Skip to main content

Command Palette

Search for a command to run...

SparroWocky & SilentMoonwalk Technique: When Backdoor Spoofs Call Stack Disables EDR

Updated
•13 min read•View as Markdown
SparroWocky & SilentMoonwalk Technique: When Backdoor Spoofs Call Stack Disables EDR

Overview

When cybersecurity researchers analyzed the memory of a compromised government server in Latin America, they found Lewis Carroll's nonsense poem Jabberwocky sitting quietly inside a sophisticated C++ code. It's not a hacker joke. It is the signature marking the appearance of SparroWocky - a new generation underground weapon developed by the notorious APT group FamousSparrow (China).

In just a few months, FamousSparrow quietly killed its "predecessor" SparrowDoor to put all its resources into a large-scale espionage campaign: 90% of the attacked targets were Latin American government agencies, including the agency that holds decision-making power in the strategic seaport trade dispute at the Panama Canal.

What makes SparroWocky so dangerous that it "cripples" the observation capabilities of today's leading EDR systems? How can a malicious code make EDR believe that its data draining behavior is just a legitimate Windows (AnimateWindow) dimming effect? The analysis below will unpack the entire technical "black box" of SparroWocky.

FamousSparrow - Notorious Hacker Group

Who is FamousSparrow?

FamousSparrow is a professional cyber warfare group identified as affiliated with China, maintaining sophisticated espionage campaigns since at least 2019 until now. This group is identified by cybersecurity analysts thanks to the exclusive development and operation of two advanced backdoor lines: SparrowDoor (period 2021–2025) and the new generation upgrade SparroWocky (from mid-2025).

In terms of identity intelligence, research from Trend Micro shows that FamousSparrow has a huge overlap in C2 infrastructure, target audience and TTPs chain with the Earth Estries group. In addition, although international media such as the Wall Street Journal have mentioned the connection between FamousSparrow and Salt Typhoon - the APT group accused of infiltrating US telecommunications eavesdropping infrastructure, independent research organizations such as ESET still choose to monitor these two groups separately because they have not recorded enough direct overlap in technical indicators (IOCs).

Operational History and Evolution

FamousSparrow's development is divided into 3 distinct strategic stages:

Phase 1 (2019 – Early 2021): Defining goals & Global hotel chain

  • In the early stages of its existence, FamousSparrow attracted attention with sophisticated espionage campaigns targeting international luxury hotel chains. The group's motive during this period was to track the travel itineraries, stay schedules and personal information of government officials, high-ranking businessmen and international diplomatic corps.

Phase 2 (2021 – First half of 2025): Explosion through ProxyLogon & SparrowDoor

  • In March 2021, FamousSparrow became one of the first APT groups to successfully take advantage of the dangerous Zero-day ProxyLogon vulnerability (CVE-2021-26855) on Microsoft Exchange Server just a few hours after the information was leaked.

Phase 3 (Second Half 2025 – Present): Latin America Shift & SparroWocky Era

  • From July 2025, FamousSparrow suddenly changed its strategy, spending up to 90% of its attack frequency targeting 8 Latin American countries (Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico, Venezuela).

Detailed Event Timeline Table

Time Event / Phase Weapons & Techniques (TTPs) Objectives & Real-World Impact
2019 Operational Launch Early custom malware; basic reconnaissance tools Targeted international 5-star hotel chains to collect information on stays and movements of government officials and diplomatic delegations
03/2021 Exchange Zero-Day Exploitation Surge ProxyLogon (CVE-2021-26855) exploitation + SparrowDoor (v1) backdoor Mass compromise of Exchange servers belonging to governments, international organizations, consulting firms, and law firms worldwide
2021–2024 Global-Scale Operations SparrowDoor (v2/v3) + DLL side-loading + open-source tools (Mimikatz, Nbtscan, Cobalt Strike) Expanded cyber-espionage operations across Europe, North America, Asia, and the Middle East
07/2025 Strategic Pivot to Latin America Preparation of new C2 infrastructure (Kaopu Cloud, LightNode, Cogent, etc.) 90% of observed targets shifted toward Latin America, including Argentina, Ecuador, Guatemala, Panama, Peru, and others
08/2025 First SparroWocky Deployment Trident Loader (side-loading via winfsp-x64.dll / DukeQt.dll) + SparroWocky delivered through SparrowDoor Beginning of the transition campaign and gradual replacement of the legacy SparrowDoor backdoor
17/11/2025 SparroWocky v1.8 Compilation SilentMoonwalk (stack spoofing) + COFF Loader (BOF execution) + PEB LDR_DATA_TABLE_ENTRY forging v1.8 incorporated advanced techniques designed to evade modern EDR/AV memory inspection
Late 2025 – Early 2026 Strategic Infrastructure Targeting SparroWocky v1.8 (TLS/RC4 C2, 500-ms screen diffing, TCP reverse proxy) Targeted a Panamanian government organization involved in disputes concerning strategic port concessions around the Panama Canal
17/09/2026 ESET Research Disclosure Detailed analysis of malware architecture, evasion techniques, and IOC set ESET Research publicly documented SparroWocky and its role in the evolution of the FamousSparrow toolset, including the transition away from SparrowDoor

