China’s FamousSparrow flies back into action, breaches US org after years off the radar
ID: e3d2d193-7c04-5f1e-bd96-8a35ec812a81
STIX ID: report--e3d2d193-7c04-5f1e-bd96-8a35ec812a81
Feed Name: The Register (Security)
FamousSparrow, a China-aligned APT, resurfaced in 2024 and conducted targeted intrusions against a US financial-sector trade group and a Mexican research institute (with likely targeting of a Honduran government entity). ESET investigators observed the attackers deploy IIS webshells exploiting outdated Windows Server and Exchange, deliver a trident loader to install two new, more sophisticated SparrowDoor backdoor variants (including a modular version), and use ShadowPad, indicating active, evolving, and high-capability malware-enabled espionage.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
