BlackTree Security · Infrastructure · Automation · AI

This Spyware Hides Its Own Threads Behind a Harmless Windows Function

A familiar Windows function can be a useful clue to what a process is doing. It can also be a disguise. ESET’s new analysis of SparroWocky describes an espionage backdoor that conceals thread origins behind a legitimate-looking function, making the first reassuring signal an incomplete answer.

Published on 17 September, the report attributes SparroWocky to the China-aligned FamousSparrow group with high confidence. ESET observed deployments against government entities in Latin America from at least August 2025. Its geopolitical explanation for the targeting remains an assessment, not independently established evidence of a government’s instructions.

A new implant, not just a renamed old one

ESET describes a distinct modular C++ backdoor replacing SparrowDoor. A legitimate executable loads a malicious DLL, which decrypts a separate payload and maps it into memory. The implant integrates public components and can execute commands, steal files, capture screens and load additional in-memory modules. Its thread-creation hook substitutes AnimateWindow as the apparent starting address.

ESET continues to track FamousSparrow separately from Salt Typhoon because it lacks technical indicators establishing that equivalence. The names should not be merged for a more dramatic headline. A malware capability also should not be reported as proof that every observed target suffered every possible action.

A trusted executable can load code you do not trust

MITRE’s DLL-hijacking guidance explains the broader technique: an adversary can place a malicious library where a legitimate application will load it, allowing malicious execution to sit beneath a familiar process. Libraries and legitimate executables are not inherently suspicious. Their relationship, location and behaviour matter.

For defenders, this is a reason to question a narrow allowlist based only on an executable’s identity. A permitted programme can still be part of an unapproved execution chain. The useful question is which libraries it loaded, from where, under what circumstances and with what subsequent activity. That is a hunting principle, not a universal detector for this implant.

How to turn the research into a bounded hunt

  • Start with the published indicators. ESET provides sample hashes and infrastructure details in its report and repository. Confirm the time context and available telemetry before deciding what a match means.
  • Correlate across evidence types. An unusual DLL load, persistence change and unexpected outbound connection together are more informative than a familiar process name alone. Preserve the underlying events for investigation.
  • Check the limits of your coverage. Establish which systems record module loads, process activity and network events, and how long those records survive. A query returning nothing may reflect missing data rather than a clean estate.
  • Validate detections safely. Use an authorised test environment and qualified practitioners. Do not run malware samples on production devices to discover whether a security product notices them.
  • Keep attribution separate from incident response. A suspicious event deserves investigation even when an actor name is uncertain. Conversely, resemblance to a published technique does not prove FamousSparrow is present.

These are BlackTree’s practical recommendations for using the report, not a claim that the campaign has moved into European organisations. The reported targeting is valuable intelligence; the general lesson about execution trust is relevant beyond that victim set without inventing a wider campaign.

BlackTree’s separate report on GrayRabbit delivered through Sogou Input Method offers related context on ordinary desktop software becoming an attack route. It does not establish a connection between those operations and SparroWocky.

The backdoor’s trick is not to make the computer look obviously alien. It is to make hostile execution look sufficiently ordinary that nobody asks the next question. A good hunt begins where that reassurance ends.

Sources

Leave a Reply

Your email address will not be published. Required fields are marked *