bleeping-computer · Crawled Sep 17, 2026

Chinese hackers use SparroWocky malware in govt espionage attacks

3 IoCs 1 Actors 1 Malware
Read original article ↗

AI Summary

The China-linked threat actor FamousSparrow has been conducting espionage campaigns against government organizations in Latin America since mid-2025, using a new modular C++ backdoor named SparroWocky. This malware replaces the group's previously used SparrowDoor backdoor and is deployed via DLL side-loading, with payloads RC4-encoded in .dat files. SparroWocky features advanced evasion techniques, including thread creation hooking to spoof legitimate Windows functions, in-memory code manipulation, and anti-analysis tricks, enabling command execution, file manipulation, screenshot capture, and proxy capabilities. The malware establishes persistence via a Windows service or registry key and communicates with C2 servers over ports 443 or 8080, sometimes through HTTP and SOCKS5 proxies.

AI-extracted · verify before operational use

Extracted Entities 2 found

Indicators of Compromise 3 extracted

Type Value Detail
Filename .dat Details →
Filename ProcAuditManager Details →
Filename SnapCart Details →

MITRE ATT&CK TTPs 35 techniques

T1003.001 LSASS Memory · Credential Access T1013 T1013 T1021.001 Remote Desktop Protocol · Lateral Movement T1027 Obfuscated Files or Information · Defense Evasion T1048 Exfiltration Over Alternative Protocol · Exfiltration T1055 Process Injection · Defense Evasion T1055.001 Dynamic-link Library Injection · Defense Evasion T1059.001 PowerShell · Execution T1071.001 Web Protocols · Command And Control T1078 Valid Accounts · Defense Evasion T1078.002 Domain Accounts · Defense Evasion T1082 System Information Discovery · Discovery T1083 File and Directory Discovery · Discovery T1087.002 Domain Account · Discovery T1090 Proxy · Command And Control T1095 Non-Application Layer Protocol · Command And Control T1098.002 Additional Email Delegate Permissions · Persistence T1105 Ingress Tool Transfer · Command And Control T1110 Brute Force · Credential Access T1110.001 Password Guessing · Credential Access T1120 Peripheral Device Discovery · Discovery T1133 External Remote Services · Persistence T1136.001 Local Account · Persistence T1190 Exploit Public-Facing Application · Initial Access T1210 Exploitation of Remote Services · Lateral Movement T1482 Domain Trust Discovery · Discovery T1499 Endpoint Denial of Service · Impact T1543.001 Launch Agent · Persistence T1556.004 Network Device Authentication · Credential Access T1558 Steal or Forge Kerberos Tickets · Credential Access T1566 Phishing · Initial Access T1571 Non-Standard Port · Command And Control T1574.001 DLL Search Order Hijacking · Persistence T1574.002 DLL Side-Loading · Persistence T1665 Hide Infrastructure · Command And Control