Chinese FamousSparrow hackers deploy upgraded malware in attacks
ID: e9971cfd-2eab-5003-b79d-f835ea162a3a
STIX ID: report--e9971cfd-2eab-5003-b79d-f835ea162a3a
Feed Name: Bleeping Computer
FamousSparrow, a China-linked cyber-espionage actor, has been observed deploying new, more advanced modular variants of its SparrowDoor backdoor and leveraging ShadowPad against multiple organizations (a US trade organization, a Mexican research institute, and a Honduran government institution). Researchers at ESET found initial access via exploitation of outdated Microsoft Exchange and Windows Server endpoints using webshells, and noted capabilities such as plugin-based in-memory modules, parallel command execution, DLL side-loading, keylogging, file operations, and stealthy C2 switching.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
