New SparroWocky Backdoor Targets Latin America
Active since at least August 2025, the malware represents a functional pivot from the threat actor's existing SparrowDoor backdoor.
All topics
Active since at least August 2025, the malware represents a functional pivot from the threat actor's existing SparrowDoor backdoor.
A new joint advisory from multiple law enforcement agencies this week warned of an Iranian cyber campaign targeting dissidents and journalists in the U.S., UK, and elsewhere.
Unlike standard commodity malware that aims for quick credential theft, this campaign features a manual, hands-on-keyboard scheme designed to escalate rapidly from a single compromised workstation to broad, network-wide access.
The investigation into UAT-7810 shows significant evolution in their toolkit, specifically the development of a successor to their previously documented SHORTLEASH backdoor.
This new ARToken operator panel has a clear lineage going back to the EvilTokens framework, which emerged in early 2026.
Known historically for its tight ties to Russia’s FSB and its development of the Snake implant, Turla has leveraged STOCKSTAY to target sensitive government and military organizations.