Attack Chain Analysis

Stage 1: Initial Access

FamousSparrow doesn't waste time on rampant Phishing campaigns. The team focuses on scanning for announced vulnerabilities (N-day) or Zero-day vulnerabilities on Microsoft Exchange servers exposed directly to the Internet. Taking advantage of the initial access from the Exchange Server, the attacker gains command execution rights and begins escalating privileges within the internal network.

Stage 2: Load malicious code via Trident Loader (Defense Evasion)

Instead of directly dropping the malicious .exe executable file - which is easily detected by Endpoint solutions, the attacker uses the Trident Loader technique (triple file model):

  1. A system-valid executable file.

  2. A DLL library file preparing to patch the .text code area.

  3. The .dat encrypted data file contains the configuration and kernel of the SparroWocky malware.

Stage 3: Execution & In-Memory Stealth

The patched DLL will decrypt the .dat file. Before putting SparroWocky into RAM (Reflective Loading), load the malicious code and delete all Magic Header characters MZ and PE. This technique makes it impossible for automatic memory scanning tools to recognize this as a PE executable file. At the same time, the malware activates the SilentMoonwalk technique to hide API calls (Call Stack Spoofing).

Phase 4: Control & Expansion (Command & Control)

SparroWocky initiates a TLS encrypted transmission channel (via the Mbed TLS library) to the C2 server. The malware supports Enterprise Proxy circumvention mechanisms (HTTP Negotiate/Basic and SOCKS5). Hackers can push down Beacon Object File (BOF) modules to collect information, clone other users' Access Tokens (WTSEnumerateSessionsW), or turn the victim machine into a TCP Reverse Proxy (PortmapReverseServer) to penetrate deeper into the internal network.

Phase 5: Data Collection & Self-destruction (Exfiltration & Cleanup)

The malware possesses an extremely bandwidth-saving screen tracking mechanism: sending an original JPG image, then every 500ms only sends the changed part (diff blocks) with pixel coordinates. When completing a mission or receiving an order to retreat, SparroWocky automatically removes persistence (Windows Service / Registry) and executes a .bat file to wipe all trace files on the drive.

Technical Deep-Dive

Trident Loader Architecture & Payload Decoding

The sophistication of FamousSparrow's Trident Loader model is that the attacker does not create a completely malicious DLL, but rather abuses a legitimate system DLL file (for example, winfsp-x64.dll or DukeQt.dll).

  1. The sophistication of FamousSparrow's Trident Loader model is that the attacker does not create a completely malicious DLL, but rather abuses a legitimate system DLL file (for example, winfsp-x64.dll or DukeQt.dll).

  2. Payload .dat file structure: The file contains cryptographic malware with a customizable header format:

    • Magic Header (4 bytes): 0x11328712 used to verify file format.

    • Config Size (4 bytes) & Payload Size (4 bytes): Length of configuration data and malicious code.

    • RC4 Key (16 bytes): RC4 decryption key is located at offset 0x0C.

  3. Reflective Loading deletes Header: After decryption with RC4 key, Loader receives SparroWocky's PE payload. At this point, the MZ (0x4D 0x5A) and PE (0x50 0x45) identification bytes have been completely erased. The loader automatically maps PE sections directly into RAM without writing them to the drive, helping to completely avoid Memory Dump tools based on Pattern Matching.

