{"id":612,"date":"2026-09-18T08:26:31","date_gmt":"2026-09-18T08:26:31","guid":{"rendered":"https:\/\/escudodigital.uy\/index.php\/2026\/09\/18\/the-backdoor-that-bites-the-commands-that-catch\/"},"modified":"2026-09-18T08:26:31","modified_gmt":"2026-09-18T08:26:31","slug":"the-backdoor-that-bites-the-commands-that-catch","status":"publish","type":"post","link":"https:\/\/escudodigital.uy\/index.php\/2026\/09\/18\/the-backdoor-that-bites-the-commands-that-catch\/","title":{"rendered":"The backdoor that bites, the commands that catch"},"content":{"rendered":"<div>\n<p>ESET Research\u2019s ongoing monitoring of FamousSparrow has borne fruit once again. Our previous public report on FamousSparrow revealed that this China-aligned APT group had developed two new versions of its custom backdoor named SparrowDoor. This time, we discovered that FamousSparrow has switched to a new backdoor, SparroWocky, and has been deploying it to several countries in Latin America since at least August 2025.<\/p>\n<p>In what was probably China\u2019s reaction to the US showing increased interest in Latin America, FamousSparrow increased its targeting of the region to almost exclusively targeting it in July 2025. A month later, we noticed that the group had started using the new SparroWocky backdoor, which then quickly replaced SparrowDoor as FamousSparrow\u2019s main implant.<\/p>\n<p>SparroWocky is a modular, C++ backdoor. Its architecture and the techniques used by its authors indicate strong knowledge of anti-analysis tricks and Windows internals. We chose to name the backdoor SparroWocky because the first samples we collected all contain the first stanza of <a href=\"https:\/\/en.wikipedia.org\/wiki\/Jabberwocky\">Jabberwocky<\/a>, a nonsense poem by Lewis Carroll. Fortunately, while advanced, SparroWocky\u2019s inner workings are much less arcane than a <em>gyre and gimble in the wabe<\/em>, so a <em>through and through [of] the vorpal blade<\/em> allowed us to bring you a detailed analysis of the backdoor.<\/p>\n<blockquote>\n<p><strong>Key points of the blogpost:<\/strong><\/p>\n<ul>\n<li>FamousSparrow is extensively targeting governmental organizations in Latin America.<\/li>\n<li>Since August 2025, the group appears to be abandoning SparrowDoor in favor of SparroWocky, a new custom C++ backdoor.<\/li>\n<li>With the switch to SparroWocky, FamousSparrow started to incorporate code from open-source projects directly into its malware.<\/li>\n<li>SparroWocky is a full-featured backdoor that manipulates low-level structures in memory, and patches code at runtime in order to avoid detection.<\/li>\n<li>SparroWocky has the capability to load and execute Beacon Object Files, a special type of executable file supported by many red-teaming and penetration-testing tools.<\/li>\n<\/ul>\n<\/blockquote>\n<p>FamousSparrow is a China-aligned cyberespionage group believed to have been active since at least 2019. We first publicly documented the group in a blogpost from September 2021 when we observed it exploiting the <a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/cve-2021-26855\">ProxyLogon<\/a> vulnerability. The group was initially known for targeting hotels around the world but has also targeted governments, international organizations, trade groups, engineering companies, and law firms. FamousSparrow is the only known user of the SparrowDoor backdoor.<\/p>\n<p>We analyzed two versions of SparrowDoor in a 2025 blogpost, in which we also discussed the attribution claims around the group. As mentioned by <a href=\"https:\/\/www.trendmicro.com\/en_us\/research\/23\/h\/earth-estries-targets-government-tech-for-cyberespionage.html\">Trend Micro<\/a>, FamousSparrow is linked to Earth Estries; however, the exact nature of the link is not fully known. FamousSparrow has also been publicly linked to <a href=\"https:\/\/www.wsj.com\/tech\/cybersecurity\/u-s-wiretap-systems-targeted-in-china-linked-hack-327fc63b\">Salt Typhoon<\/a>, but, due to the absence of any technical indicators, we track them as separate.<\/p>\n<p>Based on our investigation, we attribute the latest campaign and the SparroWocky backdoor to FamousSparrow with high confidence, since in some of the first attacks involving this backdoor, SparroWocky was deployed by the FamousSparrow-exclusive SparrowDoor. Moreover, not only does the victimology match FamousSparrow\u2019s previous targeting, we have also recorded attempts to deploy SparroWocky at many of the same organizations that had previously been targeted with SparrowDoor.<\/p>\n<h2>Latin America in the crosshairs<\/h2>\n<p>As previously mentioned, FamousSparrow currently appears to be focused on high-profile targets in Latin America. This trend started at the latest in July 2025 and has continued with the introduction of SparroWocky. In fact, from mid-2025 and into 2026, 90% of the group\u2019s targets registered in our telemetry have been located in the region. As depicted in Figure 1, we\u2019ve seen the new backdoor deployed against governmental entities in Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico, and Venezuela. This represents a rare occurrence among the China-aligned APT groups that we currently track, which are generally observed throughout various world regions within such an extended time frame.<\/p>\n<figure class=\"image\"><img decoding=\"async\" title=\"Figure 1. Victimology of SparroWocky\" src=\"https:\/\/web-assets.esetstatic.com\/wls\/2026\/09-26\/sparrowocky\/sparrowocky-victimology-map.png\" alt=\"SparroWocky_Victimology-map\" width=\"\" height=\"\"\/><figcaption><em>Figure 1. Victimology of SparroWocky<\/em><\/figcaption><\/figure>\n<p>We believe that this focus is not coincidental and likely reflects China\u2019s reaction to various recent US initiatives in the region. Indeed, Donald Trump\u2019s second presidential term has brought about <a href=\"https:\/\/www.chathamhouse.org\/2025\/12\/trump-corollary-us-security-strategy-brings-new-focus-latin-america-it-disordered-plan\">an aggressive reaffirmation<\/a> of US interests in Latin America, which threatens various long-term investments that China has cultivated throughout the continent in the last decade, in domains such as <a href=\"https:\/\/www.csis.org\/analysis\/power-moves-how-chinas-energy-investments-provide-durable-influence-south-america\">energy<\/a>, <a href=\"https:\/\/www.latinometrics.com\/articles\/mining-race\">mining<\/a>, and <a href=\"https:\/\/www.bnamericas.com\/en\/features\/where-china-is-supplying-telecoms-in-latin-america\">telecommunications<\/a>. We suspect that FamousSparrow\u2019s activities are intended to help China better monitor and anticipate the reaction of local governments to current US pressures.<\/p>\n<p>In some cases, we have observed elements that clearly seem to confirm this hypothesis. For instance, one of the Panamanian entities we\u2019ve seen being targeted is directly involved in the ongoing <a href=\"https:\/\/www.reuters.com\/world\/china\/panama-president-says-port-caught-in-us-china-dispute-2026-04-30\/\">commercial dispute<\/a> regarding two major ports located in the canal area, which were, until recently, operated by a China-based company. As the concession granted to this company was legally challenged by the Panamanian government in early 2025, it seems highly likely that FamousSparrow\u2019s operation was intended to gain early, privileged knowledge of local authorities\u2019 intentions on this issue.<\/p>\n<p>It is not clear whether the group\u2019s apparent focus on Latin America may reflect a formal, geographical mandate, or whether this focus is only temporary and dictated by the current geopolitical circumstances.<\/p>\n<h2>Examining SparroWocky<\/h2>\n<p>SparroWocky is a full-featured, modular C++ backdoor built with modularity and stealthiness in mind. It appeared shortly after FamousSparrow started focusing on Latin America and quickly became the group\u2019s new flagship implant, replacing SparrowDoor. It should be noted that SparroWocky is not a variant of SparrowDoor, but is rather a distinct malware family. The transition to this new backdoor also came with a greater level of integration of open-source tooling into FamousSparrow\u2019s workflow: while previously, standalone versions of these tools were deployed side by side with SparrowDoor, with SparroWocky, some have been incorporated directly into the malware.<\/p>\n<p>Some of SparroWocky\u2019s notable features include the ability to execute arbitrary files, to act as a TCP proxy, and to execute commands. The backdoor also collects general information about the compromised machine, such as the computer name, the username, domain name, Windows version, and the IP addresses of its network interfaces. SparroWocky is also capable of exfiltrating files and taking screenshots periodically. Exfiltrated information is encrypted using RC4 and sent over the TLS protocol.<\/p>\n<p>Depending on its configuration, SparroWocky can establish persistence either by creating a dedicated service or an entry in a registry Run key.<\/p>\n<h3>Loader<a id=\"Loader\"\/><\/h3>\n<p>SparroWocky is deployed using the common trident loader scheme, which consists of a legitimate executable, a malicious DLL standing in for one required by that executable, and a file containing an encrypted payload (see Figure 2). The loader resides in the aforementioned DLL and is executed via <a href=\"https:\/\/attack.mitre.org\/techniques\/T1574\/001\/\">DLL side-loading<\/a>. We have seen FamousSparrow use a wide range of side-loading targets; in most cases, a patched version of the legitimate DLL that the executable is supposed to load. While most of the file is left untouched, an arbitrary portion of the <span style=\"font-family: courier new, courier, monospace;\">.text<\/span> section is replaced with the malicious code, and the entry point header is changed to point inside this patched region.<\/p>\n<figure class=\"image\"><img decoding=\"async\" title=\"Figure 2. Trident loader scheme\" src=\"https:\/\/web-assets.esetstatic.com\/wls\/2026\/09-26\/sparrowocky\/sparrowocky-trident-loader-scheme.png\" alt=\"SparroWocky_Trident-loader-scheme\" width=\"\" height=\"\"\/><figcaption><em>Figure 2. Trident loader scheme<\/em><\/figcaption><\/figure>\n<p>This has some defense-evasion properties: having the metadata and exported function list of the malicious DLL be the same as that of the legitimate version allows it to more easily blend in. Since the code in the patched region does not align with the exported functions and calls in the untouched portion, automated analysis tools may have trouble recognizing function boundaries.