New FamousSparrow Malware Targets Hotels and Engineering Firms with Custom Backdoor
ID: 86b00544-2c1b-5c88-afad-1ea917fa65f7
STIX ID: report--86b00544-2c1b-5c88-afad-1ea917fa65f7
Feed Name: GBHackers
Threat Score
ESET researchers identified renewed activity from the China-aligned APT FamousSparrow in July 2024, revealing two new SparrowDoor backdoor variants and the group’s first observed use of ShadowPad; the campaign used ASHX webshells, PowerShell sessions, privilege escalation and enhanced persistence, and the malware demonstrates modular design, RC4-encrypted communications and parallelized command execution, affecting organizations in finance, research and other sectors.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
