Industry stats Updated Aug 2026 All domains worldwide 401.6M registered names +6.4% YoY Verisign · Q2 2026 .com + .net total 179.1M names in zone Verisign · Q2 2026 .com + .net 11.5M newly registered · 76.3% renewed Verisign · Q1 2026 Country-code TLDs 146.3M names +2.4% YoY Verisign · Q1 2026 New gTLDs 49.6M names · 30.9% renewed +3.7% QoQ Verisign · Q1 2026 Legacy gTLDs 20.5M names · 67.6% renewed +14.6% YoY Verisign · Q1 2026 WordPress 41.2% of all sites · 59.1% of CMS sites W3Techs · 1 Aug 2026 Shopify 5.3% of all sites · 7.6% of CMS sites W3Techs · 1 Aug 2026 Wix 4.3% of all sites · 6.1% of CMS sites W3Techs · 1 Aug 2026 Squarespace 2.5% of all sites · 3.5% of CMS sites W3Techs · 1 Aug 2026 Joomla 1.2% of all sites · 1.7% of CMS sites W3Techs · 1 Aug 2026 Webflow 0.8% of all sites · 1.2% of CMS sites W3Techs · 1 Aug 2026 Drupal 0.7% of all sites · 1.1% of CMS sites W3Techs · 1 Aug 2026 No CMS detected 30.4% of all sites W3Techs · 1 Aug 2026 Nginx on 33%–39% of sites W3Techs · Mar–Apr 2026 Apache on 24%–29% of sites W3Techs · Mar–Apr 2026 LiteSpeed gaining share among web servers W3Techs · Mar–Apr 2026 DMARC adoption 937.9K valid records +79% in 3 yrs EasyDMARC · 2026 YTD Fortune 500 95% publish DMARC · 80% enforced EasyDMARC Fortune 500 62.7% use strict reject policy EasyDMARC Inc. 5000 15.2% use strict reject policy EasyDMARC Deal CVC Capital Partners → Namecheap · CVC Capital Partners acquired a majority stake in Namecheap in September 2025, valuing the company at ~$1.5B (including debt). Namecheap reported $398M in revenue for 2024, an 18% year-on-year increase. 2025 Deal team.blue (Hg-backed) → Loopia Group · team.blue acquired Loopia Group in May 2025, expanding its customer base from 2.5M to over 3M entrepreneurs across Europe. Loopia Group operates in Sweden, Finland, Slovakia, Czechia, Hungary, and Serbia, with 320 professionals and ~650,000 customers. 2025 Deal Miss Group (Perwyn-backed) → Web4U s.r.o. · Miss Group acquired Web4U, a Prague-based web hosting and domain registration provider, in 2025. This marked Miss Group’s 14th acquisition under Perwyn ownership and its 22nd acquisition since 2018. Web4U serves 15,000+ customers and reported CZK 38M in revenue for 2021. 2025 Deal group.one → Webglobe · group.one acquired 100% of Webglobe in May 2025, a leading hosting provider in Slovakia, Czechia, and Serbia. Webglobe manages ~300,000 registered domains and registers ~10% of national domains in its core markets. 2025 Deal hosting.com → FastComet, A2 Hosting · hosting.com acquired FastComet in April 2025 and A2 Hosting in January 2025. FastComet serves 32,000 clients across 100 countries, and A2 Hosting was rebranded under the hosting.com name in April 2025, including a $2M purchase of the hosting.com domain. 2025 Industry stats Updated Aug 2026 All domains worldwide 401.6M registered names +6.4% YoY Verisign · Q2 2026 .com + .net total 179.1M names in zone Verisign · Q2 2026 .com + .net 11.5M newly registered · 76.3% renewed Verisign · Q1 2026 Country-code TLDs 146.3M names +2.4% YoY Verisign · Q1 2026 New gTLDs 49.6M names · 30.9% renewed +3.7% QoQ Verisign · Q1 2026 Legacy gTLDs 20.5M names · 67.6% renewed +14.6% YoY Verisign · Q1 2026 WordPress 41.2% of all sites · 59.1% of CMS sites W3Techs · 1 Aug 2026 Shopify 5.3% of all sites · 7.6% of CMS sites W3Techs · 1 Aug 2026 Wix 4.3% of all sites · 6.1% of CMS sites W3Techs · 1 Aug 2026 Squarespace 2.5% of all sites · 3.5% of CMS sites W3Techs · 1 Aug 2026 Joomla 1.2% of all sites · 1.7% of CMS sites W3Techs · 1 Aug 2026 Webflow 0.8% of all sites · 1.2% of CMS sites W3Techs · 1 Aug 2026 Drupal 0.7% of all sites · 1.1% of CMS sites W3Techs · 1 Aug 2026 No CMS detected 30.4% of all sites W3Techs · 1 Aug 2026 Nginx on 33%–39% of sites W3Techs · Mar–Apr 2026 Apache on 24%–29% of sites W3Techs · Mar–Apr 2026 LiteSpeed gaining share among web servers W3Techs · Mar–Apr 2026 DMARC adoption 937.9K valid records +79% in 3 yrs EasyDMARC · 2026 YTD Fortune 500 95% publish DMARC · 80% enforced EasyDMARC Fortune 500 62.7% use strict reject policy EasyDMARC Inc. 5000 15.2% use strict reject policy EasyDMARC Deal CVC Capital Partners → Namecheap · CVC Capital Partners acquired a majority stake in Namecheap in September 2025, valuing the company at ~$1.5B (including debt). Namecheap reported $398M in revenue for 2024, an 18% year-on-year increase. 2025 Deal team.blue (Hg-backed) → Loopia Group · team.blue acquired Loopia Group in May 2025, expanding its customer base from 2.5M to over 3M entrepreneurs across Europe. Loopia Group operates in Sweden, Finland, Slovakia, Czechia, Hungary, and Serbia, with 320 professionals and ~650,000 customers. 2025 Deal Miss Group (Perwyn-backed) → Web4U s.r.o. · Miss Group acquired Web4U, a Prague-based web hosting and domain registration provider, in 2025. This marked Miss Group’s 14th acquisition under Perwyn ownership and its 22nd acquisition since 2018. Web4U serves 15,000+ customers and reported CZK 38M in revenue for 2021. 2025 Deal group.one → Webglobe · group.one acquired 100% of Webglobe in May 2025, a leading hosting provider in Slovakia, Czechia, and Serbia. Webglobe manages ~300,000 registered domains and registers ~10% of national domains in its core markets. 2025 Deal hosting.com → FastComet, A2 Hosting · hosting.com acquired FastComet in April 2025 and A2 Hosting in January 2025. FastComet serves 32,000 clients across 100 countries, and A2 Hosting was rebranded under the hosting.com name in April 2025, including a $2M purchase of the hosting.com domain. 2025
Security Vulnerabilities ESET

