SparklingGoblin

Affiliated Intrusion Sets Winnti , FamousSparrow

SparklingGoblin is an Advanced Persistent Threat (APT) group tracked by ESET, also known as Earth Baku by Trend Micro. SparklingGoblin shows overlaps with the Winnti Group but exhibits distinct operational tactics.

The group uses modular backdoors, specifically "SideWalk" and "CROSSWALK", which are capable of dynamic module loading, proxy handling, and encrypted communication with command-and-control (C2) servers.

SparklingGoblin has targeted a wide range of organizations globally, with a focus on the academic sector and East and Southeast Asia.

Cyber Threat Graph Context

Explore how this Intrusion Set relates to the wider threat graph

References