<\/p>\n<p>The loader\u2019s main role is to extract and decrypt its payload from a file. These files, which typically have the same name as the executable but with a <span style=\"font-family: courier new, courier, monospace;\">.dat<\/span> extension, have a specific structure detailed in Figure 3. The file has a custom header that begins with a four-byte magic value of <span style=\"font-family: courier new, courier, monospace;\">0x11328712<\/span>, followed by the size of the configuration data, the size of the payload, and a 16-byte RC4 key. This RC4 key is used to decrypt the remainder of the file, which contains the configuration for SparroWocky (detailed in the <em><a href=\"#Configuration\">Configuration<\/a> <\/em>section) and the backdoor itself. We provide a script to decrypt SparroWocky payload files in <a href=\"https:\/\/github.com\/eset\/malware-ioc\/tree\/master\/famoussparrow\/extract_sparrowocky.py\">our GitHub repository<\/a>.<\/p>\n<figure class=\"image align-center\"><img decoding=\"async\" title=\"Figure 3. Definition of the structure of SparroWocky\u2019s payload file\" src=\"https:\/\/web-assets.esetstatic.com\/wls\/2026\/09-26\/sparrowocky\/figure-3.png\" alt=\"Figure 3. Definition of the structure of SparroWocky\u2019s payload file\" width=\"\" height=\"\"\/><figcaption><em>Figure 3. Definition of the structure of SparroWocky\u2019s payload file<\/em><\/figcaption><\/figure>\n<p>The plaintext backdoor payload is formatted as a portable executable (PE) file with the <span style=\"font-family: courier new, courier, monospace;\">MZ<\/span> and <span style=\"font-family: courier new, courier, monospace;\">PE<\/span> magic values deleted. This executable payload is reflectively mapped directly into memory without being written to disk. Thus, we believe that stripping these magic values is possibly an attempt to evade in-memory defense mechanisms that use simple pattern recognition to identify or dump suspicious sections of memory.<\/p>\n<h3>SparroWocky<\/h3>\n<p>Our analysis of SparroWocky is mainly based on a sample compiled on November 17<sup>th<\/sup>, 2025 according to its PE timestamp (SHA-1: <span style=\"font-family: courier new, courier, monospace;\">44F0A22B143B79FA760BF31E14C8FFF714C8A2A1<\/span>). The version of this backdoor appears to be <span style=\"font-family: courier new, courier, monospace;\">1.8<\/span>, based on the information collected by its fingerprint command explained in Table 3.<\/p>\n<p>As we already mentioned, we chose the name SparroWocky because we found the first stanza of Lewis Caroll\u2019s Jabberwocky in several samples we collected. We believe that this stanza comes from the test vectors in <a href=\"https:\/\/www.rfc-editor.org\/info\/rfc7539\/\">RFC 7539<\/a>, which defines the ChaCha20-Poly1305 encryption algorithm. The samples of SparroWocky also contain other strings that are used as test vectors in that RFC. However, SparroWocky does not use ChaCha20-Poly1305. While we don\u2019t know the exact version of Mbed TLS used in the backdoor, the test vectors were present in that library <a href=\"https:\/\/github.com\/Mbed-TLS\/mbedtls\/blob\/mbedtls-3.6.7\/library\/poly1305.c#L406\">prior to version 4.0.0<\/a>.<\/p>\n<p>Notably, SparroWocky relies at least on the following public projects:<\/p>\n<ul>\n<li><a href=\"https:\/\/github.com\/Mbed-TLS\/mbedtls\">Mbed TLS<\/a>, a C library it uses to establish a secure communication channel with its C&amp;C server,<\/li>\n<li><a href=\"https:\/\/github.com\/TsudaKageyu\/minhook\/tree\/master\">MinHook<\/a>, a Windows API hooking library it uses to hide the start address of newly created threads from security products, and<\/li>\n<li><a href=\"https:\/\/github.com\/trustedsec\/COFFLoader\">COFF Loader<\/a> (or a similar project) that it uses to enable dynamic loading and execution of in-memory plugins in the form of <a href=\"https:\/\/en.wikipedia.org\/wiki\/COFF\">COFF<\/a> objects.<\/li>\n<\/ul>\n<p>Additionally, our analysis revealed that the developers implemented various techniques to evade monitoring tools. This includes a variant of a technique called <a href=\"https:\/\/github.com\/klezVirus\/SilentMoonwalk\">SilentMoonwalk<\/a> (or StackMoonwalk), which allows SparroWocky to spoof the call stacks originating from MinHook routines. The backdoor also uses a custom API-hashing algorithm to dynamically resolve Windows API functions. These are explained in greater detail in the <em><a href=\"#Anti-analysis techniques\">Anti-analysis techniques<\/a><\/em> section.<\/p>\n<h4>Configuration<a id=\"Configuration\"\/><\/h4>\n<p>The SparroWocky loader extracts and decrypts its configuration from the payload <span style=\"font-family: courier new, courier, monospace;\">.dat<\/span> file located in the same directory, as explained in the<em> <a href=\"#Loader\">Loader<\/a><\/em> section. The RC4 key stored in the payload header is used to decrypt the configuration, which is provided in the form of a tab-separated string that is then parsed and stored in a structure. The fields and their values are described in Table 1 in order of appearance.<\/p>\n<p style=\"text-align: center;\"><em>Table 1. SparroWocky configuration<\/em><\/p>\n<table border=\"1\" width=\"642\" cellspacing=\"0\" cellpadding=\"0\">\n<thead>\n<tr>\n<td width=\"132\"><strong>Field<\/strong><\/td>\n<td width=\"208\"><strong>Value<\/strong><\/td>\n<td width=\"303\"><strong>Additional details<\/strong><\/td>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td width=\"132\">C&amp;C IP address<\/td>\n<td width=\"208\"><span style=\"font-family: courier new, courier, monospace;\">216.238.110[.]120<\/span><\/td>\n<td width=\"303\">\u00a0<\/td>\n<\/tr>\n<tr>\n<td width=\"132\">C&amp;C port number<\/td>\n<td width=\"208\"><span style=\"font-family: courier new, courier, monospace;\">443<\/span><\/td>\n<td width=\"303\">\u00a0<\/td>\n<\/tr>\n<tr>\n<td width=\"132\">Connection retry delay (in seconds)<\/td>\n<td width=\"208\"><span style=\"font-family: courier new, courier, monospace;\">10<\/span><\/td>\n<td width=\"303\">After the first retry, the value is randomized.<\/td>\n<\/tr>\n<tr>\n<td width=\"132\">Proxy connection type<\/td>\n<td width=\"208\"><span style=\"font-family: courier new, courier, monospace;\">0<\/span><\/td>\n<td width=\"303\"><span style=\"font-family: courier new, courier, monospace;\">0<\/span>: If enabled, use the proxy configured on the system; otherwise, connect directly.<br \/><span style=\"font-family: courier new, courier, monospace;\">1<\/span>: HTTP proxy via Negotiate or Basic authentication.<br \/><span style=\"font-family: courier new, courier, monospace;\">2<\/span>: SOCKS5 proxy via Basic authentication or without authentication.<\/td>\n<\/tr>\n<tr>\n<td width=\"132\">Proxy IP address<\/td>\n<td width=\"208\">N\/A<\/td>\n<td width=\"303\">\u00a0<\/td>\n<\/tr>\n<tr>\n<td width=\"132\">Proxy port number<\/td>\n<td width=\"208\">N\/A<\/td>\n<td width=\"303\">\u00a0<\/td>\n<\/tr>\n<tr>\n<td width=\"132\">Proxy username<\/td>\n<td width=\"208\">N\/A<\/td>\n<td width=\"303\">\u00a0<\/td>\n<\/tr>\n<tr>\n<td width=\"132\">Proxy password<\/td>\n<td width=\"208\">N\/A<\/td>\n<td width=\"303\">\u00a0<\/td>\n<\/tr>\n<tr>\n<td width=\"132\">Persistence method<\/td>\n<td width=\"208\"><span style=\"font-family: courier new, courier, monospace;\">1<\/span><\/td>\n<td width=\"303\"><span style=\"font-family: courier new, courier, monospace;\">1<\/span>: Service persistence.<br \/><span style=\"font-family: courier new, courier, monospace;\">2<\/span>: Registry persistence.<\/td>\n<\/tr>\n<tr>\n<td width=\"132\">Service persistence: service name<\/td>\n<td width=\"208\"><span style=\"font-family: courier new, courier, monospace;\">ProcAuditManager<\/span><\/td>\n<td rowspan=\"2\" width=\"303\">In the configurations we have extracted, the display name is always the same as the service name. These usually match the filename of the payload file.<\/td>\n<\/tr>\n<tr>\n<td width=\"132\">Service persistence: display name<\/td>\n<td width=\"208\"><span style=\"font-family: courier new, courier, monospace;\">ProcAuditManager<\/span><\/td>\n<\/tr>\n<tr>\n<td width=\"132\">Service persistence: service description<\/td>\n<td width=\"208\"><span style=\"font-family: courier new, courier, monospace;\">Tracks process creation,<wbr\/> termination, and related<wbr\/> system audit events.<\/span><\/td>\n<td width=\"303\">\u00a0<\/td>\n<\/tr>\n<tr>\n<td width=\"132\">Registry persistence: registry value<\/td>\n<td width=\"208\"><span style=\"font-family: courier new, courier, monospace;\">SnapCart<\/span><\/td>\n<td width=\"303\">\u00a0<\/td>\n<\/tr>\n<tr>\n<td width=\"132\">Registry persistence: registry key<\/td>\n<td width=\"208\"><span style=\"font-family: courier new, courier, monospace;\">SOFTWARE\\Microsoft\\Windo<wbr\/>ws\\CurrentVersion\\Run<\/span><\/td>\n<td width=\"303\">Uses <span style=\"font-family: courier new, courier, monospace;\">HKLM<\/span> or <span style=\"font-family: courier new, courier, monospace;\">HKCU<\/span> depending on privileges.<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h4>Capabilities<\/h4>\n<h5>Argument-controlled behavior<a id=\"Argument-controlled behavior\"\/><\/h5>\n<p>After parsing its configuration, the backdoor checks the command line of the process in which it is running and behaves differently based on the number and value of the arguments passed. If no arguments are present, SparroWocky simply sets up persistence and executes the core logic of the backdoor. Otherwise, the value of the first argument directs the malware to follow specific instructions, as described in Table 2.<\/p>\n<p style=\"text-align: center;\"><em>Table 2. SparroWocky command line arguments and their meaning<\/em><\/p>\n<table border=\"1\" width=\"642\" cellspacing=\"0\" cellpadding=\"0\">\n<thead>\n<tr>\n<td width=\"72\"><strong>Argument<\/strong><\/td>\n<td width=\"192\"><strong>Behavior<\/strong><\/td>\n<td width=\"378\"><strong>Description<\/strong><\/td>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td width=\"72\"><span style=\"font-family: courier new, courier, monospace;\">c<\/span><\/td>\n<td width=\"192\">Load and execute a PE file in memory for a specified amount of time before termination.<\/td>\n<td width=\"378\">Used in tandem with command <span style=\"font-family: courier new, courier, monospace;\">0x16<\/span>*, SparroWocky reads a command string, an execution timeout delay, and the body of a PE file from <a>standard input<\/a>\u00a0(<span style=\"font-family: courier new, courier, monospace;\">stdin<\/span>). It then loads the specified executable into memory and executes it with the given command.<\/td>\n<\/tr>\n<tr>\n<td width=\"72\"><span style=\"font-family: courier new, courier, monospace;\">p<\/span><\/td>\n<td width=\"192\">Sleep for five seconds, set up persistence, and run the core logic of the backdoor.<\/td>\n<td width=\"378\">\u00a0<\/td>\n<\/tr>\n<tr>\n<td width=\"72\"><span style=\"font-family: courier new, courier, monospace;\">s<\/span><\/td>\n<td width=\"192\">Run the core logic of the backdoor without establishing persistence.