17-09-2026
Beware the SparroWock: The backdoor that bites, the commands that catch
https://www.welivesecurity.com/en/eset-research/beware-sparrowock-backdoor-bites-commands-catch/
Report completeness: High
Actors/Campaigns:
Ghostemperor (motivation: cyber_espionage)
Threats:
Sparrowocky
Sparrowdoor
Proxylogon_exploit
Dll_sideloading_technique
Coff_loader
Silentmoonwalk_technique
Cobalt_strike_tool
Brc4_tool
Metasploit_tool
Sliver_c2_tool
Process_camouflage_technique
Victims:
Governmental organizations
Industry:
Energy, Telco, Government
Geo:
Peru, Guatemala, Honduras, Panama, China, Latin america, Puerto rico, Venezuela, Ecuador, Argentina
TTPs:
Tactics: 9
Technics: 34
IOCs:
Hash: 5
IP: 18
File: 2
Soft:
MinHook, Windows service
Algorithms:
md5, rc4, sha1, chacha20-poly1305
Functions:
CreateProcessAsUser
Win API:
ExitProcess, FindFirstFileW, WTSEnumerateSessionsW, CreateProcessAsUserW, CreateProcess, RtlUserThreadStart, CreateThread, AnimateWindow, RtlLoadString, RtlFindMessage, have more...
Platforms:
x64
Links:
https://github.com/eset/malware-ioc/tree/master/famoussparrow/extract\_sparrowocky.pyhave more...
https://github.com/Mbed-TLS/mbedtlshttps://github.com/Mbed-TLS/mbedtls/blob/mbedtls-3.6.7/library/poly1305.c#L406