SprySOCKS Backdoor Expands From Linux to Windows

2026-06-16T14:52:18Zbb46cd1c20a42762d3e4fe3a29319b808f40eaf5bfdf4cfba77091a9900cf45c
CVE-2026-11645androidauthentication-bypassbackdoorc2chromecommand-and-controlcyber-espionagedragonforceeuropolexploitation-in-the-wildfbilaw-enforcementlinuxmalwarephpbbqilinransomwarerokarollasprysockssupply-chainthreat-actortrojanwindowswordpress

What happened

A diverse set of active threats and vulnerabilities reported: China-linked SprySOCKS backdoor has developed stealthy Windows variants with 30+ C2 commands, expanding beyond Linux. Other notable incidents include the Rokarolla Android banking/spyware trojan, DragonForce ransomware hiding C2 via a Microsoft Teams visitor token, wide-scale tampering of popular WordPress plugins that backdoored ~1.2M sites, and law‑enforcement takedowns of ransomware crypto‑laundering infrastructure. Multiple high‑impact vulnerabilities are being patched or exploited in the wild (eg. Chrome CVE-2026-11645, a Check

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
infosecurity_magazine
Record identifier
bb46cd1c20a42762d3e4fe3a29319b808f40eaf5bfdf4cfba77091a9900cf45c
Enrichment time
2026-06-16T14:52:18Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.