<\/td>\n<td width=\"378\">Used in tandem with command <span style=\"font-family: courier new, courier, monospace;\">0x2F*<\/span>, this argument also means the backdoor was run as a specific user (via <a href=\"https:\/\/learn.microsoft.com\/en-us\/windows\/win32\/api\/processthreadsapi\/nf-processthreadsapi-createprocessasuserw\">CreateProcessAsUser<\/a>), identified by a session ID that was retrieved by command <span style=\"font-family: courier new, courier, monospace;\">0x2E<\/span>*.<\/td>\n<\/tr>\n<tr>\n<td width=\"72\"><span style=\"font-family: courier new, courier, monospace;\">s2<\/span><\/td>\n<td width=\"192\">Start a new instance of the backdoor with argument <span style=\"font-family: courier new, courier, monospace;\">p<\/span> and terminate.<\/td>\n<td width=\"378\">This argument indicates that the backdoor was started via the service persistence.<\/td>\n<\/tr>\n<tr>\n<td width=\"72\"><span style=\"font-family: courier new, courier, monospace;\">t<\/span><\/td>\n<td width=\"192\">Set the process working directory to the backdoor location and run the core logic of the backdoor.<\/td>\n<td width=\"378\">\u00a0<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>* Explained in the <em><a href=\"#Backdoor commands\">Backdoor commands<\/a><\/em> section.<\/p>\n<p>When SparroWocky is executed with the <span style=\"font-family: courier new, courier, monospace;\">c<\/span> option, it reads an additional comma-separated list of parameters from standard input (<span style=\"font-family: courier new, courier, monospace;\">stdin<\/span>):<\/p>\n<ul>\n<li>a command string,<\/li>\n<li>a timeout delay (in seconds), and<\/li>\n<li>optionally, the body of a PE file.<\/li>\n<\/ul>\n<p>If this last parameter is absent, the backdoor reads the executable specified in the command string from <span style=\"font-family: courier new, courier, monospace;\">C:\\Windows\\System32\\<\/span> and loads the associated English <a href=\"https:\/\/en.wikipedia.org\/wiki\/Multilingual_User_Interface\">MUI<\/a> (Multilingual User Interface) file (from <span style=\"font-family: courier new, courier, monospace;\">C:\\Windows\\System32\\en-US\\<\/span>). This process is described in the <em><a href=\"#Host process camouflage for dynamically loaded PEs\">Host process camouflage for dynamically loaded PEs<\/a> <\/em>section. Otherwise, the PE file is executed by SparroWocky\u2019s reflective loader, and the command string is passed as a command line. This functionality is likely meant to allow the backdoor to easily execute system utilities.<\/p>\n<p>SparroWocky loads the specified executable into memory and executes it with the provided command. At the same time, the backdoor creates a new thread that calls <span style=\"font-family: courier new, courier, monospace;\">ExitProcess<\/span> to kill the process when the timeout delay expires. The loading process involves setting up hooks and forging structures in memory to camouflage the host process before running the target executable. These anti-analysis tricks are explained in greater detail in the dedicated <em><a href=\"#Host process camouflage for dynamically loaded PEs\">Host process camouflage for dynamically loaded PEs<\/a> <\/em>section.<\/p>\n<p>Additionally, when the malware is executed without arguments or with the p option, an instance synchronization mechanism is started. This feature prevents multiple instances of the backdoor from running concurrently by leveraging a custom interprocess communication (<a href=\"https:\/\/en.wikipedia.org\/wiki\/Inter-process_communication\">IPC<\/a>) mechanism. When a new instance is launched, the currently running instance stops and, if the new instance is launched from a different location than the current one, the files and persistence configurations set by the currently running instance are deleted. This is achieved by using three types of global objects: a mutex, an event, and a shared memory block named <span style=\"font-family: courier new, courier, monospace;\">MyMutexName<\/span>, <span style=\"font-family: courier new, courier, monospace;\">MyEventName<\/span>, and <span style=\"font-family: courier new, courier, monospace;\">MySharedMemName<\/span>, respectively.<\/p>\n<h5>Backdoor commands<a id=\"Backdoor commands\"\/><\/h5>\n<p>The backdoor first establishes communication with its C&amp;C server, then executes its core logic in an infinite loop, within which it processes received commands. These are handled by a custom class named <span style=\"font-family: courier new, courier, monospace;\">WinHandler<\/span> (derived from a <span style=\"font-family: courier new, courier, monospace;\">ServerHandler<\/span> custom class), according to the runtime type information (RTTI) present in the malware. Handlers for a minimal set of commands are hardcoded in the command loop itself. <span style=\"font-family: courier new, courier, monospace;\">ServerHandler<\/span> has a dedicated virtual method to handle more commands. This method is implemented in <span style=\"font-family: courier new, courier, monospace;\">WinHandler<\/span>. While we have not observed other implementations of this method, this architecture would make it easy for its developers to change the set of commands that the backdoor can handle. The list of supported commands is shown in Table 3.<\/p>\n<p style=\"text-align: center;\"><em>Table 3. SparroWocky commands<\/em><\/p>\n<table style=\"height: 1800px;\" border=\"1\" width=\"642\" cellspacing=\"0\" cellpadding=\"0\">\n<thead>\n<tr style=\"height: 18px;\">\n<td style=\"height: 18px; width: 55.3594px;\" width=\"56\"><strong>ID<\/strong><\/td>\n<td style=\"height: 18px; width: 178.922px;\" width=\"180\"><strong>Arguments<\/strong><\/td>\n<td style=\"height: 18px; width: 399.719px;\" width=\"407\"><strong>Description<\/strong><\/td>\n<\/tr>\n<\/thead>\n<tbody>\n<tr style=\"height: 234px;\">\n<td style=\"height: 234px; width: 55.3594px;\" width=\"56\"><span style=\"font-family: courier new, courier, monospace;\">0x10<\/span><\/td>\n<td style=\"height: 234px; width: 178.922px;\" width=\"180\">N\/A<\/td>\n<td style=\"height: 234px; width: 399.719px;\" width=\"407\">Collects and sends the following system information:<br \/>\u00b7 MD5 hash of the machine GUID,<br \/>\u00b7 SparroWocky PID,<br \/>\u00b7 hostname,<br \/>\u00b7 IP addresses of all network interfaces,<br \/>\u00b7 username,<br \/>\u00b7 Windows product name,<br \/>\u00b7 backdoor version (<span style=\"font-family: courier new, courier, monospace;\">1.8<\/span>),<br \/>\u00b7 <span style=\"font-family: courier new, courier, monospace;\">x64<\/span> (likely backdoor architecture),<br \/>\u00b7 domain name,<br \/>\u00b7 SparroWocky\u2019s host file path,<br \/>\u00b7 connection retry delay, and<br \/>\u00b7 self-deletion enable state (<span style=\"font-family: courier new, courier, monospace;\">0<\/span> or <span style=\"font-family: courier new, courier, monospace;\">1<\/span>).<\/td>\n<\/tr>\n<tr style=\"height: 90px;\">\n<td style=\"height: 90px; width: 55.3594px;\" width=\"56\"><span style=\"font-family: courier new, courier, monospace;\">0x11*<\/span><\/td>\n<td style=\"height: 90px; width: 178.922px;\" width=\"180\">N\/A<\/td>\n<td style=\"height: 90px; width: 399.719px;\" width=\"407\">Starts a new interactive session.<br \/>Establishes a new connection to the C&amp;C server, sends an initial packet containing the byte sequence <span style=\"font-family: courier new, courier, monospace;\">44 33 22 11<\/span> (hex), and then starts processing received commands in a separate thread.<\/td>\n<\/tr>\n<tr style=\"height: 18px;\">\n<td style=\"height: 18px; width: 55.3594px;\" width=\"56\"><span style=\"font-family: courier new, courier, monospace;\">0x12<\/span><\/td>\n<td style=\"height: 18px; width: 178.922px;\" width=\"180\">N\/A<\/td>\n<td style=\"height: 18px; width: 399.719px;\" width=\"407\">Terminates by calling <span style=\"font-family: courier new, courier, monospace;\">ExitProcess<\/span>.<\/td>\n<\/tr>\n<tr style=\"height: 18px;\">\n<td style=\"height: 18px; width: 55.3594px;\" width=\"56\"><span style=\"font-family: courier new, courier, monospace;\">0x13<\/span><\/td>\n<td style=\"height: 18px; width: 178.922px;\" width=\"180\">N\/A<\/td>\n<td style=\"height: 18px; width: 399.719px;\" width=\"407\">Removes persistence then terminates by calling <span style=\"font-family: courier new, courier, monospace;\">ExitProcess<\/span>.<\/td>\n<\/tr>\n<tr style=\"height: 72px;\">\n<td style=\"height: 72px; width: 55.3594px;\" width=\"56\"><span style=\"font-family: courier new, courier, monospace;\">0x14<\/span><\/td>\n<td style=\"height: 72px; width: 178.922px;\" width=\"180\"><span style=\"font-family: courier new, courier, monospace;\"><function_name\/><\/span><br \/><span style=\"font-family: courier new, courier, monospace;\"><bof_object\/><\/span><br \/><span style=\"font-family: courier new, courier, monospace;\"><function_arguments\/><\/span><\/td>\n<td style=\"height: 72px; width: 399.719px;\" width=\"407\">Loads a Beacon Object File in memory and calls <span style=\"font-family: courier new, courier, monospace;\"><function_name\/><\/span> with <span style=\"font-family: courier new, courier, monospace;\"><function_arguments\/><\/span> as parameters, then sends the completion status.<br \/>See below for additional details.<\/td>\n<\/tr>\n<tr style=\"height: 90px;\">\n<td style=\"height: 90px; width: 55.3594px;\" width=\"56\"><span style=\"font-family: courier new, courier, monospace;\">0x16<\/span><\/td>\n<td style=\"height: 90px; width: 178.922px;\" width=\"180\"><span style=\"font-family: courier new, courier, monospace;\"><command_line\/><\/span><br \/><span style=\"font-family: courier new, courier, monospace;\"><execution_timeout\/><\/span><br \/><span style=\"font-family: courier new, courier, monospace;\"><pe_file\/><\/span><\/td>\n<td style=\"height: 90px; width: 399.719px;\" width=\"407\">Executes the provided PE file by spawning a new SparroWocky process with the <span style=\"font-family: courier new, courier, monospace;\">c<\/span> parameter and standard I\/O and error streams redirected to the pipe <span style=\"font-family: courier new, courier, monospace;\">\\\\.\\pipe\\ccpipe<\/span>. The arguments are written to the new process\u2019s <span style=\"font-family: courier new, courier, monospace;\">stdin<\/span>, then the output of the new process is read and sent to the C&amp;C server.<\/td>\n<\/tr>\n<tr style=\"height: 54px;\">\n<td style=\"height: 54px; width: 55.3594px;\" width=\"56\"><span style=\"font-family: courier new, courier, monospace;\">0x17<\/span><\/td>\n<td style=\"height: 54px; width: 178.922px;\" width=\"180\"><span style=\"font-family: courier new, courier, monospace;\"><command\/><\/span><\/td>\n<td style=\"height: 54px; width: 399.719px;\" width=\"407\">Executes <span style=\"font-family: courier new, courier, monospace;\"><command\/><\/span> by spawning <span style=\"font-family: courier new, courier, monospace;\">cmd.exe<\/span> with standard I\/O and error streams redirected to two dedicated anonymous pipes.