SprySOCKS Backdoor Expands From Linux to Windows
2026-06-16T14:52:18Z•bb46cd1c20a42762d3e4fe3a29319b808f40eaf5bfdf4cfba77091a9900cf45c
CVE-2026-11645androidauthentication-bypassbackdoorc2chromecommand-and-controlcyber-espionagedragonforceeuropolexploitation-in-the-wildfbilaw-enforcementlinuxmalwarephpbbqilinransomwarerokarollasprysockssupply-chainthreat-actortrojanwindowswordpress
What happened
A diverse set of active threats and vulnerabilities reported: China-linked SprySOCKS backdoor has developed stealthy Windows variants with 30+ C2 commands, expanding beyond Linux. Other notable incidents include the Rokarolla Android banking/spyware trojan, DragonForce ransomware hiding C2 via a Microsoft Teams visitor token, wide-scale tampering of popular WordPress plugins that backdoored ~1.2M sites, and law‑enforcement takedowns of ransomware crypto‑laundering infrastructure. Multiple high‑impact vulnerabilities are being patched or exploited in the wild (eg. Chrome CVE-2026-11645, a Check
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- infosecurity_magazine
- Record identifier
- bb46cd1c20a42762d3e4fe3a29319b808f40eaf5bfdf4cfba77091a9900cf45c
- Enrichment time
- 2026-06-16T14:52:18Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.