Chinese hackers use SparroWocky malware in govt espionage attacks

Chinese hackers use SparroWocky malware in govt espionage attacks
FamousSparrow has been using a new C++ backdoor called SparroWocky to spy on government organizations across Latin America, replacing its older SparrowDoor malware. ESET says the campaign has targeted multiple countries and appears aimed at gathering intelligence on how Latin American governments respond to U.S. pressure on Chinese economic interests. #FamousSparrow #SparroWocky #SparrowDoor #ESET

Keypoints

  • FamousSparrow deployed SparroWocky in attacks against Latin American government organizations.
  • The campaign has been active for more than a year and replaced SparrowDoor.
  • SparroWocky is a modular C++ backdoor with anti-analysis and evasion features.
  • The malware can execute commands, steal data, capture screenshots, and proxy traffic.
  • ESET found at least 18 C2 addresses and linked the activity to a well-resourced threat group.

Read More: https://www.bleepingcomputer.com/news/security/chinese-hackers-use-sparrowocky-malware-in-govt-espionage-attacks/