<\/td>\n<\/tr>\n<tr style=\"height: 72px;\">\n<td style=\"height: 72px; width: 55.3594px;\" width=\"56\"><span style=\"font-family: courier new, courier, monospace;\">0x1A*<\/span><\/td>\n<td style=\"height: 72px; width: 178.922px;\" width=\"180\"><span style=\"font-family: courier new, courier, monospace;\"><ip_address\/><\/span><br \/><span style=\"font-family: courier new, courier, monospace;\"><port\/><\/span><\/td>\n<td style=\"height: 72px; width: 399.719px;\" width=\"407\">Connects to the provided IP address (via TCP\/IP) and creates a thread to forward the traffic between the remote machine and the C&amp;C server. The completion status is sent to the C&amp;C server.<\/td>\n<\/tr>\n<tr style=\"height: 162px;\">\n<td style=\"height: 162px; width: 55.3594px;\" width=\"56\"><span style=\"font-family: courier new, courier, monospace;\">0x1B<\/span><\/td>\n<td style=\"height: 162px; width: 178.922px;\" width=\"180\">String of semicolon-separated values starting with two unknown values followed by the IP address and port number on which to listen<\/td>\n<td style=\"height: 162px; width: 399.719px;\" width=\"407\">Internally named <span style=\"font-family: courier new, courier, monospace;\">PortmapReverseServer<\/span>, it accepts TCP connections and forwards traffic to the C&amp;C server.<br \/>For each accepted connection, a new connection to the C&amp;C server is established and a first packet is sent containing the byte sequence <span style=\"font-family: courier new, courier, monospace;\">13 12 11 09<\/span> (hex). The listener code then sends the machine GUID followed by the received arguments and the list of connections opened so far. The code proceeds to handle the forwarding of the traffic between the distant machine and the C&amp;C server.<\/td>\n<\/tr>\n<tr style=\"height: 72px;\">\n<td style=\"height: 72px; width: 55.3594px;\" width=\"56\"><span style=\"font-family: courier new, courier, monospace;\">0x1C<\/span><\/td>\n<td style=\"height: 72px; width: 178.922px;\" width=\"180\">Same as <span style=\"font-family: courier new, courier, monospace;\">0x1B<\/span><\/td>\n<td style=\"height: 72px; width: 399.719px;\" width=\"407\">Closes the <span style=\"font-family: courier new, courier, monospace;\">PortmapReverseServer<\/span> connection specified by the provided IP address and port.<br \/>The list of remaining open connections is sent to the C&amp;C server.<\/td>\n<\/tr>\n<tr style=\"height: 36px;\">\n<td style=\"height: 36px; width: 55.3594px;\" width=\"56\"><span style=\"font-family: courier new, courier, monospace;\">0x1D<\/span><\/td>\n<td style=\"height: 36px; width: 178.922px;\" width=\"180\">N\/A<\/td>\n<td style=\"height: 36px; width: 399.719px;\" width=\"407\">Returns a list of all <span style=\"font-family: courier new, courier, monospace;\">PortmapReverseServer<\/span> connections to the C&amp;C server.<\/td>\n<\/tr>\n<tr style=\"height: 36px;\">\n<td style=\"height: 36px; width: 55.3594px;\" width=\"56\"><span style=\"font-family: courier new, courier, monospace;\">0x1E<\/span><\/td>\n<td style=\"height: 36px; width: 178.922px;\" width=\"180\">Path to the new working directory<\/td>\n<td style=\"height: 36px; width: 399.719px;\" width=\"407\">Sets the specified current working directory and returns the CWD to the C&amp;C server.<\/td>\n<\/tr>\n<tr style=\"height: 18px;\">\n<td style=\"height: 18px; width: 55.3594px;\" width=\"56\"><span style=\"font-family: courier new, courier, monospace;\">0x1F<\/span><\/td>\n<td style=\"height: 18px; width: 178.922px;\" width=\"180\">N\/A<\/td>\n<td style=\"height: 18px; width: 399.719px;\" width=\"407\">Returns the current working directory to the C&amp;C server.<\/td>\n<\/tr>\n<tr style=\"height: 36px;\">\n<td style=\"height: 36px; width: 55.3594px;\" width=\"56\"><span style=\"font-family: courier new, courier, monospace;\">0x20<\/span><\/td>\n<td style=\"height: 36px; width: 178.922px;\" width=\"180\">Path to the target directory<\/td>\n<td style=\"height: 36px; width: 399.719px;\" width=\"407\">Creates the specified directory, sending the completion status to the C&amp;C server.<\/td>\n<\/tr>\n<tr style=\"height: 36px;\">\n<td style=\"height: 36px; width: 55.3594px;\" width=\"56\"><span style=\"font-family: courier new, courier, monospace;\">0x21<\/span><\/td>\n<td style=\"height: 36px; width: 178.922px;\" width=\"180\">N\/A<\/td>\n<td style=\"height: 36px; width: 399.719px;\" width=\"407\">Returns the list of logical drives and their <a href=\"https:\/\/learn.microsoft.com\/en-us\/windows\/win32\/api\/fileapi\/nf-fileapi-getdrivetypea#return-value\">type<\/a> to the C&amp;C server.<\/td>\n<\/tr>\n<tr style=\"height: 36px;\">\n<td style=\"height: 36px; width: 55.3594px;\" width=\"56\"><span style=\"font-family: courier new, courier, monospace;\">0x22<\/span><\/td>\n<td style=\"height: 36px; width: 178.922px;\" width=\"180\">Path to the target directory<\/td>\n<td style=\"height: 36px; width: 399.719px;\" width=\"407\">Returns a list of the contents of the specified directory, their sizes and last-write times, collected via <a href=\"https:\/\/learn.microsoft.com\/en-us\/windows\/win32\/api\/fileapi\/nf-fileapi-findfirstfilew\">FindFirstFileW<\/a>.<\/td>\n<\/tr>\n<tr style=\"height: 18px;\">\n<td style=\"height: 18px; width: 55.3594px;\" width=\"56\"><span style=\"font-family: courier new, courier, monospace;\">0x23<\/span><\/td>\n<td style=\"height: 18px; width: 178.922px;\" width=\"180\">Path of the file to delete<\/td>\n<td style=\"height: 18px; width: 399.719px;\" width=\"407\">Deletes the specified file and returns the completion status.<\/td>\n<\/tr>\n<tr style=\"height: 36px;\">\n<td style=\"height: 36px; width: 55.3594px;\" width=\"56\"><span style=\"font-family: courier new, courier, monospace;\">0x24<\/span><\/td>\n<td style=\"height: 36px; width: 178.922px;\" width=\"180\">Source and destination paths<\/td>\n<td style=\"height: 36px; width: 399.719px;\" width=\"407\">Copies the specified file to the specified location and returns the completion status.<\/td>\n<\/tr>\n<tr style=\"height: 36px;\">\n<td style=\"height: 36px; width: 55.3594px;\" width=\"56\"><span style=\"font-family: courier new, courier, monospace;\">0x25<\/span><\/td>\n<td style=\"height: 36px; width: 178.922px;\" width=\"180\">Source and destination paths<\/td>\n<td style=\"height: 36px; width: 399.719px;\" width=\"407\">Moves the specified file to the specified location and returns the completion status.<\/td>\n<\/tr>\n<tr style=\"height: 36px;\">\n<td style=\"height: 36px; width: 55.3594px;\" width=\"56\"><span style=\"font-family: courier new, courier, monospace;\">0x26<\/span><\/td>\n<td style=\"height: 36px; width: 178.922px;\" width=\"180\">Path of the file to rename and the desired new name<\/td>\n<td style=\"height: 36px; width: 399.719px;\" width=\"407\">Renames the specified file to the specified new name and returns the completion status.<\/td>\n<\/tr>\n<tr style=\"height: 54px;\">\n<td style=\"height: 54px; width: 55.3594px;\" width=\"56\"><span style=\"font-family: courier new, courier, monospace;\">0x27*<\/span><\/td>\n<td style=\"height: 54px; width: 178.922px;\" width=\"180\">File offset and target file path<\/td>\n<td style=\"height: 54px; width: 399.719px;\" width=\"407\">Sends the file size, creation, last access, and last write timestamps, and the contents of the specified file, read from the specified offset in chunks of 4,096 bytes.<\/td>\n<\/tr>\n<tr style=\"height: 54px;\">\n<td style=\"height: 54px; width: 55.3594px;\" width=\"56\"><span style=\"font-family: courier new, courier, monospace;\">0x28*<\/span><\/td>\n<td style=\"height: 54px; width: 178.922px;\" width=\"180\">Target file path to write to<\/td>\n<td style=\"height: 54px; width: 399.719px;\" width=\"407\">Sends the current size of the specified file then receives the additional file contents in 4,096-byte chunks, appending them to the target file in a loop.<\/td>\n<\/tr>\n<tr style=\"height: 108px;\">\n<td style=\"height: 108px; width: 55.3594px;\" width=\"56\"><span style=\"font-family: courier new, courier, monospace;\">0x29<\/span><\/td>\n<td style=\"height: 108px; width: 178.922px;\" width=\"180\">N\/A<\/td>\n<td style=\"height: 108px; width: 399.719px;\" width=\"407\">Enumerates display devices and associated settings, returning for each active display device:<br \/>\u00b7 device name,<br \/>\u00b7 whether it is the main display,<br \/>\u00b7 width (pixels), and<br \/>\u00b7 height (pixels).<\/td>\n<\/tr>\n<tr style=\"height: 144px;\">\n<td style=\"height: 144px; width: 55.3594px;\" width=\"56\"><span style=\"font-family: courier new, courier, monospace;\">0x2A<\/span><\/td>\n<td style=\"height: 144px; width: 178.922px;\" width=\"180\">Display device name<\/td>\n<td style=\"height: 144px; width: 399.719px;\" width=\"407\">Takes a screenshot periodically by sending an initial JPG screenshot with its dimensions (width and height) via command ID <span style=\"font-family: courier new, courier, monospace;\">0x2C<\/span>.<br \/>Every 500\u00a0ms, if no new commands are received, a new screenshot is taken, and the difference from the previous screenshot is sent to the C&amp;C server. Changed blocks of pixels in these subsequent screenshots are sent along with coordinates (x, y) and dimensions via command ID <span style=\"font-family: courier new, courier, monospace;\">0x2D<\/span>.<\/td>\n<\/tr>\n<tr style=\"height: 54px;\">\n<td style=\"height: 54px; width: 55.3594px;\" width=\"56\"><span style=\"font-family: courier new, courier, monospace;\">0x2E<\/span><\/td>\n<td style=\"height: 54px; width: 178.922px;\" width=\"180\">N\/A<\/td>\n<td style=\"height: 54px; width: 399.719px;\" width=\"407\">Returns session IDs and usernames of enumerated remote sessions on the system, collected via <a href=\"https:\/\/learn.microsoft.com\/en-us\/windows\/win32\/api\/wtsapi32\/nf-wtsapi32-wtsenumeratesessionsw\">WTSEnumerateSessionsW<\/a>.<\/td>\n<\/tr>\n<tr style=\"height: 54px;\">\n<td style=\"height: 54px; width: 55.3594px;\" width=\"56\"><span style=\"font-family: courier new, courier, monospace;\">0x2F<\/span><\/td>\n<td style=\"height: 54px; width: 178.922px;\" width=\"180\">Session ID of the target user session (retrieved via command <span style=\"font-family: courier new, courier, monospace;\">0x2E<\/span>)<\/td>\n<td style=\"height: 54px; width: 399.719px;\" width=\"407\">Spawns a new instance of SparroWocky (with option <span style=\"font-family: courier new, courier, monospace;\">s<\/span>) by duplicating the token associated with the specified session ID and calling <a href=\"https:\/\/learn.microsoft.com\/en-us\/windows\/win32\/api\/processthreadsapi\/nf-processthreadsapi-createprocessasuserw\">CreateProcessAsUserW<\/a>.