SparklingGoblin is an APT group targeting retail sector known for deploying SideWalk and CROSSWALK modular backdoors.
Analyst brief
SparklingGoblin is an APT group identified by ESET that recently targeted a US-based computer retail company. They utilize a newly discovered modular backdoor called SideWalk, which shares significant similarities with their other known tool, CROSSWALK. Their key TTPs involve deploying custom backdoors for persistent access, likely achieving initial access through phishing or exploitation, and using encrypted C2 channels for communication. Defenders should focus on monitoring for abnormal process behavior, analyzing encrypted C2 traffic patterns linked to SideWalk, and deploying detection rules (e.g., YARA) for these specific backdoor signatures.
SparklingGoblin
unknown
ESET researchers have discovered a new undocumented modular backdoor, SideWalk, being used by an APT group they’ve named SparklingGoblin; this backdoor was used during one of SparklingGoblin’s recent campaigns that targeted a computer retail company based in the USA. This backdoor shares multiple similarities with another backdoor used by the group: CROSSWALK.