Beware the SparroWock: The backdoor that bites, the commands that catch

2026-09-18T08:51:31Z•a243af023747cd58c5f97428010c061bac92d12c180339a93edb64c7c942350b
AI securityAPTEDR evasionESET ResearchFamousSparrowSparroWockyUEFI Secure Bootbackdoorcyberespionagemalwarephishingransomwarethreat-intelligence

What happened

ESET’s September 17, 2026 research documents SparroWocky, described as the flagship backdoor of the FamousSparrow APT group. The accompanying feed also covers a broad range of cyberthreat research, including UEFI Secure Boot bypasses, APT activity, malware, phishing, ransomware, EDR evasion, and AI-related security risks. This document is a threat-intelligence feed entry rather than a confirmed vulnerability advisory.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
eset_welivesecurity
Record identifier
a243af023747cd58c5f97428010c061bac92d12c180339a93edb64c7c942350b
Enrichment time
2026-09-18T08:51:31Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Beware the SparroWock: The backdoor that bites, the commands that catch · Baitaphish