Beware the SparroWock: The backdoor that bites, the commands that catch
SparroWocky is a sophisticated C++ backdoor used by the China-aligned FamousSparrow APT group since August 2025. It targets governmental organizations in Latin America, replacing the group's previous SparrowDoor backdoor. The malware features advanced evasion techniques such as reflective loading, call stack spoofing (SilentMoonwalk), and encrypted communications using TLS and RC4. It also incorporates open-source projects and uses modular components including Beacon Object Files. The backdoor employs API hooking and custom PE loading to camouflage itself within host processes. This campaign aligns with China's strategic interest in monitoring Latin American governmental responses to US pressures on investments and infrastructure.
AI Analysis
Technical Summary
ESET researchers documented SparroWocky, a modular and sophisticated C++ backdoor deployed by the FamousSparrow APT group since August 2025. This malware replaces the previous SparrowDoor backdoor and targets Latin American governmental organizations. SparroWocky uses advanced techniques such as reflective loading, SilentMoonwalk call stack spoofing, and execution of Beacon Object Files. It integrates open-source code directly, communicates over TLS with RC4 encryption for data exfiltration, and employs evasion methods including MinHook API hooking and custom PE loading with host process camouflage. The targeting reflects geopolitical motivations tied to China's interest in Latin America amid US regional pressures.
Potential Impact
The backdoor enables persistent, stealthy access to targeted governmental networks in Latin America, facilitating espionage activities. Its advanced evasion and encryption techniques hinder detection and analysis, increasing the difficulty of incident response. The modular design allows flexible execution of additional payloads, potentially expanding the scope of compromise. While no active exploits in the wild are reported, the threat actor's focus on sensitive government targets indicates a medium-level espionage risk.
Mitigation Recommendations
No specific patch or remediation is available as this is malware deployed by a threat actor. Defenders should focus on detection and response capabilities tailored to the described techniques, such as monitoring for reflective loading, API hooking, and unusual TLS traffic with RC4 encryption. Employing threat intelligence to identify Indicators of Compromise (IoCs) related to SparroWocky and FamousSparrow is recommended. Network segmentation and endpoint protection with behavioral analysis may help mitigate impact. There is no vendor advisory or official fix for this malware.
Indicators of Compromise
- ip: 27.102.113.240
- ip: 103.85.25.166
- hash: 23e228d5603b4802398b2e7419187aef71ff9dd5
- hash: 2560b7e28b322bb7a56d0b1da1b2652e1efe76ea
- hash: 4df896624695ea2780552e9ea3c40661dc84efc8
- hash: 76c430b55f180a85f4e1a1e40e4a2ea37db97599
- hash: 873f98caf234c3a8a9db18343dad7b42117e85d4
- hash: b9601e60f87545441bf8579b2f62668c56507f4a
- hash: bb2f5b573ac7a761015daad0b7ff03b294dc60f6
- hash: c36ecd2e0f38294e1290f4b9b36f602167e33614
- hash: e2b0851e2e281cc7bca3d6d9b2fa0c4b7ac5a02b
- hash: fdc44057e87d7c350e6df84bb72541236a770ba2
- domain: credits.offices-analytics.com
- hash: 0dc20b2f11118d5c0cc46b082d7f5dc060276157
- hash: f35ce62abeedfb8c6a38ceac50a250f48c41e65e
- hash: 0925f24082971f50edd987d82f708845a6a9d7c9
- ip: 38.60.224.51
- hash: 1b06e877c2c12d74336e7532bc0ecf761e5fa5d4
- hash: 3a395daaf518be113fcff2e5e48acd9b9c0de69d
- hash: 5265e8edc9b5f7dd00fc772522511b8f3be217e3
- hash: 5df3c882db6be14887182b7439b72a86bd28b83f
- hash: 5f1553f3af9425ef5d68341e991b6c5ec96a82eb
- hash: 7d66b550ea68a86fcc0958e7c159531d4431b788
- hash: a91b42e5062fef608f285002debaff9358162b25
- hash: aa823148eea6f43d8eb9bf20412402a7739d91c2
- hash: c26f04790c6fb7950d89ab1b08207ace01efb536
- hash: cc350ba25947b7f9ec5d11ea8269407c0fd74095
- hash: d03fd329627a58b40e805f4f55b5d821063ac27f
- hash: d6d32a1f17d48fe695c0778018c0d51626db4a3b
- hash: db1591c6e23160a94f6312ca46da2d0bb243322c
- hash: ebc93a546bcdf6cc1eb61d7174bcb85407bbd892
- hash: ef189737fb7d61b110b9293e8838526dce920127
- ip: 45.131.179.24
- domain: amelicen.com
- ip: 43.254.216.195
- hash: 44f0a22b143b79fa760bf31e14c8fff714c8a2a1
- ip: 38.54.57.17
- ip: 38.60.197.55
- ip: 38.60.209.106
- ip: 38.60.224.235
- ip: 38.60.241.65
- ip: 38.60.241.127
- ip: 38.60.241.193
- ip: 130.94.101.82
- ip: 149.104.87.228
- ip: 149.104.90.203
- hash: 922c1edb47fba94b548edca863165fb1
- hash: e0b6f8535e19f0a4938e3317de0c4493ecea17aa906fd0454805ba2086cbf3a8
Beware the SparroWock: The backdoor that bites, the commands that catch
Description
SparroWocky is a sophisticated C++ backdoor used by the China-aligned FamousSparrow APT group since August 2025. It targets governmental organizations in Latin America, replacing the group's previous SparrowDoor backdoor. The malware features advanced evasion techniques such as reflective loading, call stack spoofing (SilentMoonwalk), and encrypted communications using TLS and RC4. It also incorporates open-source projects and uses modular components including Beacon Object Files. The backdoor employs API hooking and custom PE loading to camouflage itself within host processes. This campaign aligns with China's strategic interest in monitoring Latin American governmental responses to US pressures on investments and infrastructure.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
ESET researchers documented SparroWocky, a modular and sophisticated C++ backdoor deployed by the FamousSparrow APT group since August 2025. This malware replaces the previous SparrowDoor backdoor and targets Latin American governmental organizations. SparroWocky uses advanced techniques such as reflective loading, SilentMoonwalk call stack spoofing, and execution of Beacon Object Files. It integrates open-source code directly, communicates over TLS with RC4 encryption for data exfiltration, and employs evasion methods including MinHook API hooking and custom PE loading with host process camouflage. The targeting reflects geopolitical motivations tied to China's interest in Latin America amid US regional pressures.
