title":54,"audio_url":55},"e22b8429-5dc4-4528-b6a9-5c6947f17903","2026-06-16","afternoon","ThreatNoir Afternoon Brief — June 16","https:\u002F\u002Fcdn.threatnoir.com\u002Fpodcasts\u002F2026-06-16\u002Fthreatnoir-afternoon-brief-2026-06-16.mp3"]