NCSC analyzes SparrowDoor variant with enhanced capabilities
NCSC published technical analysis of a SparrowDoor malware variant discovered on a UK network in 2021 with expanded capabilities including clipboard logging and API hooking.
The UK National Cyber Security Centre (NCSC) released a malware analysis report examining a new variant of SparrowDoor, a persistent loader and backdoor first documented by ESET in September 2021. This variant was discovered on a UK network during 2021 and demonstrates enhanced capabilities beyond the originally reported version.
SparrowDoor functions as a persistent backdoor that uses XOR encoding to obfuscate its command-and-control communications over HTTPS. The newly analyzed variant incorporates additional functionality including clipboard logging for credential harvesting, antivirus detection to evade security tools, inline hooking of Windows API functions for stealth and persistence, and token impersonation capabilities for privilege escalation and lateral movement.
The NCSC has made available technical indicators of compromise, STIX-formatted threat intelligence, and detection rules to support defensive operations. Organizations should review the IOCs and detection signatures to identify potential SparrowDoor infections within their networks and implement appropriate mitigations against this persistent threat.
Mentioned in this report
Source reporting: https://www.ncsc.gov.uk/report/mar-sparrowdoor
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free