Malware analysis report on SparrowDoor malware
A technical analysis of a new variant of the SparrowDoor malware.
Our advice & guidance covers a broad range of topics
Resources for individuals and organisations in the UK who have experienced an online scam or cyber attack.
Find a range of products & services from NCSC and certified 3rd party suppliers
Working with industry, government and academia to support the next generation of researchers, students and cyber security professionals
All the latest information to help you keep track of what's happening

The NCSC malware analysis report on a variant of the SparrowDoor malware is available below, along with indicators of compromise, STIX and detection rules.
The report covers technical analysis of a variant of SparrowDoor reported by ESET in September 2021. The variant was found on a UK network in 2021 and contains additional functionality.
SparrowDoor is a persistent loader and backdoor which employs XOR encoding for the C2 channel underneath HTTPS. The additional functionality includes clipboard logging, AV detection, inline hooking of Windows API functions and token impersonation.
This report covers technical analysis of a new variant of the SparrowDoor malware.