#famoussparrow

2 posts· Last used 2d

#ESETresearch discovered SparroWocky, a new backdoor of the #FamousSparrow APT group. This new malware has quickly replaced SparrowDoor as the 🇨🇳 China-aligned group’s flagship backdoor. https://www.welivesecurity.com/en/eset-research/beware-sparrowock-backdoor-bites-commands-catch/ The switch to SparroWocky happened shortly after FamousSparrow started targeting Latin America almost exclusively, going mainly after governmental entities. This is most probably part of 🇨🇳 China’s reaction to the increased 🇺🇸 US interest in the region. SparroWocky is a highly modular C++ backdoor built with stealthiness in mind. Its capabilities include collecting general info about the compromised machine, exfiltrating files, and taking screenshots. It can also load and execute BOF (Beacon Object File) files. With the transition to the new backdoor, FamousSparrow started to incorporate code from open-source projects directly into its malware. Specifically, we noticed that SparroWocky uses Mbed TLS, MinHook, and COFF Loader. The developers also implemented various anti-analysis techniques: SilentMoonwalk for call spoofing, concealing thread start address from security products using the MinHook library, and a custom PE loader with integrated host process camouflage. IoCs available in our GitHub repo: https://github.com/eset/malware-ioc/tree/master/famoussparrow
5
0
4
1
You've seen all posts