SprySOCKS Windows variants target government networks

ESET identifies Windows versions of a Linux backdoor tied to Chinese APT group Earth Lusca, broadening espionage campaigns.

SprySOCKS Windows variants target government networks
Clint Patterson · Unsplash

Security firm ESET has identified Windows-based versions of the SprySOCKS malware, a backdoor previously confined to Linux systems. The malware has been deployed in targeted attacks against government organizations in Taiwan, Thailand, Pakistan, and Honduras, with a focus on foreign affairs, technology, and telecommunications sectors. ESET attributes the campaign to Earth Lusca, a Chinese advanced persistent threat (APT) group also known by aliases including FishMonger, Aquatic Panda, and Red Dev 10.

The discovery highlights the group’s expanding toolset, which now includes kernel-level capabilities designed to conceal malicious activity on compromised systems. While the original Linux variant provided remote access and control, the Windows versions introduce additional evasion techniques to bypass standard detection methods.

How the malware operates

The Windows variants of SprySOCKS appear in two forms: WIN_DRV and WIN_PLUS. Both retain the core functionality of the Linux version, enabling communication over TCP, UDP, and WebSocket protocols, as well as execution of over 30 command-and-control (C2) instructions. The malware can collect system information, manage processes and files, and function as a SOCKS proxy. It also includes keylogging and clipboard monitoring features to capture user activity.

The WIN_DRV variant distinguishes itself by incorporating a kernel driver named RawWNPF, loaded via another driver called DriverLoader (fsdiskbit.sys). This driver, signed with a leaked certificate from the GitHub PastDSE project, allows the malware to hide processes, network connections, files, and Registry keys from security tools. Persistence is maintained through scheduled tasks and Image File Execution Options (IFEO) using the vds.exe process. Additionally, WIN_DRV can redirect incoming TCP traffic to the backdoor without exposing its actual listening port, complicating network-based detection.

In contrast, the WIN_PLUS variant lacks the kernel driver but achieves persistence by registering as a Windows Print Processor. While it omits the advanced stealth features of WIN_DRV, it retains the core backdoor capabilities of the original malware.

Background

Background: SprySOCKS is a backdoor malware initially discovered in Linux environments, designed to grant remote access to infected systems. Earth Lusca, the group behind it, has a history of targeting government and critical infrastructure for espionage purposes. Kernel-level malware operates at the operating system’s lowest layer, making it harder to detect without specialized tools.

Detection and response

ESET’s telemetry suggests a possible link to a UEFI bootkit component, potentially exploiting CVE-2023-24932, a Secure Boot vulnerability previously associated with the BlackLotus UEFI malware. However, ESET has not provided conclusive evidence connecting the two threats. The firm’s report includes indicators of compromise (IoCs) to assist organizations in identifying and mitigating infections.

For professionals

For professionals: Security teams should monitor for unusual kernel driver activity, particularly drivers signed with leaked or suspicious certificates. Network traffic analysis should account for potential diversion techniques, such as unexpected TCP port usage. Updating detection rules in SIEM and EDR systems with the provided IoCs can help identify compromised systems early.

The emergence of Windows variants demonstrates Earth Lusca’s efforts to broaden its attack surface. Organizations in sectors frequently targeted by state-sponsored actors should adopt multi-layered defense strategies to counter evolving threats.

What to watch

Government, technology, and telecommunications entities should remain alert for signs of Earth Lusca activity. The group’s use of kernel-level techniques and traffic diversion indicates a focus on long-term persistence and evasion. Future developments may involve further exploitation of UEFI vulnerabilities or additional stealth mechanisms. Security teams are advised to review ESET’s technical analysis and integrate the provided IoCs into their threat detection frameworks.

Companies mentioned

ESET

Discussion · coming soon

Be the first to join the thread when community discussion launches.