SparroWocky Backdoor: FamousSparrow Targets Governments
ID: c9f9c307-972b-5321-b927-5c96129f1bcb
STIX ID: report--c9f9c307-972b-5321-b927-5c96129f1bcb
Feed Name: CyberNexora News
**SparroWocky Backdoor:** This report summarizes ESET’s findings on the SparroWocky modular C++ backdoor used by the FamousSparrow group to target government entities across Latin America, describing an attack chain that leverages internet-facing Microsoft Exchange exploitation, DLL side-loading, in-memory decrypted payloads, and encrypted communications to enable command execution, file theft, screenshots, TCP proxying, and persistence; the report provides IoC-focused hunting advice and remediation guidance including Exchange patching, exposure reduction, memory monitoring, and persistence review.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