<\/td>\n<\/tr>\n<tr style=\"height: 36px;\">\n<td style=\"height: 36px; width: 55.3594px;\" width=\"56\"><span style=\"font-family: courier new, courier, monospace;\">0x30<\/span><br \/><span style=\"font-family: courier new, courier, monospace;\">0x31<\/span><\/td>\n<td style=\"height: 36px; width: 178.922px;\" width=\"180\">N\/A<\/td>\n<td style=\"height: 36px; width: 399.719px;\" width=\"407\">Echoes the command ID back to the C&amp;C server.<\/td>\n<\/tr>\n<tr style=\"height: 72px;\">\n<td style=\"height: 72px; width: 55.3594px;\" width=\"56\"><span style=\"font-family: courier new, courier, monospace;\">0x33<\/span><\/td>\n<td style=\"height: 72px; width: 178.922px;\" width=\"180\"><span style=\"font-family: courier new, courier, monospace;\"><command\/><\/span><\/td>\n<td style=\"height: 72px; width: 399.719px;\" width=\"407\">Executes <span style=\"font-family: courier new, courier, monospace;\"><command\/><\/span> in the current directory by calling <a href=\"https:\/\/learn.microsoft.com\/en-us\/windows\/win32\/api\/processthreadsapi\/nf-processthreadsapi-createprocessw\">CreateProcess<\/a> with <span style=\"font-family: courier new, courier, monospace;\">lpCommandLine<\/span> set to <span style=\"font-family: courier new, courier, monospace;\"><command\/><\/span> and <span style=\"font-family: courier new, courier, monospace;\">lpCurrentDirectory<\/span> set to the CWD. The PID of the newly created process is returned to the C&amp;C server.<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>* Hardcoded command.<\/p>\n<p>Command <span style=\"font-family: courier new, courier, monospace;\">0x14<\/span> uses a slightly modified version of <a href=\"https:\/\/github.com\/trustedsec\/COFFLoader\/blob\/7460a2f00cdeb530c748f940ccec824662830605\/COFFLoader.c#L191\">RunCOFF<\/a> from the open-source <a href=\"https:\/\/github.com\/trustedsec\/COFFLoader\">COFF Loader<\/a> project to load and execute a <a href=\"https:\/\/hstechdocs.helpsystems.com\/manuals\/cobaltstrike\/current\/userguide\/content\/topics\/beacon-object-files_main.htm\">Beacon Object File<\/a> (BOF). A BOF is a position-independent Common Object File Format (COFF) executable that is meant to be run within the memory of an implant. BOFs were first introduced in Cobalt Strike and have since been adopted by other popular red-teaming frameworks such as <a href=\"https:\/\/bruteratel.com\/\">Brute Ratel<\/a>, <a href=\"https:\/\/docs.metasploit.com\/docs\/using-metasploit\/advanced\/meterpreter\/meterpreter-executebof-command.html\">Metasploit<\/a>, and <a href=\"https:\/\/sliver.sh\/docs\/?name=BOF+and+COFF+Support\">Sliver<\/a>. The change to RunCOFF resides in the resolution of imported symbols. SparroWocky redirects calls to external libraries in the BOF to a stack-spoofing subroutine. This effectively hides and proxies calls made by the BOF object. Once the object is loaded, the BOF loader finds and executes <span style=\"font-family: courier new, courier, monospace;\">function_name<\/span>, passing the arguments provided in <span style=\"font-family: courier new, courier, monospace;\">function_arguments<\/span>. The ability to load BOFs allows FamousSparrow to use existing modules and tools designed to work with this file type.<\/p>\n<h5>Self-deletion<\/h5>\n<p>As described in the <em><a href=\"#Argument-controlled behavior\">Argument-controlled behavior<\/a> <\/em>section, SparroWocky can delete itself entirely from the system. This can be done from the C&amp;C server via command <span style=\"font-family: courier new, courier, monospace;\">0x13<\/span>. First, the persistence mechanism previously set is removed and then the batch file shown in Figure 4 is created and executed.<\/p>\n<pre style=\"font-family: 'Courier New', Courier, monospace !important; border: 1px solid #ccc; padding: 10px; background-color: #f5f5f5;\"><code style=\"font-family: 'Courier New', Courier, monospace !important;\">@echo off\ntimeout \/t 2\ndel \"<legitimate_executable>\" \/f \/q\ndel \"<loader_library>\" \/f \/q\ndel \"<payload_filepath>\" \/f \/q\ndel \"%%0\" \/f \/q\\n<\/payload_filepath><\/loader_library><\/legitimate_executable><\/code><\/pre>\n<p style=\"text-align: center;\"><em>Figure 4. Batch file for self-deletion<\/em><\/p>\n<p>This deletes the files used by the backdoor: the legitimate executable, the side-loading library, and the payload file. The batch file deletes itself at the end of the script.<\/p>\n<h5>Anti-analysis techniques<a id=\"Anti-analysis techniques\"\/><\/h5>\n<p>SparroWocky employs a few techniques to complicate its analysis and to evade security software that may be in place. A common technique that the backdoor uses is dynamic API resolution via API hashing, but the backdoor also uses more interesting ones, described below.<\/p>\n<h5>SilentMoonwalk<\/h5>\n<p>The first noteworthy technique is called SilentMoonwalk, which essentially provides a way to forge fake call stacks. Its purpose is to prevent analysis tools and products from inspecting the true caller of specific functions that are frequently monitored, such as Windows API functions. This method requires a few initialization steps:<\/p>\n<ul>\n<li>Finding the offset of <span style=\"font-family: courier new, courier, monospace;\">RtlUserThreadStart<\/span> and <span style=\"font-family: courier new, courier, monospace;\">BaseThreadInitThunk<\/span>, two functions that are usually found at the start (or bottom) of any call stack.<\/li>\n<li>Finding a JOP (jump-oriented programming) and a <a href=\"https:\/\/en.wikipedia.org\/wiki\/Return-oriented_programming\">ROP<\/a> (return-oriented programming) gadget in the legitimate <span style=\"font-family: courier new, courier, monospace;\">kernel32.dll<\/span> library to restore the original call stack.<\/li>\n<\/ul>\n<p>Once these requirements are met, when SparroWocky makes an obfuscated call to a Windows API function, it first saves the current context (registers); next, it forges a fake stack using the gadgets found previously, and then inserts the address of a stack and context restoration routine. This makes it appear as if the calls to Windows API functions are originating from <span style=\"font-family: courier new, courier, monospace;\">RtlUserThreadStart<\/span> and <span style=\"font-family: courier new, courier, monospace;\">BaseThreadInitThunk<\/span>. Figure 5 shows the call stack view from a debugging session using WinDbg.<\/p>\n<figure class=\"image\"><img decoding=\"async\" title=\"Figure 5. WinDbg call stack view of an obfuscated call to Sleep\" src=\"https:\/\/web-assets.esetstatic.com\/wls\/2026\/09-26\/sparrowocky\/figure-5.png\" alt=\"Figure 5. WinDbg call stack view of an obfuscated call to Sleep\" width=\"\" height=\"\"\/><figcaption><em>Figure 5. WinDbg call stack view of an obfuscated call to <\/em><span style=\"font-family: courier new, courier, monospace;\">Sleep<\/span><\/figcaption><\/figure>\n<p>In the case of SparroWocky, this technique is used to obfuscate calls made by BOF-formatted plugins (command <span style=\"font-family: courier new, courier, monospace;\">0x14<\/span>) or by the statically linked MinHook hooking library.<\/p>\n<h5>Concealing the thread start address<\/h5>\n<p>SparroWocky uses the MinHook library to hook the <a href=\"https:\/\/learn.microsoft.com\/en-us\/windows\/win32\/api\/processthreadsapi\/nf-processthreadsapi-createthread\">CreateThread<\/a> function in order to conceal the original <span style=\"font-family: courier new, courier, monospace;\">lpStartAddress<\/span> parameter from security products. Essentially, any thread created by SparroWocky would have <span style=\"font-family: courier new, courier, monospace;\">AnimateWindow<\/span> as the starting address, which would likely be considered legitimate by a security product. The patch applied to <span style=\"font-family: courier new, courier, monospace;\">AnimateWindow<\/span> turns it into a <a href=\"https:\/\/en.wikipedia.org\/wiki\/Trampoline_(computing)#Low-level_programming\">trampoline<\/a> that simply executes the original start address, as illustrated in Figure 6.<\/p>\n<figure class=\"image\"><img decoding=\"async\" title=\"Figure 6. AnimateWindow API is patched to execute the original start address\" src=\"https:\/\/web-assets.esetstatic.com\/wls\/2026\/09-26\/sparrowocky\/figure-6.png\" alt=\"Figure 6. AnimateWindow API is patched to execute the original start address\" width=\"\" height=\"\"\/><figcaption><em>Figure 6. <\/em><span style=\"font-family: courier new, courier, monospace;\">AnimateWindow<\/span><em> API is patched to execute the original start address<\/em><\/figcaption><\/figure>\n<h5>Host process camouflage for dynamically loaded PEs<a id=\"Host process camouflage for dynamically loaded PEs\"\/><\/h5>\n<p>The last notable piece of code from SparroWocky is its custom PE loader, used when executed with option c. While implementing PE loaders is pretty much routine for malware authors, SparroWocky authors took it a step further and integrated host process camouflage.<\/p>\n<p>As described in Table 2, when SparroWocky is executed with the c option, it loads a PE file in memory and executes it. If the file is not passed as an argument, the PE loader parses the specified command line to extract the file\u2019s name. It searches for that filename in the <span style=\"font-family: courier new, courier, monospace;\">C:\\Windows\\System32\\<\/span> directory, but most importantly it retrieves the English <a href=\"https:\/\/en.wikipedia.org\/wiki\/Multilingual_User_Interface\">localization MUI<\/a> file associated with the target PE (stored as <span style=\"font-family: courier new, courier, monospace;\">C:\\Windows\\System32\\en-US\\<exe_name>.mui<\/exe_name><\/span>). In that case, the PE file is loaded in memory, and a few hooks are set to make sure any calls made by the loaded PE file to retrieve resource data, such as <span style=\"font-family: courier new, courier, monospace;\">RtlLoadString<\/span> or <span style=\"font-family: courier new, courier, monospace;\">RtlFindMessage<\/span>, are redirected to the <span style=\"font-family: courier new, courier, monospace;\">.mui<\/span> data. This process mirrors normal behavior of Windows when loading PEs, and reduces the risk of unexpected errors.<\/p>\n<p>The command line retrieved from <span style=\"font-family: courier new, courier, monospace;\">Stdin<\/span> is parsed and SparroWocky hooks the following functions, which are used to retrieve information about command line arguments, to make them point to this command line:<\/p>\n<ul>\n<li><span style=\"font-family: courier new, courier, monospace;\">GetCommandline[AW]<\/span><\/li>\n<li><span style=\"font-family: courier new, courier, monospace;\">__(w}getmainargs<\/span><\/li>\n<li><span style=\"font-family: courier new, courier, monospace;\">__p___argc<\/span><\/li>\n<li><span style=\"font-family: courier new, courier, monospace;\">__p___{w}argv<\/span><\/li>\n<\/ul>\n<p>The PE loader is also able to register the exception handlers of the newly loaded executable \u2013 an unusual, yet critical, addition \u2013 since it allows exceptions to be handled correctly.