logo

Chinese FamousSparrow hackers deploy upgraded malware in attacks

ID: e9971cfd-2eab-5003-b79d-f835ea162a3a

STIX ID: report--e9971cfd-2eab-5003-b79d-f835ea162a3a

Feed Name: Bleeping Computer

Threat Score
85/100

Date Published: 2025-03-27

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

FamousSparrow, a China-linked cyber-espionage actor, has been observed deploying new, more advanced modular variants of its SparrowDoor backdoor and leveraging ShadowPad against multiple organizations (a US trade organization, a Mexican research institute, and a Honduran government institution). Researchers at ESET found initial access via exploitation of outdated Microsoft Exchange and Windows Server endpoints using webshells, and noted capabilities such as plugin-based in-memory modules, parallel command execution, DLL side-loading, keylogging, file operations, and stealthy C2 switching.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.