SparklingGoblin is a cyber-espionage threat actor first identified with specific campaigns in May 2020, operating with high confidence from China. This group's primary motivation is intelligence gathering, focusing on intellectual property theft and sensitive data exfiltration. While closely associated with and considered by some to be an alias of the broader Winnti Group, also known as APT41, Barium, Wicked Panda, and Grayfly, SparklingGoblin exhibits distinct operational patterns that have led researchers to track it as a separate entity. A defining characteristic of SparklingGoblin is its exclusive use of the SideWalk backdoor.