SparklingGoblin

First seen
2020-07-01 00:00:00
Primary motivation
espionage
Sophistication
advanced
Actor type
nation-state
Profile updated
2026-07-07 12:05:34

Targeted industries: retail-and-hospitality education-and-nonprofits

Targeted regions: country_code:us

Context

ESET researchers have discovered a new undocumented modular backdoor, SideWalk, being used by an APT group they’ve named SparklingGoblin; this backdoor was used during one of SparklingGoblin’s recent campaigns that targeted a computer retail company based in the USA. This backdoor shares multiple similarities with another backdoor used by the group: CROSSWALK.

Reports & references

  • ESET — Sidewalk May Be As Dangerous As Crosswalk (report)

External references