Files
splunk-security_content/stories/silver_sparrow.yml
2022-03-09 14:43:09 +01:00

32 lines
1.6 KiB
YAML

name: Silver Sparrow
id: cb4f48fe-7699-11eb-af77-acde48001122
version: 1
date: '2021-02-24'
author: Michael Haag, Splunk
description: Silver Sparrow, identified by Red Canary Intelligence, is a new forward
looking MacOS (Intel and M1) malicious software downloader utilizing JavaScript
for execution and a launchAgent to establish persistence.
narrative: "Silver Sparrow works is a dropper and uses typical persistence mechanisms\
\ on a Mac. It is cross platform, covering both Intel and Apple M1 architecture.\
\ To this date, no implant has been downloaded for malicious purposes. During installation\
\ of the update.pkg or updater.pkg file, the malicious software utilizes JavaScript\
\ to generate files and scripts on disk for persistence.These files later download\
\ a implant from an S3 bucket every hour. This analytic assists with identifying\
\ different types of macOS malware families establishing LaunchAgent persistence.\
\ Per SentinelOne source, it is predicted that Silver Sparrow is likely selling\
\ itself as a mechanism to 3rd party Caffiliates or pay-per-install (PPI)\
\ partners, typically seen as commodity adware/malware. Additional indicators and\
\ behaviors may be found within the references."
references:
- https://redcanary.com/blog/clipping-silver-sparrows-wings/
- https://www.sentinelone.com/blog/5-things-you-need-to-know-about-silver-sparrow/
tags:
analytic_story: Silver Sparrow
category:
- Adversary Tactics
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
usecase: Advanced Threat Detection