logo

SparroWocky Backdoor: FamousSparrow Targets Governments

ID: c9f9c307-972b-5321-b927-5c96129f1bcb

STIX ID: report--c9f9c307-972b-5321-b927-5c96129f1bcb

Feed Name: CyberNexora News

Threat Score
88/100

Date Published: 2026-09-17

Date Updated: 2026-09-17

Author: Debolina Barik

...
...

**SparroWocky Backdoor:** This report summarizes ESET’s findings on the SparroWocky modular C++ backdoor used by the FamousSparrow group to target government entities across Latin America, describing an attack chain that leverages internet-facing Microsoft Exchange exploitation, DLL side-loading, in-memory decrypted payloads, and encrypted communications to enable command execution, file theft, screenshots, TCP proxying, and persistence; the report provides IoC-focused hunting advice and remediation guidance including Exchange patching, exposure reduction, memory monitoring, and persistence review.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.