The China-aligned FamousSparrow crew has resurfaced after a long period of presumed inactivity, compromising a US financial-sector trade group and a Mexican research institute. The gang also likely targeted a governmental institution in Honduras, along with other yet-to-be-identified victims. Plus, according to ESET researchers who spotted the activity, the Beijing-backed snoops developed two new versions of their custom SparrowDoor backdoor during what appeared to be a quiet stretch between 2022 and 2024. ESET first documented FamousSparrow after uncovering its bespoke malware on hotel and government networks around the world - though the crew had likely been active since at least 2019. After a long public silence, the Chinese gang appears to be back in action. The security shop noticed the crew's resurgence while assisting a US trade group recovering from an attack in July 2024. "While helping the affected entity remediate the compromise, we made an unexpected discovery in the victim's network: Malicious tools belonging to FamousSparrow, a China-aligned APT [advanced persistent threat] group," ESET malware researcher Alexandre Côté Cyr said in a Wednesday report. Specifically, ESET found two previously undocumented versions of the group's flagship remote-control backdoor, SparrowDoor, which appears to be exclusive to the group. The researchers also documented FamousSparrow using ShadowPad, a privately sold backdoor believed to be available only to China-aligned attackers. A...
China’s FamousSparrow flies back into action, breaches US org after years off the radar
Affected Software
Frequently Asked Questions
What is the main topic of this article?
The article discusses the resurgence of the hacking group FamousSparrow, which has breached a U.S. financial-sector trade group and a Mexican research institute after years of inactivity.
What security implications are discussed in the article?
The article highlights the renewed threat posed by FamousSparrow, particularly in terms of targeting organizations in sensitive sectors like finance and research.
What organizations were compromised by FamousSparrow?
FamousSparrow compromised a U.S. financial-sector trade group and a Mexican research institute.
What software products are mentioned as being potentially affected by the attacks?
The article mentions Microsoft Windows Server, Microsoft Exchange, and Microsoft Internet Information Services (IIS) as potentially affected software.
What is the significance of FamousSparrow resuming operations?
The resurgence of FamousSparrow signifies a continued and evolving threat landscape, particularly from state-aligned hacking groups targeting critical sectors.