Threats Tagged 'sparrowocky'
View all threats tagged with 'sparrowocky'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'sparrowocky'
Click on any threat for detailed analysis and mitigation recommendations
SparroWocky is a sophisticated C++ backdoor used by the China-aligned FamousSparrow APT group since August 2025. It targets governmental organizations in Latin America, replacing the group's previous SparrowDoor backdoor. The malware features advanced evasion techniques such as reflective loading, call stack spoofing (SilentMoonwalk), and encrypted communications using TLS and RC4. It also incorporates open-source projects and uses modular components including Beacon Object Files. The backdoor employs API hooking and custom PE loading to camouflage itself within host processes. This campaign aligns with China's strategic interest in monitoring Latin American governmental responses to US pressures on investments and infrastructure. Join the discussion | AlienVault OTX General | 09/17/2026, 16:19:02 UTC Added: 09/18/2026, 08:46:41 UTC |
Showing 1 to 1 of 1 result