ESET details FamousSparrow’s SparroWocky backdoor targeting Latin American governments

· Original article ↗

Summary

ESET reports that China-aligned group FamousSparrow has used its new SparroWocky backdoor against government targets in Latin America since at least August 2025, replacing SparrowDoor with malware designed for stealth and remote access.

Key points

  • ESET attributes SparroWocky deployments to FamousSparrow with high confidence; the group’s telemetry showed 90% of its targets in Latin America from mid-2025 into 2026.
  • The group deployed the backdoor against government entities in Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico, and Venezuela.
  • The article’s MITRE ATT&CK mapping says FamousSparrow gained access by exploiting publicly reachable Exchange servers; the malware loader uses DLL side-loading.
  • SparroWocky is a modular C++ backdoor that can execute commands, exfiltrate files, take screenshots, proxy network traffic, and establish persistence through a Windows service or registry Run key.
  • The malware uses memory manipulation, runtime code patching, call-stack spoofing, and process camouflage to evade analysis and security monitoring.
  • It can load and execute Beacon Object Files, allowing the group to use modules designed for red-teaming and penetration-testing tools.
  • ESET published technical analysis and a repository of indicators of compromise and samples.

Article Details

Attack Vectors
  • FamousSparrow gained access to target networks by exploiting publicly reachable Exchange servers, according to the article’s ATT&CK table.
  • SparroWocky is deployed through DLL side-loading: a legitimate executable loads a patched DLL that decrypts a backdoor payload from a .dat file.
  • SparroWocky can persist through a Windows service or a registry Run key.
  • The backdoor can execute commands, in-memory PE files, and Beacon Object Files; proxy traffic; collect files; and capture screenshots.
Defensive Notes
  • The loader’s patched DLL can retain the legitimate DLL’s metadata and exported functions, making it harder to distinguish by those properties alone.
  • An analyzed configuration uses the service name ProcAuditManager or the Run-key value SnapCart.
  • Observed C&C servers generally use port 443, although port 8080 has also been seen. ESET reports no reliable generic certificate fingerprint.
  • SparroWocky uses call-stack spoofing, API hashing, concealed thread start addresses, and in-memory loading to complicate analysis and detection.

Indicators of compromise

TypeIndicatorContext
IPV4130[.]94[.]101[.]82SparroWocky C&C server.
IPV4140[.]99[.]164[.]199SparroWocky C&C server.
IPV4149[.]104[.]87[.]228SparroWocky C&C server.
IPV4149[.]104[.]90[.]203SparroWocky C&C server.
IPV4216[.]238[.]105[.]53SparroWocky C&C server.
IPV4216[.]238[.]110[.]120SparroWocky C&C server also shown in an analyzed backdoor configuration.
IPV4216[.]238[.]121[.]164SparroWocky C&C server.
IPV4216[.]238[.]92[.]2SparroWocky C&C server.
IPV438[.]54[.]57[.]17SparroWocky C&C server.
IPV438[.]60[.]197[.]55SparroWocky C&C server.
IPV438[.]60[.]209[.]106SparroWocky C&C server.
IPV438[.]60[.]224[.]235SparroWocky C&C server.
IPV438[.]60[.]224[.]51SparroWocky C&C server.
IPV438[.]60[.]241[.]127SparroWocky C&C server.
IPV438[.]60[.]241[.]193SparroWocky C&C server.
IPV438[.]60[.]241[.]65SparroWocky C&C server.
IPV477[.]111[.]101[.]40SparroWocky C&C server.
IPV491[.]148[.]134[.]115SparroWocky C&C server.
SHA13209689e509205ccdb7e49062b7b407ddc23cac1SHA-1 of a SparroWocky loader.
SHA144f0a22b143b79fa760bf31e14c8fff714c8a2a1SHA-1 of the in-memory SparroWocky backdoor sample analyzed in detail.
SHA152c6646759cf6037bb17466203631c4bd794532fSHA-1 of a SparroWocky loader.
SHA199e7070b5af24a0fe1e6febe5954b03cb385e91fSHA-1 of a SparroWocky loader.
SHA19aa9ff61bc63ccab9074fe837f39c980ca9ddc8cSHA-1 of an in-memory SparroWocky backdoor sample.

