The China-linked espionage group FamousSparrow has been using a new backdoor named SparroWocky in attacks on government organizations in Latin America.
The operations have been ongoing for more than a year, with the new malware replacing the previously used SparrowDoor custom backdoor.
ESET researchers observed SparroWocky in attacks targeting organizations in Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico, and Venezuela.
The researchers believe the threat actor's objective was to collect intelligence on Latin American governments’ responses to increasing U.S. pressure on Chinese economic interests.
FamousSparrow victims
Source: ESET
ESET's analysis revealed that SparroWocky is a modular, full-blown C++ backdoor that includes code from open-source projects.
The malware features anti-analysis mechanisms, like manipulating low-level structures in memory and patching code at runtime. SparroWocky's capabilities include:
run commands and executable files
load and execute Beacon Object Files in memory
... continue reading