<\/p>\n<p>Finally, before calling the entry point of the loaded PE file, SparroWocky forges and inserts a fake <a href=\"https:\/\/learn.microsoft.com\/en-us\/windows\/win32\/api\/winternl\/ns-winternl-peb_ldr_data\">LDR_DATA_TABLE_ENTRY<\/a> structure in the doubly linked list of the <span style=\"font-family: courier new, courier, monospace;\">PEB_LDR_DATA<\/span> structure. This doubly linked list is used by Windows to keep track of loaded modules and is usually monitored by security products. Figure 7 shows a snippet of the code used to set some of its fields.<\/p>\n<figure class=\"image\"><img decoding=\"async\" title=\"Figure 7. SparroWocky forges an LDR_DATA_TABLE_ENTRY structure\" src=\"https:\/\/web-assets.esetstatic.com\/wls\/2026\/09-26\/sparrowocky\/figure-7.png\" alt=\"Figure 7. SparroWocky forges an LDR_DATA_TABLE_ENTRY structure\" width=\"\" height=\"\"\/><figcaption><em>Figure 7. SparroWocky forges an <\/em><span style=\"font-family: courier new, courier, monospace;\">LDR_DATA_TABLE_ENTRY<\/span><em> structure<\/em><\/figcaption><\/figure>\n<p>This last technique shows that SparroWocky authors possess a deep understanding of the Windows PE loading mechanism and are willing to go the extra mile to camouflage the host process and confuse monitoring software.<\/p>\n<h4>Network protocol<\/h4>\n<p>To communicate with its C&amp;C server, SparroWocky uses the TLS encryption protocol. Under the hood, the backdoor uses the Mbed TLS library and the only element worth mentioning is that it uses the personalization string <span style=\"font-family: courier new, courier, monospace;\">acdbenus<\/span> when initializing the deterministic random bit generator, as seen in Figure 8.<\/p>\n<figure class=\"image\"><img decoding=\"async\" title=\"Figure 8. Custom initialization of Mbed TLS random bit generator\" src=\"https:\/\/web-assets.esetstatic.com\/wls\/2026\/09-26\/sparrowocky\/figure-8.png\" alt=\"Figure 8. Custom initialization of Mbed TLS random bit generator\" width=\"\" height=\"\"\/><figcaption><em>Figure 8. Custom initialization of Mbed TLS random bit generator<\/em><\/figcaption><\/figure>\n<p>Before the initial TLS handshake, a TCP connection is established with the C&amp;C server using one of three connection modes:<\/p>\n<p>A connection mode of <span style=\"font-family: courier new, courier, monospace;\">0<\/span> means that SparroWocky uses the proxy currently configured on the machine or a direct TCP connection if no system proxy is configured. This configuration is retrieved by querying the ProxyServer registry value located under the registry key <span style=\"font-family: courier new, courier, monospace;\">HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings<\/span>. If the connection to the proxy server is not successful, SparroWocky tries to connect via mode <span style=\"font-family: courier new, courier, monospace;\">1<\/span>, then mode <span style=\"font-family: courier new, courier, monospace;\">2<\/span>.<\/p>\n<p>Connection mode <span style=\"font-family: courier new, courier, monospace;\">1<\/span> represents a connection via an HTTP proxy. This connection uses either the <a href=\"https:\/\/learn.microsoft.com\/en-us\/dotnet\/framework\/wcf\/feature-details\/understanding-http-authentication\">Negotiate<\/a> (Kerberos or NTLM) or Basic authentication scheme with the username and password provided in the configuration. Both authentication methods use generic HTTP headers with the User-Agent string set to <span style=\"font-family: courier new, courier, monospace;\">Mozilla\/5.0<\/span>.<\/p>\n<p>Connection mode <span style=\"font-family: courier new, courier, monospace;\">2<\/span> uses a <a href=\"https:\/\/en.wikipedia.org\/wiki\/SOCKS#SOCKS5\">SOCKS5<\/a> proxy without authentication (<span style=\"font-family: courier new, courier, monospace;\">AUTH<\/span> field set to <span style=\"font-family: courier new, courier, monospace;\">0x00<\/span>) or with a username and password (<span style=\"font-family: courier new, courier, monospace;\">AUTH<\/span> field set to <span style=\"font-family: courier new, courier, monospace;\">0x02<\/span>). The values used by the latter are provided in the configuration.<\/p>\n<h5>Command messages<\/h5>\n<p>Once the TLS handshake is complete, SparroWocky sends the bytes <span style=\"font-family: courier new, courier, monospace;\">0x11223344<\/span> (big-endian) to indicate that it is ready to receive commands in the main session. The backdoor uses a simple format to receive commands and send results, as illustrated in Figure 9.<\/p>\n<figure class=\"image\"><img decoding=\"async\" title=\"Figure 9. Command message format\" src=\"https:\/\/web-assets.esetstatic.com\/wls\/2026\/09-26\/sparrowocky\/figure-9.png\" alt=\"Figure 9. Command message format\" width=\"\" height=\"\"\/><figcaption><em>Figure 9. Command message format<\/em><\/figcaption><\/figure>\n<p>If the <span style=\"font-family: courier new, courier, monospace;\">command_arg_size<\/span> field does not equal <span style=\"font-family: courier new, courier, monospace;\">0<\/span>, then additional data is to be received or sent after the header. In that case, the data (command arguments or results) is encrypted via RC4, and each command message uses a newly generated eight-byte key, which is sent in the header.<\/p>\n<h2>Network infrastructure<\/h2>\n<p>SparroWocky uses the IP address of its C&amp;C servers, which is generally running on port 443, to connect directly. We have also seen it running on port 8080 in some cases. While we have observed some self-signed certificates being reused across multiple servers, we do not have a reliable generic fingerprint.<\/p>\n<h2>Conclusion<\/h2>\n<p>Over the latter half of 2025 and the first half of 2026, FamousSparrow had been focusing on targets in Latin America. This represents a shift from its previous global targeting. To go along with this change, the group has developed SparroWocky, which replaced SparrowDoor as its main implant. While it doesn\u2019t appear to be based on the same codebase, we can see that SparroWocky still shares some of the functionality and concepts that were present in the group\u2019s previous backdoor, which we analyzed in our previous blogpost. SparroWocky uses more complex defense evasion techniques to stay under the radar.<\/p>\n<p>FamousSparrow still uses open-source offensive tooling for its own malicious ends. Previously, these tools were mainly used side by side with the group\u2019s backdoor. With SparroWocky, we can observe that it also has the development capabilities to integrate open-source code directly into its own custom backdoor.<\/p>\n<blockquote>\n<div><em>For any inquiries about our research published on WeLiveSecurity, please contact us at threatintel@eset.com.\u00a0<\/em><\/div>\n<div><em>ESET Research offers private APT intelligence reports and data feeds. For any inquiries about this service, visit the <a href=\"https:\/\/www.eset.com\/int\/business\/services\/threat-intelligence\/?utm_source=welivesecurity.com&amp;utm_medium=referral&amp;utm_campaign=wls-research&amp;utm_content=beware-sparrowock-backdoor-bites-commands-catch&amp;sfdccampaignid=7011n0000017htTAAQ\" target=\"_blank\" rel=\"noopener\">ESET Threat Intelligence<\/a> page.<\/em><\/div>\n<\/blockquote>\n<h2>IoCs<\/h2>\n<p>A comprehensive list of indicators of compromise (IoCs) and samples can be found in <a href=\"https:\/\/github.com\/eset\/malware-ioc\/tree\/master\/famoussparrow\/\">our GitHub repository<\/a>.<\/p>\n<h3>Files<\/h3>\n<table border=\"1\" width=\"643\" cellspacing=\"0\" cellpadding=\"0\">\n<thead>\n<tr>\n<td width=\"179\"><strong>SHA-1<\/strong><\/td>\n<td width=\"142\"><strong>Filename<\/strong><\/td>\n<td width=\"161\"><strong>Detection<\/strong><\/td>\n<td width=\"161\"><strong>Description<\/strong><\/td>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td width=\"179\"><span style=\"font-family: courier new, courier, monospace;\">3209689E509205CCDB7E<wbr\/>49062B7B407DDC23CAC1<\/span><\/td>\n<td width=\"142\"><span style=\"font-family: courier new, courier, monospace;\">winfsp-x64.dll<\/span><\/td>\n<td width=\"161\">Win64\/Agent.HUP<\/td>\n<td width=\"161\">SparroWocky loader.<\/td>\n<\/tr>\n<tr>\n<td width=\"179\"><span style=\"font-family: courier new, courier, monospace;\">52C6646759CF6037BB17<wbr\/>466203631C4BD794532F<\/span><\/td>\n<td width=\"142\"><span style=\"font-family: courier new, courier, monospace;\">winfsp-x64.dll<\/span><\/td>\n<td width=\"161\">Win64\/Agent.HUP<\/td>\n<td width=\"161\">SparroWocky loader.<\/td>\n<\/tr>\n<tr>\n<td width=\"179\"><span style=\"font-family: courier new, courier, monospace;\">99E7070B5AF24A0FE1E6<wbr\/>FEBE5954B03CB385E91F<\/span><\/td>\n<td width=\"142\"><span style=\"font-family: courier new, courier, monospace;\">DukeQt.dll<\/span><\/td>\n<td width=\"161\">Win64\/Agent.ISF<\/td>\n<td width=\"161\">SparroWocky loader.<\/td>\n<\/tr>\n<tr>\n<td width=\"179\"><span style=\"font-family: courier new, courier, monospace;\">44F0A22B143B79FA760B<wbr\/>F31E14C8FFF714C8A2A1<\/span><\/td>\n<td width=\"142\">N\/A (in-memory)<\/td>\n<td width=\"161\">Win64\/Agent.ASW<\/td>\n<td width=\"161\">SparroWocky backdoor.<\/td>\n<\/tr>\n<tr>\n<td width=\"179\"><span style=\"font-family: courier new, courier, monospace;\">9AA9FF61BC63CCAB907<wbr\/>4FE837F39C980CA9DDC8C<\/span><\/td>\n<td width=\"142\">N\/A (in-memory)<\/td>\n<td width=\"161\">Win64\/Agent.ASW<\/td>\n<td width=\"161\">SparroWocky backdoor.<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h3>Network<\/h3>\n<table style=\"height: 1274px;\" border=\"1\" width=\"643\" cellspacing=\"0\" cellpadding=\"0\">\n<thead>\n<tr style=\"height: 50px;\">\n<td style=\"height: 50px;\" width=\"151\"><strong>IP<\/strong><\/td>\n<td style=\"height: 50px;\" width=\"66\"><strong>Domain<\/strong><\/td>\n<td style=\"height: 50px;\" width=\"170\"><strong>Hosting provider<\/strong><\/td>\n<td style=\"height: 50px;\" width=\"95\"><strong>First seen<\/strong><\/td>\n<td style=\"height: 50px;\" width=\"161\"><strong>Details<\/strong><\/td>\n<\/tr>\n<\/thead>\n<tbody>\n<tr style=\"height: 68px;\">\n<td style=\"height: 68px;\" width=\"151\"><span style=\"font-family: courier new, courier, monospace;\">38.54.57[.]17<\/span><\/td>\n<td style=\"height: 68px;\" width=\"66\">N\/A<\/td>\n<td style=\"height: 68px;\" width=\"170\">LightNode\u2011BR<\/td>\n<td style=\"height: 68px;\" width=\"95\">2026\u201102\u201125<\/td>\n<td style=\"height: 68px;\" width=\"161\">SparroWocky C&amp;C server.