SparklingGoblin
- First seen
- 2020-07-01 00:00:00
- Primary motivation
- espionage
- Sophistication
- advanced
- Actor type
- nation-state
- Profile updated
- 2026-07-07 12:05:34
Targeted industries: retail-and-hospitality education-and-nonprofits
Targeted regions: country_code:us
Context
ESET researchers have discovered a new undocumented modular backdoor, SideWalk, being used by an APT group they’ve named SparklingGoblin; this backdoor was used during one of SparklingGoblin’s recent campaigns that targeted a computer retail company based in the USA. This backdoor shares multiple similarities with another backdoor used by the group: CROSSWALK.
Reports & references
- ESET — Sidewalk May Be As Dangerous As Crosswalk (report)