• News/
  • https://www.theregister.com/2025/03/27/china_famoussparrow_back/

China’s FamousSparrow flies back into action, breaches US org after years off the radar

The Register
·
Jessica Lyons
·
Published Mar 27, 2025
·
Updated

The China-aligned FamousSparrow crew has resurfaced after a long period of presumed inactivity, compromising a US financial-sector trade group and a Mexican research institute. The gang also likely targeted a governmental institution in Honduras, along with other yet-to-be-identified victims. Plus, according to ESET researchers who spotted the activity, the Beijing-backed snoops developed two new versions of their custom SparrowDoor backdoor during what appeared to be a quiet stretch between 2022 and 2024. ESET first documented FamousSparrow after uncovering its bespoke malware on hotel and government networks around the world - though the crew had likely been active since at least 2019. After a long public silence, the Chinese gang appears to be back in action. The security shop noticed the crew's resurgence while assisting a US trade group recovering from an attack in July 2024. "While helping the affected entity remediate the compromise, we made an unexpected discovery in the victim's network: Malicious tools belonging to FamousSparrow, a China-aligned APT [advanced persistent threat] group," ESET malware researcher Alexandre Côté Cyr said in a Wednesday report. Specifically, ESET found two previously undocumented versions of the group's flagship remote-control backdoor, SparrowDoor, which appears to be exclusive to the group. The researchers also documented FamousSparrow using ShadowPad, a privately sold backdoor believed to be available only to China-aligned attackers. A...

Read full article

Affected Software

3 affected components
Microsoft Windows Server
Microsoft Exchange
Microsoft Internet Information Services (IIS)
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses the resurgence of the hacking group FamousSparrow, which has breached a U.S. financial-sector trade group and a Mexican research institute after years of inactivity.

2

What security implications are discussed in the article?

The article highlights the renewed threat posed by FamousSparrow, particularly in terms of targeting organizations in sensitive sectors like finance and research.

3

What organizations were compromised by FamousSparrow?

FamousSparrow compromised a U.S. financial-sector trade group and a Mexican research institute.

4

What software products are mentioned as being potentially affected by the attacks?

The article mentions Microsoft Windows Server, Microsoft Exchange, and Microsoft Internet Information Services (IIS) as potentially affected software.

5

What is the significance of FamousSparrow resuming operations?

The resurgence of FamousSparrow signifies a continued and evolving threat landscape, particularly from state-aligned hacking groups targeting critical sectors.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203