← Back to Feed

Beware the SparroWock: The backdoor that bites, the commands that catch

September 17, 2026 · WeLiveSecurity · Severity: MEDIUM

ESET researchers document SparroWocky, the new flagship backdoor of the FamousSparrow APT group. The backdoor features a modular architecture with a sophisticated command protocol that allows operators to execute arbitrary commands, manipulate files, and maintain persistent access to compromised networks. ESET's analysis reveals that FamousSparrow has been actively deploying the new backdoor in attacks targeting hospitality and government organizations worldwide, signaling an evolution in the group's toolset and operational capabilities.

Key Takeaways

  • ESET documented SparroWocky, a new modular backdoor from the FamousSparrow APT group that features sophisticated command protocols for executing arbitrary commands and maintaining persistent network access.
  • FamousSparrow has been actively deploying SparroWocky against hospitality and government organizations worldwide, representing a significant evolution in the group's malware toolset and operational scope.
☕ Buy a Coffee