Beware the SparroWock: The backdoor that bites, the commands that catch

Imported from official source

Cybersecurity Classified by Officially

ESET Research’s ongoing monitoring of FamousSparrow has borne fruit once again. Our previous public report on FamousSparrow revealed that this China-aligned APT group had developed two new versions of its custom backdoor named SparrowDoor. This time, we discovered that FamousSparrow has switched to a new backdoor, SparroWocky, and has been deploying it to several countries in Latin America since at least August 2025.

In what was probably China’s reaction to the US showing increased interest in Latin America, FamousSparrow increased its targeting of the region to almost exclusively targeting it in July 2025. A month later, we noticed that the group had started using the new SparroWocky backdoor, which then quickly replaced SparrowDoor as FamousSparrow’s main implant.

SparroWocky is a modular, C++ backdoor. Its architecture and the techniques used by its authors indicate strong knowledge of anti-analysis tricks and Windows internals. We chose to name the backdoor SparroWocky because the first samples we collected all contain the first stanza of Jabberwocky, a nonsense poem by Lewis Carroll. Fortunately, while advanced, SparroWocky’s inner workings are much less arcane than a gyre and gimble in the wabe, so a through and through [of] the vorpal blade allowed us to bring you a detailed analysis of the backdoor.

  • FamousSparrow is extensively targeting governmental organizations in Latin America.
  • Since August 2025, the group appears to be abandoning SparrowDoor in favor of SparroWocky, a new custom C++ backdoor.
  • With the switch to SparroWocky, FamousSparrow started to incorporate code from open-source projects directly into its malware.
  • SparroWocky is a full-featured backdoor that manipulates low-level structures in memory, and patches code at runtime in order to avoid detection.
  • SparroWocky has the capability to load and execute Beacon Object Files, a special type of executable file supported by many red-teaming and penetration-testing tools.
  • This is an extract. The publication continues at the source.

    Read the original at the source: https://www.welivesecurity.com/en/eset-research/beware-sparrowock-backdoor-bites-commands-catch/

    Officially imported this from ESET’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.

    Provenance

    Organization
    ESET — imported from official source
    Official source
    https://www.welivesecurity.com/en/rss/feed/ RSS
    Imported
    September 18, 2026 11:35
    Versions
    1 recorded
    Identity
    https://www.welivesecurity.com/en/eset-research/beware-sparrowock-backdoor-bites-comman...

    Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.