I ka makahiki i hala aku nei, ua loaʻa i ka UK's National Cyber Security Center (NCSC) kahi ʻano like ʻole o ka spy malware SparrowDoor ma kahi pūnaewele UK i ʻike ʻole ʻia. Ua paʻi ʻia kahi loiloi o ka ʻano like ʻole i kēia lā, hiki ke ʻaihue i ka ʻikepili mai ka clipboard, a me nā mea ʻē aʻe. Eia kekahi, ua hoʻolako ʻia nā hōʻailona o ka ʻae a me nā lula Yara e hiki ai i nā hui ke ʻike i ka malware i loko o kā lākou pūnaewele ponoʻī.
Ua ʻike ʻia ka mana mua o SparrowDoor e ka hui antivirus ESET a ua ʻōlelo ʻia ua hoʻohana ʻia e kūʻē i nā hōkele a puni ka honua, a me nā aupuni. Ua hoʻohana nā mea hoʻouka i nā mea palupalu i Microsoft Exchange, Microsoft SharePoint a me Oracle Opera e uhaʻi i nā hui. Aia nā hui i hoʻopilikia ʻia ma Kanada, Israel, Farani, Saudi Arabia, Taiwan, Thailand a me United Kingdom, a me nā mea ʻē aʻe. ʻAʻole i hōʻike ʻo ESET i ka pahuhopu pololei o nā mea hoʻouka.
Ua ʻōlelo ka British NCSC ua loaʻa kahi ʻano like ʻole o SparrowDoor ma kahi pūnaewele Pelekane i ka makahiki i hala. Hiki i kēia mana ke ʻaihue i ka ʻikepili mai ka clipboard a nānā i kahi papa inoa hardcoded inā e holo ana kekahi polokalamu antivirus. Hiki i kēia ʻokoʻa ke hoʻohālike i ka hōʻailona moʻokāki mea hoʻohana ke hoʻonohonoho i nā pilina pūnaewele. Malia paha ua hana ʻia kēia "hoʻohaʻahaʻa" i mea ʻike ʻole ʻia, hiki iā ia ke hana i nā kamaʻilio pūnaewele ma lalo o ka mooolelo SYSTEM, no ka laʻana.
ʻO kekahi hiʻohiʻona hou ka hijacking o nā ʻano like ʻole Windows Nā hana API. ʻAʻole maopopo i ka wā e hoʻohana ai ka malware i ka "API hooking" a me ka "token impersonation", akā e like me ka British NCSC, ke hana nei nā mea hoʻouka i nā hoʻoholo palekana hana. ʻAʻole hāʻawi ʻia nā kikoʻī hou aʻe e pili ana i ka pūnaewele i hoʻouka ʻia a i ʻole ma hope o ka malware.