MITRE ATT&CK

T1005 · Data from Local SystemSparroWocky can read files from mapped storage and send their contents to its C&C server.T1027.007 · Dynamic API ResolutionSparroWocky hashes API names to resolve Windows API functions at runtime.T1033 · System Owner/User DiscoverySparroWocky collects the current username and can enumerate usernames associated with remote sessions.T1036.001 · Invalid Code SignatureAccording to the article’s ATT&CK table, the patched loader DLL retains the now-invalid signature of the legitimate module it impersonates.T1036.004 · Masquerade Task or ServiceSparroWocky gives its persistence service a legitimate-looking or generic name and description.T1041 · Exfiltration Over C2 ChannelSparroWocky sends collected files and screenshots through its C&C connection.T1059.003 · Windows Command ShellSparroWocky can run commands by spawning cmd.exe.T1070.004 · File DeletionSparroWocky can execute a batch file that deletes its executable, loader DLL, payload file, and then the batch file itself.T1070.009 · Clear PersistenceA SparroWocky command removes its persistence mechanism before termination.T1082 · System Information DiscoverySparroWocky collects system details including the Windows version, hostname, and network-interface IP addresses.T1083 · File and Directory DiscoverySparroWocky can enumerate directory contents and files on mapped drives.T1090.001 · Internal ProxySparroWocky can forward traffic between its C&C server and another remote machine.T1090.002 · External ProxySparroWocky can connect to its C&C server through an HTTP or SOCKS5 proxy.T1095 · Non-Application Layer ProtocolSparroWocky communicates with its C&C server using TLS over TCP and a custom command-message format.T1106 · Native APISparroWocky uses native Windows API functions for operations including process creation and session enumeration.T1113 · Screen CaptureSparroWocky can take periodic screenshots and send image changes to its C&C server.T1120 · Peripheral Device DiscoverySparroWocky enumerates active display devices and their settings.T1134.002 · Create Process with TokenSparroWocky can duplicate a token from an existing user session and launch a new instance with CreateProcessAsUserW.T1140 · Deobfuscate/Decode Files or InformationThe loader uses an RC4 key in the payload file header to decrypt SparroWocky and its configuration.T1190 · Exploit Public-Facing ApplicationThe article reports that FamousSparrow exploited publicly reachable Exchange servers to access target networks.T1480.002 · Mutual ExclusionSparroWocky uses a mutex as part of a mechanism that prevents concurrent instances.T1543.003 · Windows ServiceSparroWocky can create a Windows service for persistence.T1547.001 · Registry Run Keys / Startup FolderSparroWocky can establish persistence through a registry Run-key entry.T1559 · Inter-Process CommunicationSparroWocky uses interprocess communication to synchronize running instances.T1564.010 · Process Argument SpoofingWhen loading an external PE, SparroWocky hooks argument-retrieval functions to present a command line supplied through stdin.T1569.002 · Service ExecutionSparroWocky directly starts the service it creates for persistence.T1573.001 · Symmetric CryptographySparroWocky encrypts command arguments or results with RC4 keys carried in message headers.T1573.002 · Asymmetric CryptographySparroWocky establishes TLS connections with its C&C server.T1574.001 · DLLA legitimate executable side-loads the patched DLL containing the SparroWocky loader.T1583.003 · Virtual Private ServerThe article reports that FamousSparrow acquired servers for SparroWocky C&C and delivery.T1587.001 · MalwareFamousSparrow developed SparroWocky and its loader.T1608.001 · Upload MalwareFamousSparrow uploaded the SparroWocky trident loader to attacker-controlled delivery servers.T1620 · Reflective Code LoadingSparroWocky reflectively maps its payload into memory and can load PE files and Beacon Object Files in memory.T1680 · Local Storage DiscoverySparroWocky can return a list of logical drives and their types.

Threat Actors

Malware

Products

Tools

Countries

ArgentinaAs depicted in Figure 1, we’ve seen the new backdoor deployed against governmental entities in Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico, and Venezuela.ChinaOur previous public report on FamousSparrow revealed that this China-aligned APT group had developed two new versions of its custom backdoor named SparrowDoor.EcuadorAs depicted in Figure 1, we’ve seen the new backdoor deployed against governmental entities in Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico, and Venezuela.GuatemalaAs depicted in Figure 1, we’ve seen the new backdoor deployed against governmental entities in Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico, and Venezuela.HondurasAs depicted in Figure 1, we’ve seen the new backdoor deployed against governmental entities in Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico, and Venezuela.PanamaAs depicted in Figure 1, we’ve seen the new backdoor deployed against governmental entities in Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico, and Venezuela.PeruAs depicted in Figure 1, we’ve seen the new backdoor deployed against governmental entities in Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico, and Venezuela.Puerto RicoAs depicted in Figure 1, we’ve seen the new backdoor deployed against governmental entities in Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico, and Venezuela.VenezuelaAs depicted in Figure 1, we’ve seen the new backdoor deployed against governmental entities in Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico, and Venezuela.

Industries

Related Articles