Potential Impact
The backdoor enables persistent, stealthy access to targeted governmental networks in Latin America, facilitating espionage activities. Its advanced evasion and encryption techniques hinder detection and analysis, increasing the difficulty of incident response. The modular design allows flexible execution of additional payloads, potentially expanding the scope of compromise. While no active exploits in the wild are reported, the threat actor's focus on sensitive government targets indicates a medium-level espionage risk.
Defensive Guidance
No specific patch or remediation is available as this is malware deployed by a threat actor. Defenders should focus on detection and response capabilities tailored to the described techniques, such as monitoring for reflective loading, API hooking, and unusual TLS traffic with RC4 encryption. Employing threat intelligence to identify Indicators of Compromise (IoCs) related to SparroWocky and FamousSparrow is recommended. Network segmentation and endpoint protection with behavioral analysis may help mitigate impact. There is no vendor advisory or official fix for this malware.
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://www.welivesecurity.com/en/eset-research/beware-sparrowock-backdoor-bites-commands-catch/"]
- Adversary
- GhostEmperor
- Pulse Id
- 6aac12f6c8ffca0418768251
Indicators of Compromise
Ip
| Value | Description | Copy |
|---|---|---|
ip27.102.113.240 | — | |
ip103.85.25.166 | — | |
ip38.60.224.51 | — | |
ip45.131.179.24 | — | |
ip43.254.216.195 | — | |
ip38.54.57.17 | — | |
ip38.60.197.55 | — | |
ip38.60.209.106 | — | |
ip38.60.224.235 | — | |
ip38.60.241.65 | — | |
ip38.60.241.127 | — | |
ip38.60.241.193 | — | |
ip130.94.101.82 | — | |
ip149.104.87.228 | — | |
ip149.104.90.203 | — |
Hash
| Value | Description | Copy |
|---|---|---|
hash23e228d5603b4802398b2e7419187aef71ff9dd5 | — | |
hash2560b7e28b322bb7a56d0b1da1b2652e1efe76ea | — | |
hash4df896624695ea2780552e9ea3c40661dc84efc8 | — | |
hash76c430b55f180a85f4e1a1e40e4a2ea37db97599 | — | |
hash873f98caf234c3a8a9db18343dad7b42117e85d4 | — | |
hashb9601e60f87545441bf8579b2f62668c56507f4a | — | |
hashbb2f5b573ac7a761015daad0b7ff03b294dc60f6 | — | |
hashc36ecd2e0f38294e1290f4b9b36f602167e33614 | — | |
hashe2b0851e2e281cc7bca3d6d9b2fa0c4b7ac5a02b | — | |
hashfdc44057e87d7c350e6df84bb72541236a770ba2 | — | |
hash0dc20b2f11118d5c0cc46b082d7f5dc060276157 | — | |
hashf35ce62abeedfb8c6a38ceac50a250f48c41e65e | — | |
hash0925f24082971f50edd987d82f708845a6a9d7c9 | — | |
hash1b06e877c2c12d74336e7532bc0ecf761e5fa5d4 | — | |
hash3a395daaf518be113fcff2e5e48acd9b9c0de69d | — | |
hash5265e8edc9b5f7dd00fc772522511b8f3be217e3 | — | |
hash5df3c882db6be14887182b7439b72a86bd28b83f | — | |
hash5f1553f3af9425ef5d68341e991b6c5ec96a82eb | — | |
hash7d66b550ea68a86fcc0958e7c159531d4431b788 | — | |
hasha91b42e5062fef608f285002debaff9358162b25 | — | |
hashaa823148eea6f43d8eb9bf20412402a7739d91c2 | — | |
hashc26f04790c6fb7950d89ab1b08207ace01efb536 | — | |
hashcc350ba25947b7f9ec5d11ea8269407c0fd74095 | — | |
hashd03fd329627a58b40e805f4f55b5d821063ac27f | — | |
hashd6d32a1f17d48fe695c0778018c0d51626db4a3b | — | |
hashdb1591c6e23160a94f6312ca46da2d0bb243322c | — | |
hashebc93a546bcdf6cc1eb61d7174bcb85407bbd892 | — | |
hashef189737fb7d61b110b9293e8838526dce920127 | — | |
hash44f0a22b143b79fa760bf31e14c8fff714c8a2a1 | — | |
hash922c1edb47fba94b548edca863165fb1 | — | |
hashe0b6f8535e19f0a4938e3317de0c4493ecea17aa906fd0454805ba2086cbf3a8 | — |
Domain
| Value | Description | Copy |
|---|---|---|
domaincredits.offices-analytics.com | — | |
domainamelicen.com | — |
Threat ID: 6aacfa7155bf5e2cf5c39c77
Added to database: 09/18/2026, 08:46:41 UTC
Last enriched: 09/18/2026, 09:01:30 UTC
Last updated: 09/18/2026, 09:12:09 UTC
Views: 5
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.