← Threat Actors / Global / SparklingGoblin
DOSSIER // SPARKLINGGOBLIN

SparklingGoblin

▲ High Threat
Primary Aliases: APT41 Brass Typhoon Leopard Typhoon WICKED PANDA
Confidence Rating 70% (Grounded)

ESET researchers have discovered a new undocumented modular backdoor, SideWalk, being used by an APT group they’ve named SparklingGoblin; this backdoor was used during one of SparklingGoblin’s recent campaigns that targeted a computer retail company based in the USA. This backdoor shares multiple similarities with another backdoor used by the group: CROSSWALK.

🎯 Target Sectors & Focus

Defense & Aerospace Government & Diplomacy Financial & Crypto Critical Infrastructure

🛡️ MITRE ATT&CK® Attack Lifecycle (82 TTPs)

📥 Download Navigator JSON
Copied to clipboard

LINK COPIED TO CLIPBOARD