<\/td>\n<\/tr>\n<tr style=\"height: 68px;\">\n<td style=\"height: 68px;\" width=\"151\"><span style=\"font-family: courier new, courier, monospace;\">38.60.197[.]55<\/span><\/td>\n<td style=\"height: 68px;\" width=\"66\">N\/A<\/td>\n<td style=\"height: 68px;\" width=\"170\">Kaopu Cloud HK Limited<\/td>\n<td style=\"height: 68px;\" width=\"95\">2026\u201103\u201116<\/td>\n<td style=\"height: 68px;\" width=\"161\">SparroWocky C&amp;C server.<\/td>\n<\/tr>\n<tr style=\"height: 68px;\">\n<td style=\"height: 68px;\" width=\"151\"><span style=\"font-family: courier new, courier, monospace;\">38.60.209[.]106<\/span><\/td>\n<td style=\"height: 68px;\" width=\"66\">N\/A<\/td>\n<td style=\"height: 68px;\" width=\"170\">Kaopu Cloud HK Limited<\/td>\n<td style=\"height: 68px;\" width=\"95\">2026\u201102\u201126<\/td>\n<td style=\"height: 68px;\" width=\"161\">SparroWocky C&amp;C server.<\/td>\n<\/tr>\n<tr style=\"height: 68px;\">\n<td style=\"height: 68px;\" width=\"151\"><span style=\"font-family: courier new, courier, monospace;\">38.60.224[.]51<\/span><\/td>\n<td style=\"height: 68px;\" width=\"66\">N\/A<\/td>\n<td style=\"height: 68px;\" width=\"170\">Kaopu Cloud HK Limited<\/td>\n<td style=\"height: 68px;\" width=\"95\">2026\u201102\u201125<\/td>\n<td style=\"height: 68px;\" width=\"161\">SparroWocky C&amp;C server.<\/td>\n<\/tr>\n<tr style=\"height: 68px;\">\n<td style=\"height: 68px;\" width=\"151\"><span style=\"font-family: courier new, courier, monospace;\">38.60.224[.]235<\/span><\/td>\n<td style=\"height: 68px;\" width=\"66\">N\/A<\/td>\n<td style=\"height: 68px;\" width=\"170\">Kaopu Cloud HK Limited<\/td>\n<td style=\"height: 68px;\" width=\"95\">2026\u201102\u201124<\/td>\n<td style=\"height: 68px;\" width=\"161\">SparroWocky C&amp;C server.<\/td>\n<\/tr>\n<tr style=\"height: 68px;\">\n<td style=\"height: 68px;\" width=\"151\"><span style=\"font-family: courier new, courier, monospace;\">38.60.241[.]65<\/span><\/td>\n<td style=\"height: 68px;\" width=\"66\">N\/A<\/td>\n<td style=\"height: 68px;\" width=\"170\">Cogent Communications<\/td>\n<td style=\"height: 68px;\" width=\"95\">2026\u201103\u201110<\/td>\n<td style=\"height: 68px;\" width=\"161\">SparroWocky C&amp;C server.<\/td>\n<\/tr>\n<tr style=\"height: 68px;\">\n<td style=\"height: 68px;\" width=\"151\"><span style=\"font-family: courier new, courier, monospace;\">38.60.241[.]127<\/span><\/td>\n<td style=\"height: 68px;\" width=\"66\">N\/A<\/td>\n<td style=\"height: 68px;\" width=\"170\">Cogent Communications<\/td>\n<td style=\"height: 68px;\" width=\"95\">2026\u201103\u201104<\/td>\n<td style=\"height: 68px;\" width=\"161\">SparroWocky C&amp;C server.<\/td>\n<\/tr>\n<tr style=\"height: 68px;\">\n<td style=\"height: 68px;\" width=\"151\"><span style=\"font-family: courier new, courier, monospace;\">38.60.241[.]193<\/span><\/td>\n<td style=\"height: 68px;\" width=\"66\">N\/A<\/td>\n<td style=\"height: 68px;\" width=\"170\">KaopuCloud\u2011BR<\/td>\n<td style=\"height: 68px;\" width=\"95\">2026\u201101\u201122<\/td>\n<td style=\"height: 68px;\" width=\"161\">SparroWocky C&amp;C server.<\/td>\n<\/tr>\n<tr style=\"height: 68px;\">\n<td style=\"height: 68px;\" width=\"151\"><span style=\"font-family: courier new, courier, monospace;\">77.111.101[.]40<\/span><\/td>\n<td style=\"height: 68px;\" width=\"66\">N\/A<\/td>\n<td style=\"height: 68px;\" width=\"170\">Latitude.sh<\/td>\n<td style=\"height: 68px;\" width=\"95\">2026\u201105\u201120<\/td>\n<td style=\"height: 68px;\" width=\"161\">SparroWocky C&amp;C server.<\/td>\n<\/tr>\n<tr style=\"height: 68px;\">\n<td style=\"height: 68px;\" width=\"151\"><span style=\"font-family: courier new, courier, monospace;\">91.148.134[.]115<\/span><\/td>\n<td style=\"height: 68px;\" width=\"66\">N\/A<\/td>\n<td style=\"height: 68px;\" width=\"170\">Charles\u2011R Paquet<\/td>\n<td style=\"height: 68px;\" width=\"95\">2026\u201106\u201117<\/td>\n<td style=\"height: 68px;\" width=\"161\">SparroWocky C&amp;C server.<\/td>\n<\/tr>\n<tr style=\"height: 68px;\">\n<td style=\"height: 68px;\" width=\"151\"><span style=\"font-family: courier new, courier, monospace;\">130.94.101[.]82<\/span><\/td>\n<td style=\"height: 68px;\" width=\"66\">N\/A<\/td>\n<td style=\"height: 68px;\" width=\"170\">NTT America, Inc.<\/td>\n<td style=\"height: 68px;\" width=\"95\">2026\u201102\u201126<\/td>\n<td style=\"height: 68px;\" width=\"161\">SparroWocky C&amp;C server.<\/td>\n<\/tr>\n<tr style=\"height: 68px;\">\n<td style=\"height: 68px;\" width=\"151\"><span style=\"font-family: courier new, courier, monospace;\">140.99.164[.]199<\/span><\/td>\n<td style=\"height: 68px;\" width=\"66\">N\/A<\/td>\n<td style=\"height: 68px;\" width=\"170\">Private Customer<\/td>\n<td style=\"height: 68px;\" width=\"95\">2026\u201102\u201126<\/td>\n<td style=\"height: 68px;\" width=\"161\">SparroWocky C&amp;C server.<\/td>\n<\/tr>\n<tr style=\"height: 68px;\">\n<td style=\"height: 68px;\" width=\"151\"><span style=\"font-family: courier new, courier, monospace;\">149.104.87[.]228<\/span><\/td>\n<td style=\"height: 68px;\" width=\"66\">N\/A<\/td>\n<td style=\"height: 68px;\" width=\"170\">Lightnode\u2011MX<\/td>\n<td style=\"height: 68px;\" width=\"95\">2026\u201102\u201124<\/td>\n<td style=\"height: 68px;\" width=\"161\">SparroWocky C&amp;C server.<\/td>\n<\/tr>\n<tr style=\"height: 68px;\">\n<td style=\"height: 68px;\" width=\"151\"><span style=\"font-family: courier new, courier, monospace;\">149.104.90[.]203<\/span><\/td>\n<td style=\"height: 68px;\" width=\"66\">N\/A<\/td>\n<td style=\"height: 68px;\" width=\"170\">BEDGE CO LIMITED<\/td>\n<td style=\"height: 68px;\" width=\"95\">2026\u201101\u201122<\/td>\n<td style=\"height: 68px;\" width=\"161\">SparroWocky C&amp;C server.<\/td>\n<\/tr>\n<tr style=\"height: 68px;\">\n<td style=\"height: 68px;\" width=\"151\"><span style=\"font-family: courier new, courier, monospace;\">216.238.92[.]2<\/span><\/td>\n<td style=\"height: 68px;\" width=\"66\">N\/A<\/td>\n<td style=\"height: 68px;\" width=\"170\">The Constant Company, LLC<\/td>\n<td style=\"height: 68px;\" width=\"95\">2026\u201102\u201125<\/td>\n<td style=\"height: 68px;\" width=\"161\">SparroWocky C&amp;C server.<\/td>\n<\/tr>\n<tr style=\"height: 68px;\">\n<td style=\"height: 68px;\" width=\"151\"><span style=\"font-family: courier new, courier, monospace;\">216.238.105[.]53<\/span><\/td>\n<td style=\"height: 68px;\" width=\"66\">N\/A<\/td>\n<td style=\"height: 68px;\" width=\"170\">The Constant Company, LLC<\/td>\n<td style=\"height: 68px;\" width=\"95\">2026\u201101\u201122<\/td>\n<td style=\"height: 68px;\" width=\"161\">SparroWocky C&amp;C server.<\/td>\n<\/tr>\n<tr style=\"height: 68px;\">\n<td style=\"height: 68px;\" width=\"151\"><span style=\"font-family: courier new, courier, monospace;\">216.238.110[.]120<\/span><\/td>\n<td style=\"height: 68px;\" width=\"66\">N\/A<\/td>\n<td style=\"height: 68px;\" width=\"170\">The Constant Company, LLC<\/td>\n<td style=\"height: 68px;\" width=\"95\">2025\u201112\u201111<\/td>\n<td style=\"height: 68px;\" width=\"161\">SparroWocky C&amp;C server.<\/td>\n<\/tr>\n<tr style=\"height: 68px;\">\n<td style=\"height: 68px;\" width=\"151\"><span style=\"font-family: courier new, courier, monospace;\">216.238.121[.]164<\/span><\/td>\n<td style=\"height: 68px;\" width=\"66\">N\/A<\/td>\n<td style=\"height: 68px;\" width=\"170\">The Constant Company, LLC<\/td>\n<td style=\"height: 68px;\" width=\"95\">2026\u201103\u201116<\/td>\n<td style=\"height: 68px;\" width=\"161\">SparroWocky C&amp;C server.<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2>MITRE ATT&amp;CK techniques<\/h2>\n<p>This table was built using <a href=\"https:\/\/attack.mitre.org\/resources\/versions\/\"><em>version 19<\/em><\/a> of the MITRE ATT&amp;CK framework.<\/p>\n<table border=\"1\" width=\"642\" cellspacing=\"0\" cellpadding=\"0\">\n<thead>\n<tr>\n<td width=\"113\"><strong>Tactic<\/strong><\/td>\n<td width=\"113\"><strong>ID<\/strong><\/td>\n<td width=\"151\"><strong>Name<\/strong><\/td>\n<td width=\"265\"><strong>Description<\/strong><\/td>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td rowspan=\"3\" width=\"113\"><strong>Resource Development<\/strong><\/td>\n<td width=\"113\"><a href=\"https:\/\/attack.mitre.org\/versions\/v19\/techniques\/T1583\/003\" target=\"_blank\" rel=\"noopener\">T1583.003<\/a><\/td>\n<td width=\"151\">Acquire Infrastructure: Virtual Private Server<\/td>\n<td width=\"265\">FamousSparrow has acquired servers to use for C&amp;C and delivery servers for SparroWocky.<\/td>\n<\/tr>\n<tr>\n<td width=\"113\"><a href=\"https:\/\/attack.mitre.org\/versions\/v19\/techniques\/T1587\/001\" target=\"_blank\" rel=\"noopener\">T1587.001<\/a><\/td>\n<td width=\"151\">Develop Capabilities: Malware<\/td>\n<td width=\"265\">FamousSparrow has developed SparroWocky and its loader.<\/td>\n<\/tr>\n<tr>\n<td width=\"113\"><a href=\"https:\/\/attack.mitre.org\/versions\/v19\/techniques\/T1608\/001\" target=\"_blank\" rel=\"noopener\">T1608.001<\/a><\/td>\n<td width=\"151\">Stage Capabilities: Upload Malware<\/td>\n<td width=\"265\">FamousSparrow has uploaded the SparroWocky trident loader to attacker-controlled delivery servers.<\/td>\n<\/tr>\n<tr>\n<td width=\"113\"><strong>Initial Access<\/strong><\/td>\n<td width=\"113\"><a href=\"https:\/\/attack.mitre.org\/versions\/v19\/techniques\/T1190\" target=\"_blank\" rel=\"noopener\">T1190<\/a><\/td>\n<td width=\"151\">Exploit Public-Facing Application<\/td>\n<td width=\"265\">FamousSparrow gained access to targets\u2019 networks by exploiting publicly reachable Exchange servers.<\/td>\n<\/tr>\n<tr>\n<td rowspan=\"5\" width=\"113\"><strong>Execution<\/strong><\/td>\n<td width=\"113\"><a href=\"https:\/\/attack.mitre.org\/versions\/v19\/techniques\/T1059\/003\" target=\"_blank\" rel=\"noopener\">T1059.003<\/a><\/td>\n<td width=\"151\">Command and Scripting Interpreter: Windows Command Shell<\/td>\n<td width=\"265\">SparroWocky has functionality to run commands via the Windows command shell.<\/td>\n<\/tr>\n<tr>\n<td width=\"113\"><a href=\"https:\/\/attack.mitre.org\/versions\/v19\/techniques\/T1569\/002\" target=\"_blank\" rel=\"noopener\">T1569.002<\/a><\/td>\n<td width=\"151\">System Services: Service Execution<\/td>\n<td width=\"265\">When establishing persistence via a service, SparroWocky starts the service directly.<\/td>\n<\/tr>\n<tr>\n<td width=\"113\"><a href=\"https:\/\/attack.mitre.org\/versions\/v19\/techniques\/T1106\" target=\"_blank\" rel=\"noopener\">T1106<\/a><\/td>\n<td width=\"151\">Native API<\/td>\n<td width=\"265\">SparroWocky uses the native Windows API.<\/td>\n<\/tr>\n<tr>\n<td width=\"113\"><a href=\"https:\/\/attack.mitre.org\/versions\/v19\/techniques\/T1559\" target=\"_blank\" rel=\"noopener\">T1559<\/a><\/td>\n<td width=\"151\">Inter-Process Communication<\/td>\n<td width=\"265\">SparroWocky uses an interprocess communication mechanism to synchronize instances when a new one is launched.