/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Trend Micro: Chinese cyberespionage group Earth Lusca used a new Linux malware dubbed SprySOCKS to target government agencies in multiple countries in H1 2023

A Chinese espionage-focused hacker tracked as ‘Earth Lusca’ was observed targeting government agencies in multiple countries, using a new Linux backdoor dubbed ‘SprySOCKS.’

BleepingComputer Bill Toulas

Context & Ripple Effects

This report adds a Linux-specific backdoor to a coverage trail of government-focused intrusion activity: Lancefly’s custom-malware campaign against Asian governments and telecoms was reported earlier in 2023, while later research described another China-linked campaign, Earth Krahang, reaching organizations across many countries.

The significance is less the name of one tool than the targeting pattern: government agencies are being pursued with tailored malware across operating environments, rather than through a single platform or sector.

First-order effects

  • Government agencies targeted by Earth Lusca need to investigate Linux hosts for SprySOCKS activity and reassess exposure to the group’s access paths.
  • Earth Lusca gains a purpose-built Linux option for operations against public-sector targets, broadening the malware it can deploy in these campaigns.

Second-order effects

  • Public-sector defenders and incident-response teams are pushed to give Linux telemetry and backdoor detection the same priority as endpoint coverage on other systems.
  • The finding reinforces demand for cross-platform threat intelligence; it follows reporting on malware able to compromise Windows, macOS, and Linux devices through router-focused activity.

Third-order effects

  • If campaigns continue to add platform-specific tooling, government cyber defense will increasingly be judged on coverage across heterogeneous estates, not just protection of dominant desktop endpoints.
  • The broader pattern points to a more durable ecosystem-defense challenge: espionage operators can vary malware and infrastructure while retaining the same public-sector targeting objective.

The trend: State-linked cyberespionage is moving toward more adaptable, cross-platform toolsets that test whether government defenses can see and respond across their full technology estate.

Discussion

  • @arstechnica@mastodon.social @arstechnica@mastodon.social on mastodon
    Never-before-seen Linux backdoor is a Windows malware knockoff  —  SprySOCKS borrows from open source Windows malware and adds new tricks.  —  https://arstechnica.com/...  [image]
  • @780thc @780thc on x
    In this report, @TrendMicro discusses the new backdoor SprySOCKS used by Earth Lusca, a China-linked threat actor, which expands the group's Linux arsenal. https://www.trendmicro.com/...
  • r/technews r on reddit
    Chinese hackers have unleashed a never-before-seen Linux backdoor
  • r/hacking r on reddit
    Chinese hackers have unleashed a never-before-seen Linux backdoor