Configuration structure of SparroWocky

SparroWocky's configuration data after the RC4 code is a Tab (\t) delimited character string. This configuration is parsed and stored in memory as a data structure that manages overall network behavior and persistence.

Configuration Field Sample Value Technical Analysis
C&C IP Address 216.238.110[.]120 IP address of the command-and-control (C2) server.
C&C Port 443 Service port used for C2 communication. Port 443 may be used to blend traffic with legitimate HTTPS traffic.
Connection Retry 10 Initial reconnection delay in seconds. Subsequent connection attempts may use randomized timing to reduce the predictability of network activity and introduce jitter.
Proxy Type 0 0: Uses the system proxy configuration or connects directly.
1: HTTP Proxy, supporting Basic or NTLM/Negotiate authentication.
2: SOCKS5 Proxy, supporting anonymous or username/password authentication.
Persistence Type 1 1: Creates a Windows Service.
2: Writes a Registry Run Key.
Service Config ProcAuditManager Name of the Windows service. The service name, display name, and description are designed to appear legitimate and resemble a system process-auditing component, including wording related to tracking process creation and termination.
Registry Config SnapCart Name of the value used for automatic execution under SOFTWARE\Microsoft\Windows\CurrentVersion\Run, located in either HKLM or HKCU depending on the privileges available to the malware.

Techniques to Bypass EDR & Evade Memory (Anti-Analysis)

SparroWocky is equipped with an in-depth set of evasion techniques that few other malware lines have:

  • SilentMoonwalk (Call Stack Spoofing): Spoof Call Stack about kernel32.dll (Disable EDR Tracing)

  • Masking Thread Start Address via AnimateWindow: Masking the Thread's lpStartAddress to a valid graphics API

  • Host Process Camouflage & Fake PEB LDR_DATA_TABLE_ENTRY: Load .mui file and make fake LDR_DATA_TABLE_ENTRY structure

  • Ability to load and run Beacon Object Files (BOF): Load and run directly the Cobalt Strike BOF file wrapped in Stack Spoof

IOC

Hash File

  • 3209689E509205CCDB7E49062B7B407DDC23CAC1

  • 52C6646759CF6037BB17466203631C4BD794532F

  • 99E7070B5AF24A0FE1E6FEBE5954B03CB385E91F

  • 44F0A22B143B79FA760BF31E14C8FFF714C8A2A1

  • 9AA9FF61BC63CCAB9074FE837F39C980CA9DDC8C

Network

  • 38.54.57[.]17

  • 38.60.197[.]55

  • 38.60.209[.]106

  • 38.60.224[.]51

  • 38.60.224[.]235

  • 38.60.241[.]65

  • 38.60.241[.]127

  • 38.60.241[.]193

  • 77.111.101[.]40

  • 91.148.134[.]115

  • 130.94.101[.]82

  • 140.99.164[.]199

  • 149.104.87[.]228

  • 149.104.90[.]203

  • 216.238.92[.]2

  • 216.238.105[.]53

  • 216.238.110[.]120

  • 216.238.121[.]164

Mapping MITRE ATT&CK Framework

Tactic Technique ID Technique Name SparroWocky Behavioral Description
Resource Development T1583.003 Virtual Private Server Acquires VPS infrastructure from providers such as Kaopu Cloud, LightNode, and Cogent for use as C2 infrastructure.
T1587.001 Malware Develops custom malware, including the SparroWocky backdoor and Trident Loader.
Initial Access T1190 Exploit Public-Facing Application Exploits vulnerabilities in Microsoft Exchange Server, including ProxyLogon/N-day vulnerabilities, to obtain initial access.
Execution T1059.003 Windows Command Shell Executes system commands through cmd.exe, including command handling associated with opcode 0x17.
T1569.002 Service Execution Executes a Windows service to support malware operation and persistence.
T1106 Native API Directly invokes native Windows APIs to perform low-level or stealth-oriented operations.
T1559 Inter-Process Communication Uses synchronization mechanisms such as mutexes/shared memory to coordinate execution and prevent duplicate instances.
Persistence T1547.001 Registry Run Keys / Startup Folder Creates an autostart Registry entry under HKLM or HKCU, using the SnapCart value.
T1543.003 Windows Service Creates a masqueraded Windows service named ProcAuditManager.
Defense Evasion T1574.001 DLL Search Order Hijacking Abuses DLL side-loading through files such as winfsp-x64.dll / DukeQt.dll.
T1134.002 Create Process with Token Duplicates or uses an access token associated with another session and invokes CreateProcessAsUserW to create a process in that security context.
T1140 Deobfuscate/Decode Files or Information Decrypts the .dat configuration and payload using the RC4 algorithm.
T1480.002 Mutual Exclusion Uses a mutex to prevent or terminate duplicate/older SparroWocky instances running on the same host.

