FamousSparrow (China-aligned): SparroWocky modular backdoor hits LatAm governments
ESET Research (17 September 2026; “Beware the SparroWock”) documents SparroWocky, the new flagship modular C++ backdoor of China-aligned APT FamousSparrow, replacing SparrowDoor in campaigns focused on Latin American government targets (Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico, Venezuela per BleepingComputer). ESET attributes with high confidence (early SparroWocky deployments via SparrowDoor). Capabilities include command/file execution, in-memory BOF load, system/network/user enumeration, file ops, screenshot streaming, cross-session process create, TCP proxy, and self-removal; persistence via Windows service (e.g. ProcAuditManager) or registry Run key (e.g. SnapCart); DLL side-load after RC4 .dat decrypt. Evasion includes MinHook CreateThread spoofing (AnimateWindow start address), call-stack spoofing, and dynamic API resolve. C2 over 443/8080 or HTTP/SOCKS5 proxies (ESET lists ≥18 addresses). No CVE. Primary: ESET; wire: BleepingComputer 17 Sep 2026.
- Product
- SparroWocky backdoor (FamousSparrow APT; Windows)
- Exploited in Australia?
- unknown
- Patch to
- Hunt DLL side-loads, ProcAuditManager / SnapCart persistence, AnimateWindow-spoofed threads, and ESET IoCs; restrict egress to listed C2 ports/proxies
Primary: ESET Research — Beware the SparroWock (17 Sep 2026) · Vendor: ESET WeLiveSecurity research · BleepingComputer — SparroWocky / FamousSparrow (17 Sep 2026)
