VORANT. Threat Intelligence Sign in Get the full feed

NCSC details new SparrowDoor backdoor variant

medium threat

NCSC published a technical analysis of a new SparrowDoor backdoor variant found on a UK network, adding clipboard logging and API hooking.

The UK's National Cyber Security Centre released a malware analysis report on a newly identified variant of SparrowDoor, a persistent loader and backdoor first reported by ESET in September 2021. The variant analysed by NCSC was discovered on a UK network in 2021 and includes enhanced capabilities beyond the originally documented sample, including clipboard logging, antivirus detection, inline hooking of Windows API functions, and token impersonation for privilege manipulation.

SparrowDoor communicates with its command-and-control infrastructure using XOR-encoded traffic tunnelled beneath HTTPS, a technique intended to blend malicious traffic with legitimate encrypted web sessions. The report is accompanied by indicators of compromise, STIX objects, and detection rules to support defenders in identifying the malware on their networks.

No specific threat actor, campaign, or victim sector is attributed in the NCSC advisory beyond noting the sample's discovery on a UK network; the report is primarily technical in nature, intended to aid detection and response rather than describe an active, ongoing campaign.

Mentioned in this report

Malware SparrowDoor

Source reporting: https://www.ncsc.gov.uk/report/mar-sparrowdoor

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free