Expert Comments

The appearance of SparroWocky marks an important turning point in the programming thinking of the FamousSparrow group. If in the past APT groups tended to drop open source malware (such as Cobalt Strike Beacon) as an independent executable file next to the main backdoor, now FamousSparrow has directly embedded open source code (COFF Loader, MinHook, Mbed TLS) into its own C++ source file.

This allows hackers to leverage the flexible power of the BOF (Beacon Object File) module ecosystem without leaving the footprint of commercial frameworks that are susceptible to signature-based detection (EDR).

Challenges for the EDR defense system in Vietnam

SilentMoonwalk (Call Stack Spoofing) technique combined with Masking Thread Start Address (AnimateWindow) and Erasing Magic Bytes (MZ/PE) directly impacts the weaknesses of most commercial EDR solutions being deployed in the Vietnamese market.

Most SOCs today rely on two main alerting mechanisms:

  1. Detect abnormal function call traces (Stack Walk Anomaly).

  2. Scan Unmapped Executable Memory (Memory Inspection).

When SparroWocky fakes a function call trace from a valid kernel32.dll and assigns the execution thread to AnimateWindow, the basic signature/behavior standard EDR system ignores it (false alarm).

Risk of shifting TTPs to Southeast Asia

Although SparroWocky's current attack is focusing 90% of its effort on Latin America for the purpose of gathering geopolitical intelligence, Chinese APT groups (especially affiliated groups such as Earth Estries or Salt Typhoon) have a history of sharing infrastructure, techniques and tools with each other. The introduction of Stack Spoofing and BOF Loading techniques into private commercial malware will soon spread to attack campaigns targeting government agencies and critical infrastructure in Southeast Asia as well as Vietnam.

Defense & Response Recommendations

Enterprise organizations and SOC centers should immediately implement a 3-level defense process:

Instant (Immediate: 0 - 24 hours)

  • Threat Hunting IOCs: Scan all IOCs indicators (Hashes, IPs, Mutex MyMutexName, Service ProcAuditManager, Named Pipe \.\pipe\ccpipe) on the SIEM/EDR system.

  • Check Microsoft Exchange: Check the list of public-facing Exchange servers, make sure the latest security patches from Microsoft are fully installed.

Short-term (Short-term: 1 - 7 days)

  • Hunt for Side-loading DLLs: Set up rules to monitor writing/loading behavior of unusual DLLs in system application folders (especially patched DLLs such as winfsp-x64.dll, DukeQt.dll).

  • Memory Hunting for BOF/COFF Execution: Configure EDR/Memory Scanner to scan Executable memory areas without backing files on the hard disk (Unbacked Executable Memory), especially threads with state created by CreateThread but pointing to graphics APIs (AnimateWindow).

Long-term (Long-term: Strategy)

  • Upgrade EDR to support Advanced Stack Inspection: Equipped with advanced EDR/XDR solutions capable of deeply analyzing the Frame Pointer/Unwind Info structure of the Call Stack instead of simply reading the Return Address.

  • Apply AppLocker / WDAC: Deploy Windows Defender Application Control (WDAC) policy in Enforce mode to block the execution of unsigned DLLs in the system.

References

Chinese hackers use SparroWocky malware in govt espionage attacks

Beware the SparroWock: The backdoor that bites, the commands that catch

Dark Web Scanner: What SparroWocky Reveals About Espionage | DarknetSearch

More from this blog

F

FPT IS Security

1031 posts

Dedicated to providing insightful articles on cybersecurity threat intelligence, aimed at empowering individuals and organizations to navigate the digital landscape safely.