<\/td>\n<\/tr>\n<tr>\n<td width=\"113\"><a href=\"https:\/\/attack.mitre.org\/versions\/v19\/techniques\/T1574\/001\" target=\"_blank\" rel=\"noopener\">T1574.001<\/a><\/td>\n<td width=\"151\">Hijack Execution Flow: DLL<\/td>\n<td width=\"265\">The SparroWocky loader is executed via DLL side-loading.<\/td>\n<\/tr>\n<tr>\n<td rowspan=\"2\" width=\"113\"><strong>Persistence<\/strong><\/td>\n<td width=\"113\"><a href=\"https:\/\/attack.mitre.org\/versions\/v19\/techniques\/T1547\/001\" target=\"_blank\" rel=\"noopener\">T1547.001<\/a><\/td>\n<td width=\"151\">Boot or Logon Autostart Execution: Registry Run Keys \/ Startup Folder<\/td>\n<td width=\"265\">SparroWocky can persist via a registry Run key.<\/td>\n<\/tr>\n<tr>\n<td width=\"113\"><a href=\"https:\/\/attack.mitre.org\/versions\/v19\/techniques\/T1543\/003\" target=\"_blank\" rel=\"noopener\">T1543.003<\/a><\/td>\n<td width=\"151\">Create or Modify System Process: Windows Service<\/td>\n<td width=\"265\">SparroWocky can persist via a Windows service.<\/td>\n<\/tr>\n<tr>\n<td rowspan=\"10\" width=\"113\"><strong>Stealth<\/strong><\/td>\n<td width=\"113\"><a href=\"https:\/\/attack.mitre.org\/versions\/v19\/techniques\/T1134\/002\" target=\"_blank\" rel=\"noopener\">T1134.002<\/a><\/td>\n<td width=\"151\">Access Token Manipulation: Create Process with Token<\/td>\n<td width=\"265\">SparroWocky can create processes using a token obtained from any existing user session.<\/td>\n<\/tr>\n<tr>\n<td width=\"113\"><a href=\"https:\/\/attack.mitre.org\/versions\/v19\/techniques\/T1140\" target=\"_blank\" rel=\"noopener\">T1140<\/a><\/td>\n<td width=\"151\">Deobfuscate\/Decode Files or Information<\/td>\n<td width=\"265\">SparroWocky\u2019s loader retrieves the configuration and payload via RC4 decryption of the content of a file with a custom format.<\/td>\n<\/tr>\n<tr>\n<td width=\"113\"><a href=\"https:\/\/attack.mitre.org\/versions\/v19\/techniques\/T1480\/002\" target=\"_blank\" rel=\"noopener\">T1480.002<\/a><\/td>\n<td width=\"151\">Execution Guardrails: Mutual Exclusion<\/td>\n<td width=\"265\">SparroWocky uses a mutex to prevent multiple instances from running concurrently.<\/td>\n<\/tr>\n<tr>\n<td width=\"113\"><a href=\"https:\/\/attack.mitre.org\/versions\/v19\/techniques\/T1564\/010\" target=\"_blank\" rel=\"noopener\">T1564.010<\/a><\/td>\n<td width=\"151\">Hide Artifacts: Process Argument Spoofing<\/td>\n<td width=\"265\">When loading an external PE file, SparroWocky hooks functions to retrieve its command line arguments from stdin.<\/td>\n<\/tr>\n<tr>\n<td width=\"113\"><a href=\"https:\/\/attack.mitre.org\/versions\/v19\/techniques\/T1027\/007\" target=\"_blank\" rel=\"noopener\">T1027.007<\/a><\/td>\n<td width=\"151\">Obfuscated Files or Information: Dynamic API Resolution<\/td>\n<td width=\"265\">SparroWocky uses a custom API hashing algorithm to dynamically resolve API functions at runtime.<\/td>\n<\/tr>\n<tr>\n<td width=\"113\"><a href=\"https:\/\/attack.mitre.org\/versions\/v19\/techniques\/T1620\" target=\"_blank\" rel=\"noopener\">T1620<\/a><\/td>\n<td width=\"151\">Reflective Code Loading<\/td>\n<td width=\"265\">The SparroWocky reflectively loads its payload into memory. SparroWocky can reflectively load and execute PE and BOF objects.<\/td>\n<\/tr>\n<tr>\n<td width=\"113\"><a href=\"https:\/\/attack.mitre.org\/versions\/v19\/techniques\/T1070\/004\" target=\"_blank\" rel=\"noopener\">T1070.004<\/a><\/td>\n<td width=\"151\">Indicator Removal: File Deletion<\/td>\n<td width=\"265\">SparroWocky can delete itself from the compromised machine.<\/td>\n<\/tr>\n<tr>\n<td width=\"113\"><a href=\"https:\/\/attack.mitre.org\/versions\/v19\/techniques\/T1070\/009\" target=\"_blank\" rel=\"noopener\">T1070.009<\/a><\/td>\n<td width=\"151\">Indicator Removal: Clear Persistence<\/td>\n<td width=\"265\">SparroWocky can remove its persistence mechanism from the compromised machine.<\/td>\n<\/tr>\n<tr>\n<td width=\"113\"><a href=\"https:\/\/attack.mitre.org\/versions\/v19\/techniques\/T1036\/001\" target=\"_blank\" rel=\"noopener\">T1036.001<\/a><\/td>\n<td width=\"151\">Masquerading: Invalid Code Signature<\/td>\n<td width=\"265\">The SparroWocky loader keeps the now invalid signature of the legitimate module it is impersonating.<\/td>\n<\/tr>\n<tr>\n<td width=\"113\"><a href=\"https:\/\/attack.mitre.org\/versions\/v19\/techniques\/T1036\/004\" target=\"_blank\" rel=\"noopener\">T1036.004<\/a><\/td>\n<td width=\"151\">Masquerading: Masquerade Task or Service<\/td>\n<td width=\"265\">SparroWocky uses legitimate or generic names and descriptions for its persistence service.<\/td>\n<\/tr>\n<tr>\n<td rowspan=\"5\" width=\"113\"><strong>Discovery<\/strong><\/td>\n<td width=\"113\"><a href=\"https:\/\/attack.mitre.org\/versions\/v19\/techniques\/T1083\" target=\"_blank\" rel=\"noopener\">T1083<\/a><\/td>\n<td width=\"151\">File and Directory Discovery<\/td>\n<td width=\"265\">SparroWocky can list files and directories on mapped drives.<\/td>\n<\/tr>\n<tr>\n<td width=\"113\"><a href=\"https:\/\/attack.mitre.org\/versions\/v19\/techniques\/T1680\" target=\"_blank\" rel=\"noopener\">T1680<\/a><\/td>\n<td width=\"151\">Local Storage Discovery<\/td>\n<td width=\"265\">SparroWocky can retrieve information about mapped storage devices.<\/td>\n<\/tr>\n<tr>\n<td width=\"113\"><a href=\"https:\/\/attack.mitre.org\/versions\/v19\/techniques\/T1082\" target=\"_blank\" rel=\"noopener\">T1082<\/a><\/td>\n<td width=\"151\">System Information Discovery<\/td>\n<td width=\"265\">SparroWocky can collect information about the system it is running on, such as the Windows version, hostname, and the IP addresses of network interfaces.<\/td>\n<\/tr>\n<tr>\n<td width=\"113\"><a href=\"https:\/\/attack.mitre.org\/versions\/v19\/techniques\/T1033\" target=\"_blank\" rel=\"noopener\">T1033<\/a><\/td>\n<td width=\"151\">System Owner\/User Discovery<\/td>\n<td width=\"265\">SparroWocky can retrieve the username of the current user and of any user with an active session.<\/td>\n<\/tr>\n<tr>\n<td width=\"113\"><a href=\"https:\/\/attack.mitre.org\/versions\/v19\/techniques\/T1120\" target=\"_blank\" rel=\"noopener\">T1120<\/a><\/td>\n<td width=\"151\">Peripheral Device Discovery<\/td>\n<td width=\"265\">SparroWocky can retrieve information about connected display devices.<\/td>\n<\/tr>\n<tr>\n<td rowspan=\"2\" width=\"113\"><strong>Collection<\/strong><\/td>\n<td width=\"113\"><a href=\"https:\/\/attack.mitre.org\/versions\/v19\/techniques\/T1005\" target=\"_blank\" rel=\"noopener\">T1005<\/a><\/td>\n<td width=\"151\">Data from Local System<\/td>\n<td width=\"265\">SparroWocky can exfiltrate files from mapped storage.<\/td>\n<\/tr>\n<tr>\n<td width=\"113\"><a href=\"https:\/\/attack.mitre.org\/versions\/v19\/techniques\/T1113\" target=\"_blank\" rel=\"noopener\">T1113<\/a><\/td>\n<td width=\"151\">Screen Capture<\/td>\n<td width=\"265\">SparroWocky can periodically capture screenshots.<\/td>\n<\/tr>\n<tr>\n<td rowspan=\"5\" width=\"113\"><strong>Command and Control<\/strong><\/td>\n<td width=\"113\"><a href=\"https:\/\/attack.mitre.org\/versions\/v19\/techniques\/T1573\/002\" target=\"_blank\" rel=\"noopener\">T1573.002<\/a><\/td>\n<td width=\"151\">Encrypted Channel: Asymmetric Cryptography<\/td>\n<td width=\"265\">SparroWocky uses TLS, which uses asymmetric cryptography in its handshake.<\/td>\n<\/tr>\n<tr>\n<td width=\"113\"><a href=\"https:\/\/attack.mitre.org\/versions\/v19\/techniques\/T1573\/001\" target=\"_blank\" rel=\"noopener\">T1573.001<\/a><\/td>\n<td width=\"151\">Encrypted Channel: Symmetric Cryptography<\/td>\n<td width=\"265\">SparroWocky uses RC4 to encrypt the information it exfiltrates.<\/td>\n<\/tr>\n<tr>\n<td width=\"113\"><a href=\"https:\/\/attack.mitre.org\/versions\/v19\/techniques\/T1090\/001\" target=\"_blank\" rel=\"noopener\">T1090.001<\/a><\/td>\n<td width=\"151\">Proxy: Internal Proxy<\/td>\n<td width=\"265\">SparroWocky can proxy connections between the C&amp;C server and another remote machine.<\/td>\n<\/tr>\n<tr>\n<td width=\"113\"><a href=\"https:\/\/attack.mitre.org\/versions\/v19\/techniques\/T1090\/002\" target=\"_blank\" rel=\"noopener\">T1090.002<\/a><\/td>\n<td width=\"151\">Proxy: External Proxy<\/td>\n<td width=\"265\">SparroWocky can use an HTTP or SOCKS5 proxy to connect to its C&amp;C server.<\/td>\n<\/tr>\n<tr>\n<td width=\"113\"><a href=\"https:\/\/attack.mitre.org\/versions\/v19\/techniques\/T1095\" target=\"_blank\" rel=\"noopener\">T1095<\/a><\/td>\n<td width=\"151\">Non-Application Layer Protocol<\/td>\n<td width=\"265\">SparroWocky uses TLS over TCP to communicate with its C&amp;C server.<\/td>\n<\/tr>\n<tr>\n<td width=\"113\"><strong>Exfiltration<\/strong><\/td>\n<td width=\"113\"><a href=\"https:\/\/attack.mitre.org\/versions\/v19\/techniques\/T1041\" target=\"_blank\" rel=\"noopener\">T1041<\/a><\/td>\n<td width=\"151\">Exfiltration Over C2 Channel<\/td>\n<td width=\"265\">SparroWocky exfiltrates data through the same connection used to receive commands from the C&amp;C server.<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p><a href=\"https:\/\/www.eset.com\/int\/business\/services\/threat-intelligence\/?utm_source=welivesecurity.com&amp;utm_medium=referral&amp;utm_campaign=wls-research&amp;utm_content=beware-sparrowock-backdoor-bites-commands-catch&amp;sfdccampaignid=7011n0000017htTAAQ\" target=\"_blank\" rel=\"noopener\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/web-assets.esetstatic.com\/wls\/eti-eset-threat-intelligence.png\" alt=\"\" width=\"915\" height=\"296\"\/><\/a><\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>ESET Research\u2019s ongoing monitoring of FamousSparrow has borne fruit once again. Our previous public report on FamousSparrow revealed<\/p>\n","protected":false},"author":1,"featured_media":613,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2],"tags":[],"class_list":["post-612","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-security"],"_links":{"self":[{"href":"https:\/\/escudodigital.uy\/index.php\/wp-json\/wp\/v2\/posts\/612","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/escudodigital.uy\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/escudodigital.uy\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/escudodigital.uy\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/escudodigital.uy\/index.php\/wp-json\/wp\/v2\/comments?post=612"}],"version-history":[{"count":0,"href":"https:\/\/escudodigital.uy\/index.php\/wp-json\/wp\/v2\/posts\/612\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/escudodigital.uy\/index.php\/wp-json\/wp\/v2\/media\/613"}],"wp:attachment":[{"href":"https:\/\/escudodigital.uy\/index.php\/wp-json\/wp\/v2\/media?parent=612"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/escudodigital.uy\/index.php\/wp-json\/wp\/v2\/categories?post=612"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/escudodigital.uy\/index.php\/wp-json\/wp\/v2\/tags?post=612"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}