Categories: Article

British government discovers new variant of spy malware SparrowDoor

Last year, the UK’s National Cyber ​​Security Center (NCSC) found a variant of the spy malware SparrowDoor on an undisclosed UK network. An analysis of the variant was published today, which can now steal data from the clipboard, among other things. In addition, indicators of compromise and Yara rules have been made available that allow organizations to detect the malware within their own network.

The first version of SparrowDoor was discovered by antivirus company ESET and is said to have been used against hotels worldwide, as well as against governments. The attackers used vulnerabilities in Microsoft Exchange, Microsoft SharePoint and Oracle Opera to break into organizations. Affected organizations were in Canada, Israel, France, Saudi Arabia, Taiwan, Thailand and the United Kingdom, among others. ESET did not disclose the exact target of the attackers.

The British NCSC says it found a variant of SparrowDoor on a British network last year. This version can steal data from the clipboard and checks against a hardcoded list whether certain antivirus software is running. This variant can also imitate the user account token when setting up network connections. It is likely that this “downgrade” is done to be inconspicuous, which it could if it were performing network communications under the SYSTEM account, for example.

Another new feature is the hijacking of various Windows API functions. It is not clear when the malware uses “API hooking” and “token impersonation”, but according to the British NCSC, the attackers are making conscious operational security decisions. Further details about the attacked network or who is behind the malware are not given.

Max Reisler

Greetings! I'm Max, part of our malware removal team. Our mission is to stay vigilant against evolving malware threats. Through our blog, we keep you updated on the latest malware and computer virus dangers, equipping you with the tools to safeguard your devices. Your support in spreading this valuable information across social media is invaluable in our collective effort to protect others.

Recent Posts

Remove Tylophes.xyz (virus removal guide)

Many individuals report facing issue­s with a website called Tylophes.xyz. This we­bsite tricks users into…

17 hours ago

Remove Sadre.co.in (virus removal guide)

Many individuals report facing issue­s with a website called Sadre.co.in. This we­bsite tricks users into…

22 hours ago

Remove Search.rainmealslow.live browser hijacker virus

Upon closer inspection, Search.rainmealslow.live is more than just a browser tool. It's actually a browser…

22 hours ago

Remove Seek.asrcwus.com browser hijacker virus

Upon closer inspection, Seek.asrcwus.com is more than just a browser tool. It's actually a browser…

22 hours ago

Remove Brobadsmart.com (virus removal guide)

Many individuals report facing issue­s with a website called Brobadsmart.com. This we­bsite tricks users into…

22 hours ago

Remove Re-captha-version-3-265.buzz (virus removal guide)

Many individuals report facing issue­s with a website called Re-captha-version-3-265.buzz. This we­bsite tricks users into…

2 days ago