SparklingGoblin primarily targets East and Southeast Asia. It is present worldwide and has a variety of objectives, with a particular focus on the university sector
Researchers of ESET, discovered a Linux variant of the SideWalk backdoor, one of multiple customized systems used by the APT group SparklingGoblin. This variant was first deployed against a university in Hong Kong in February 2021, the same one that had already been targeted by SparklingGoblin during the student protests of May 2020. SparklingGoblin is an APT group operating primarily in East and Southeast Asia, although ESET Research has found that they target numerous organizations and verticals around the world, with a particular focus on the university sector.
"The SideWalk backdoor is characteristic of SparklingGoblin. In addition to the many code similarities between Linux variants of SideWalk and various tools from the APT group, one of SideWalk's Linux samples uses a C&C (Command&Control) address already exploited by SparklingGoblin. Considering all these factors, we are reasonably certain that SideWalk Linux can be traced back to the APT SparklingGoblin group," he explains Vladislav Hrčka, ESET researcher who made the discovery together with Thibault Passilly and Mathieu Tartare.
SparklingGoblin first breached a university in Hong Kong in May 2020, and ESET detected the Linux variant of SideWalk on this university's network in February 2021. The group targeted the organization over a long period of time, managing to compromise several servers, including a print server, an email server, and one used to manage student schedules and course registrations. In this case, it is a Linux variant of the original backdoor. This Linux version has several similarities with its Windows equivalent, as well as some technical innovations.
A peculiarity of SideWalk is the use of multiple threads to perform a single specific task. It was found that in both variants there are exactly five threads running simultaneously, each of which has a specific task. Four commands are not implemented or are implemented differently in the Linux variant. "Considering the numerous code overlaps between the samples, we believe we have found a Linux variant of SideWalk, which we call SideWalk Linux. Similarities include the same customized ChaCha20, software architecture, configuration and implementation of the dead-drop resolver," says Hrčka.
"The Windows variant of SideWalk was developed in a way to hide the goals of its code. All data and code not necessary for its execution were removed and the rest encrypted. On the other hand, the Linux variants contain symbols and leave some unique authentication keys and other artifacts unencrypted, which makes detection and analysis much easier," concludes Hrčka.
Further technical information on SideWalk Linux, at this link You never walk alone: SideWalk backdoor gets a Linux variant su WeLiveSecurity.






