#ESETresearch discovered SparroWocky, a new backdoor of the #FamousSparrow APT group. This new malware has quickly replaced SparrowDoor as the 🇨🇳 China-aligned group’s flagship backdoor. https://www.welivesecurity.com/en/eset-research/beware-sparrowock-backdoor-bites-commands-catch/
The switch to SparroWocky happened shortly after FamousSparrow started targeting Latin America almost exclusively, going mainly after governmental entities. This is most probably part of 🇨🇳 China’s reaction to the increased 🇺🇸 US interest in the region.
SparroWocky is a highly modular C++ backdoor built with stealthiness in mind. Its capabilities include collecting general info about the compromised machine, exfiltrating files, and taking screenshots. It can also load and execute BOF (Beacon Object File) files.
With the transition to the new backdoor, FamousSparrow started to incorporate code from open-source projects directly into its malware. Specifically, we noticed that SparroWocky uses Mbed TLS, MinHook, and COFF Loader.
The developers also implemented various anti-analysis techniques: SilentMoonwalk for call spoofing, concealing thread start address from security products using the MinHook library, and a custom PE loader with integrated host process camouflage.
IoCs available in our GitHub repo: https://github.com/eset/malware-ioc/tree/master/famoussparrow
About This Hashtag
#famoussparrow
2 posts
Last used 2d
#famoussparrow
2 posts· Last used 2d
ESET reports China-linked FamousSparrow used the new C++ backdoor SparroWocky against government targets in eight Latin American countries from mid-2025 onward. The focus on stealth and persistence indicates long-term espionage operations against state networks. #FamousSparrow #SparroWocky #CyberEspionage
https://cyberworldops.eu/en/sparrowocky-backdoor-gives-famoussparrow-a-stealthier-foothold-in
You've seen all posts