SparroWocky is a modular C++ Windows backdoor used by the China-aligned cyberespionage group FamousSparrow. First observed by at least August 2025, it rapidly replaced the group’s earlier SparrowDoor implant and has been used primarily against government entities in Latin America, including targets in Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico, and Venezuela. The malware performs host and user reconnaissance, executes commands and arbitrary files, enumerates files, directories, drives, displays, and user sessions, captures screenshots, transfers and exfiltrates files, and operates as a TCP proxy. It can also execute Beacon Object Files and PE payloads directly in memory, enabling modular post-compromise functionality. SparroWocky uses TLS-protected command-and-control communications and RC4 encryption for transmitted data. It can maintain persistence through Windows services or Registry Run keys. Deployment uses a DLL side-loading chain comprising a legitimate executable, a malicious DLL, and an encrypted payload, with the final backdoor reflectively mapped into memory. Its defense-evasion features include stripped PE signatures, dynamic API resolution, API hooking, call-stack spoofing, concealed thread start addresses, and forged Windows loader metadata intended to make reflectively loaded modules appear legitimate.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
FamousSparrow has deployed SparroWocky, a new custom backdoor that rapidly replaced SparrowDoor as the group's primary implant.
23 distinct techniques documented for this family, organized by ATT&CK tactic.
« le fichier .dat chiffré contenant la configuration et le payload » ; « Payload PE chargé en mémoire sans écriture disque [...] avec valeurs magiques MZ/PE supprimées ».
Its custom PE loader performs additional host-process camouflage. When loading executable code into memory, SparroWocky can construct fake Windows loader structures and insert them into the Process Environment Block's module tracking structures.
« Le fichier .dat commence par le magic 0x11328712, suivi des tailles de configuration et payload, et d’une clé RC4 de 16 octets. »
The malware collects extensive host information, including... network-interface IP addresses.
“[It] collects information including hostnames, usernames, domain names, Windows versions and IP addresses.”
The malware collects extensive host information, including the computer and user names, domain, Windows version, network-interface IP addresses, malware process ID, executable location, and other configuration information.
The malware supports direct connections as well as connections through system-configured, HTTP, and SOCKS5 proxies.
61 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
17 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A modular C++ backdoor used by FamousSparrow for remote command execution, reconnaissance, file transfer and exfiltration, screenshots, TCP proxying, in-memory PE execution, and extensible in-memory BOF execution. It uses DLL side-loading, reflective loading, stack spoofing, API hooking, and fabricated Windows loader structures to evade detection.
A modular C++ cyberespionage backdoor used by FamousSparrow. It collects host and user information, captures screenshots, executes commands, exfiltrates files over TLS with RC4 encryption, provides TCP proxying, and can persist through services or Registry Run keys. It is deployed through DLL sideloading and reflectively loaded after PE magic values are removed to evade detection; it also uses stack spoofing for anti-analysis.
A modular C++ backdoor used by FamousSparrow. It executes arbitrary files and commands, proxies TCP traffic, collects host information, exfiltrates files, captures screenshots, and loads Beacon Object Files in memory. It uses RC4-encrypted configuration/payload data and TLS C2 communications, and persists through a Windows service or Registry Run key. Its evasion includes API hashing, call-stack spoofing, reflective PE loading, and DLL side-loading deployment.
A modular C++ espionage backdoor used by Salt Typhoon/FamousSparrow. It communicates with C2 infrastructure over TLS, uses anti-analysis and security-evasion mechanisms including API hooking, call-stack spoofing, API hashing, and in-memory COFF plugins, and is deployed through DLL side-loading. It can collect system and remote-session information, steal or delete files, take periodic screenshots, manage sessions and persistence, and spawn additional instances.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.