#ESETresearch discovered SparroWocky, a new backdoor of the #FamousSparrow APT group. This new malware has quickly replaced SparrowDoor as the 🇨🇳 China-aligned group’s flagship backdoor. https://www.welivesecurity.com/en/eset-research/beware-sparrowock-backdoor-bites-commands-catch/
The switch to SparroWocky happened shortly after FamousSparrow started targeting Latin America almost exclusively, going mainly after governmental entities. This is most probably part of 🇨🇳 China’s reaction to the increased 🇺🇸 US interest in the region.
SparroWocky is a highly modular C++ backdoor built with stealthiness in mind. Its capabilities include collecting general info about the compromised machine, exfiltrating files, and taking screenshots. It can also load and execute BOF (Beacon Object File) files.
With the transition to the new backdoor, FamousSparrow started to incorporate code from open-source projects directly into its malware. Specifically, we noticed that SparroWocky uses Mbed TLS, MinHook, and COFF Loader.
The developers also implemented various anti-analysis techniques: SilentMoonwalk for call spoofing, concealing thread start address from security products using the MinHook library, and a custom PE loader with integrated host process camouflage.
IoCs available in our GitHub repo: https://github.com/eset/malware-ioc/tree/master/famoussparrow
About This Hashtag
#esetresearch
3 posts
Last used 2d
#esetresearch
3 posts· Last used 2d
In H1 2026, #ESETresearch analyzed 900,000 agentic AI skills – add-ons providing instructions that teach agents how to perform specific tasks – and found 25,000 suspicious ones and more than 3,000 outright malicious.
Many of the malicious AI skills were designed to perform red-teaming actions, such as attacking Active Directory, enumerating data, exfiltrating credentials, or gaining highly privileged, persistent access.
Their instructions referenced external offensive security tools and platforms such as Impacket, Mimikatz, or BloodHound. In other words, some AI skills do not just “help” an agent – they can steer it toward offensive behavior.
One skill, labeled by ESET as suspicious, was instructed to create a persistence mechanism via a JSON file and a tool for self-modification in Python. While this can improve the skill, it can also lead to unpredictable agent behavior or abuse by an attacker.
Even some benign skills are problematic, such as those marked as security scanners, many of which implement basic techniques, resembling AV tools from the 1990s: catching obvious threats, but offering little protection against complex, emerging, or obfuscated attacks.
Read more about the growing attack surface of agentic AI in H1 2026 ESET Threat Report https://web-assets.esetstatic.com/wls/en/papers/threat-reports/eset-threat-report-h12026.pdf
In H1 2026, #ESETresearch continued tracking a growing number of #EDR killers, currently counting 100+ such tools. The dominant approach is still BYOVD, with 60+ of the EDR killers abusing legitimate yet vulnerable drivers.
We expect those numbers to keep growing, as threat actors can weaponize any of thousands of available vulnerable drivers – some with public PoC exploits – while leveraging AI coding tools to adapt them, giving them a virtually endless supply.
The report also details #ESETresearch findings from the Gentlemen leak. We found the gang uses a shared defense-evasion layer across its EDR killer suite – spanning in-house GentleKiller, third-party, and leaked tools – and can operationalize new BYOVD PoCs within days.
While ransomware gangs are ramping up attacks (+50% YoY) only a minority of victims are willing to pay, with public reports putting that figure at just 14–28%. The total sum of ransom payments is also trending down, falling 8% from 2024 to 2025.
For more on developments across the ransomware scene in H1 2026 – including gang infighting and successes in the fight against the gangs – read the full report: https://web-assets.esetstatic.com/wls/en/papers/threat-reports/eset-threat-report-h12026.pdf
You've seen all posts