CTIPilot
← Back to Daily brief 2026-09-18
NOTABLENATOB2threat

FamousSparrow retires SparrowDoor for SparroWocky, a modular backdoor with BOF-loading and call-stack spoofing, deployed almost exclusively against Latin American governments

ESET: a China-aligned actor's new backdoor forges call stacks with legitimate kernel32.dll gadgets so its hooked API calls look native

Analysis

ESET documents FamousSparrow's shift to a new flagship backdoor, SparroWocky, replacing SparrowDoor as the group's main implant since August 2025 (ESET, 2026-09-17). From mid-2025 into 2026, 90% of FamousSparrow's observed targets were in Latin America (Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico and Venezuela) with government entities named among the targets, an unusually sustained single-region focus for a China-aligned group ESET otherwise tracks globally; ESET assesses the focus likely reflects Chinese state interest in monitoring regional government reactions to renewed US engagement, citing a Panamanian port-concession dispute as a specific target-motive match (ESET, 2026-09-17). SparroWocky deploys via a "trident loader": a legitimate executable, a side-loading DLL with a patched .text-section entry point that keeps the impersonated module's export table and metadata intact, and an RC4-encrypted .dat payload whose decrypted PE has its MZ/PE header bytes stripped before being reflectively mapped into memory. The backdoor incorporates Mbed TLS for its C2 channel and MinHook for API hooking, and runs a modified TrustedSec COFF loader that executes Cobalt Strike, Brute Ratel, Metasploit and Sliver-compatible Beacon Object Files, redirecting BOF-imported-symbol calls through a stack-spoofing subroutine. Its anti-analysis techniques include a SilentMoonwalk-style call-stack forger that uses JOP/ROP gadgets inside legitimate kernel32.dll so hooked API calls appear to originate from RtlUserThreadStart or BaseThreadInitThunk, and a MinHook-based CreateThread hook that reports the benign-looking AnimateWindow as the thread's start address; for dynamically loaded PE payloads, the backdoor also forges a fake LDR_DATA_TABLE_ENTRY structure in the PEB_LDR_DATA doubly linked list Windows uses to track loaded modules, a list security products routinely monitor. Persistence is operator-configurable via a Windows service or a registry Run key. ESET attributes SparroWocky to FamousSparrow with high confidence, since early attacks show the FamousSparrow-exclusive SparrowDoor deploying the new backdoor directly.

Triage: call-stack forgery targeting RtlUserThreadStart or BaseThreadInitThunk is not something a legitimate application produces; a stack walk that resolves cleanly to one of those two entry points via JOP/ROP gadgets in kernel32.dll, rather than a normal thread-creation call chain, is the discriminator ESET's own analysis supports.

Cited evidence

We believe that this focus is not coincidental and likely reflects China's reaction to various recent US initiatives in the region.

Based on our investigation, we attribute the latest campaign and the SparroWocky backdoor to FamousSparrow with high confidence, since in some of the first attacks involving this backdoor, SparroWocky was deployed by the FamousSparrow-exclusive SparrowDoor.

ESET (WeLiveSecurity) 2026-09-17

Sources1

PROVENANCE

AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.