Skip to main content

Beware the SparroWock: The backdoor that bites, the commands that catch

0
Medium
Published: 09/17/2026 (09/17/2026, 16:19:02 UTC)
Source: AlienVault OTX General

Description

SparroWocky is a sophisticated C++ backdoor used by the China-aligned FamousSparrow APT group since August 2025. It targets governmental organizations in Latin America, replacing the group's previous SparrowDoor backdoor. The malware features advanced evasion techniques such as reflective loading, call stack spoofing (SilentMoonwalk), and encrypted communications using TLS and RC4. It also incorporates open-source projects and uses modular components including Beacon Object Files. The backdoor employs API hooking and custom PE loading to camouflage itself within host processes. This campaign aligns with China's strategic interest in monitoring Latin American governmental responses to US pressures on investments and infrastructure.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/18/2026, 09:01:30 UTC

Technical Analysis

ESET researchers documented SparroWocky, a modular and sophisticated C++ backdoor deployed by the FamousSparrow APT group since August 2025. This malware replaces the previous SparrowDoor backdoor and targets Latin American governmental organizations. SparroWocky uses advanced techniques such as reflective loading, SilentMoonwalk call stack spoofing, and execution of Beacon Object Files. It integrates open-source code directly, communicates over TLS with RC4 encryption for data exfiltration, and employs evasion methods including MinHook API hooking and custom PE loading with host process camouflage. The targeting reflects geopolitical motivations tied to China's interest in Latin America amid US regional pressures.

Potential Impact

The backdoor enables persistent, stealthy access to targeted governmental networks in Latin America, facilitating espionage activities. Its advanced evasion and encryption techniques hinder detection and analysis, increasing the difficulty of incident response. The modular design allows flexible execution of additional payloads, potentially expanding the scope of compromise. While no active exploits in the wild are reported, the threat actor's focus on sensitive government targets indicates a medium-level espionage risk.

Defensive Guidance

No specific patch or remediation is available as this is malware deployed by a threat actor. Defenders should focus on detection and response capabilities tailored to the described techniques, such as monitoring for reflective loading, API hooking, and unusual TLS traffic with RC4 encryption. Employing threat intelligence to identify Indicators of Compromise (IoCs) related to SparroWocky and FamousSparrow is recommended. Network segmentation and endpoint protection with behavioral analysis may help mitigate impact. There is no vendor advisory or official fix for this malware.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Author
AlienVault
Tlp
white
References
["https://www.welivesecurity.com/en/eset-research/beware-sparrowock-backdoor-bites-commands-catch/"]
Adversary
GhostEmperor
Pulse Id
6aac12f6c8ffca0418768251

Indicators of Compromise

Ip

ValueDescriptionCopy
ip27.102.113.240
ip103.85.25.166
ip38.60.224.51
ip45.131.179.24
ip43.254.216.195
ip38.54.57.17
ip38.60.197.55
ip38.60.209.106
ip38.60.224.235
ip38.60.241.65
ip38.60.241.127
ip38.60.241.193
ip130.94.101.82
ip149.104.87.228
ip149.104.90.203

Hash

ValueDescriptionCopy
hash23e228d5603b4802398b2e7419187aef71ff9dd5
hash2560b7e28b322bb7a56d0b1da1b2652e1efe76ea
hash4df896624695ea2780552e9ea3c40661dc84efc8
hash76c430b55f180a85f4e1a1e40e4a2ea37db97599
hash873f98caf234c3a8a9db18343dad7b42117e85d4
hashb9601e60f87545441bf8579b2f62668c56507f4a
hashbb2f5b573ac7a761015daad0b7ff03b294dc60f6
hashc36ecd2e0f38294e1290f4b9b36f602167e33614
hashe2b0851e2e281cc7bca3d6d9b2fa0c4b7ac5a02b
hashfdc44057e87d7c350e6df84bb72541236a770ba2
hash0dc20b2f11118d5c0cc46b082d7f5dc060276157
hashf35ce62abeedfb8c6a38ceac50a250f48c41e65e
hash0925f24082971f50edd987d82f708845a6a9d7c9
hash1b06e877c2c12d74336e7532bc0ecf761e5fa5d4
hash3a395daaf518be113fcff2e5e48acd9b9c0de69d
hash5265e8edc9b5f7dd00fc772522511b8f3be217e3
hash5df3c882db6be14887182b7439b72a86bd28b83f
hash5f1553f3af9425ef5d68341e991b6c5ec96a82eb
hash7d66b550ea68a86fcc0958e7c159531d4431b788
hasha91b42e5062fef608f285002debaff9358162b25
hashaa823148eea6f43d8eb9bf20412402a7739d91c2
hashc26f04790c6fb7950d89ab1b08207ace01efb536
hashcc350ba25947b7f9ec5d11ea8269407c0fd74095
hashd03fd329627a58b40e805f4f55b5d821063ac27f
hashd6d32a1f17d48fe695c0778018c0d51626db4a3b
hashdb1591c6e23160a94f6312ca46da2d0bb243322c
hashebc93a546bcdf6cc1eb61d7174bcb85407bbd892
hashef189737fb7d61b110b9293e8838526dce920127
hash44f0a22b143b79fa760bf31e14c8fff714c8a2a1
hash922c1edb47fba94b548edca863165fb1
hashe0b6f8535e19f0a4938e3317de0c4493ecea17aa906fd0454805ba2086cbf3a8

Domain

ValueDescriptionCopy
domaincredits.offices-analytics.com
domainamelicen.com

Threat ID: 6aacfa7155bf5e2cf5c39c77

Added to database: 09/18/2026, 08:46:41 UTC

Last enriched: 09/18/2026, 09:01:30 UTC

Last updated: 09/18/2026, 09:12:09 UTC

Views: 5

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses