Verticals Targeted: Health, Government, Telecommunications, Justice, Maritime Transportation
Regions Targeted: Guatemala, Honduras, Puerto Rico, Panama, Venezuela, Ecuador, Peru, Argentina
Related Threat Actors: FamousSparrow
Related Families: SparroWocky
FamousSparrow Takes Flight with New SparroWocky Backdoor
Sep 25, 2026, 10:20:37 AM / by The Hivemind posted in Threat Bulletin, Latin America, DLL side-loading, SparroWocky backdoor, Beacon Object Files, APT malware, government cyberattacks, FamousSparrow malware, Chinese cyberespionage
SLEEPWALKER: Passive Backdoor Awakens Only When Attackers Call
Aug 31, 2026, 2:54:48 PM / by The Hivemind posted in Threat Bulletin, DLL side-loading, passive backdoor, ESET Management Agent malware, ERAAgent.exe, SLEEPWALKER malware
Executive Summary
SLEEPWALKER is a novel passive Windows backdoor. The malware is designed for DLL side-loading into the ESET Management Agent process ERAAgent.exe and does not autonomously beacon or contain fixed C2 infrastructure. Instead, SLEEPWALKER remains dormant until receiving a specially crafted network packet, then decrypts and executes attacker-supplied bytecode through a custom 23-instruction command language supporting scheduling, multiple communications mechanisms, staged payload delivery, lateral movement, and in-memory code execution.
Fancy Bear Uses NotDoor to Target NATO Countries
Sep 12, 2025, 2:38:23 PM / by The Hivemind posted in Threat Bulletin, Fancy Bear, NotDoor, VBA macro, Russian threat actors, Outlook backdoor, DLL side-loading, email exfiltration, malware persistence, NATO targets
Verticals Targeted: Not specified
Regions Targeted: NATO countries
Related Families: None