mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
32 lines
1.6 KiB
YAML
32 lines
1.6 KiB
YAML
name: Silver Sparrow
|
|
id: cb4f48fe-7699-11eb-af77-acde48001122
|
|
version: 1
|
|
date: '2021-02-24'
|
|
author: Michael Haag, Splunk
|
|
description: Silver Sparrow, identified by Red Canary Intelligence, is a new forward
|
|
looking MacOS (Intel and M1) malicious software downloader utilizing JavaScript
|
|
for execution and a launchAgent to establish persistence.
|
|
narrative: "Silver Sparrow works is a dropper and uses typical persistence mechanisms\
|
|
\ on a Mac. It is cross platform, covering both Intel and Apple M1 architecture.\
|
|
\ To this date, no implant has been downloaded for malicious purposes. During installation\
|
|
\ of the update.pkg or updater.pkg file, the malicious software utilizes JavaScript\
|
|
\ to generate files and scripts on disk for persistence.These files later download\
|
|
\ a implant from an S3 bucket every hour. This analytic assists with identifying\
|
|
\ different types of macOS malware families establishing LaunchAgent persistence.\
|
|
\ Per SentinelOne source, it is predicted that Silver Sparrow is likely selling\
|
|
\ itself as a mechanism to 3rd party Caffiliates or pay-per-install (PPI)\
|
|
\ partners, typically seen as commodity adware/malware. Additional indicators and\
|
|
\ behaviors may be found within the references."
|
|
references:
|
|
- https://redcanary.com/blog/clipping-silver-sparrows-wings/
|
|
- https://www.sentinelone.com/blog/5-things-you-need-to-know-about-silver-sparrow/
|
|
tags:
|
|
analytic_story: Silver Sparrow
|
|
category:
|
|
- Adversary Tactics
|
|
product:
|
|
- Splunk Enterprise
|
|
- Splunk Enterprise Security
|
|
- Splunk Cloud
|
|
usecase: Advanced Threat Detection
|