The group struck targets in the United States, Mexico and Honduras. Two new variants of the SparrowDoor backdoor have been detected, improved in architecture and functionality. The ShadowPad malware was also used for the first time
Researchers of ESET, a global European leader in the cybersecurity market, conducted an investigation into some suspicious activity in the network of a US trade association operating in the financial sector. During victim support operations to manage the incident, researchers discovered the presence of malicious tools attributable to FamousSparrow, a China-aligned APT group. Until then, the group was thought to be inactive, as there had been no public reports since 2022. ESET's investigation shows that not only was the group still active, but that it had also updated its techniques in the meantime, as demonstrated by the two unreleased versions of the SparrowDoor backdoor detected within the compromised network.
The group's activity between 2022 and 2024 also included targeting a government institution in Honduras. Furthermore, it emerged that, shortly before the attack in the USA, the group had managed to breach a research institute in Mexico: both compromises date back to the end of June 2024. The new versions of SparrowDoor show a notable improvement over the previous ones, both in code quality and architecture, and one of them includes command parallelization.
"Although presenting important updates, the new variants maintain elements attributable to previous versions already known publicly. The loaders used in these attacks also present extensive code overlaps with samples attributed in the past to FamousSparrow", explains Alexandre Côté Cyr, ESET researcher who authored the discovery.
To gain initial access to the victims' networks, the group exploited a webshell installed on an IIS server. ESET was unable to determine the specific exploit used to deploy the webshells, but both compromised systems were running outdated versions of Windows Server and Microsoft Exchange, which are vulnerable to publicly available exploits.
During the campaign, customized tools and malware already used by other China-aligned APT groups, as well as public domain tools, were used. The final payloads were the SparrowDoor and ShadowPad backdoors. Features observed include command execution, file system operations, keylogging, file transfer, process management, monitoring file changes, and taking screenshots.
In September 2024, the Wall Street Journal published an article that some US internet service providers had been compromised by a malicious actor called Salt Typhoon. According to Microsoft, this would be the same group known as FamousSparrow or GhostEmperor.
"It was the first public report to overlap these two entities. However, based on our data and analysis of available reports, we believe that FamousSparrow and GhostEmperor are distinct groups. The similarities are few, while the differences are many", observes Côté Cyr again.
FamousSparrow is a cyberespionage group that has been active since at least 2019. ESET publicly documented its activities for the first time in 2021, observing use of the ProxyLogon vulnerability. Initially known for attacks on hotel properties in several countries, the group has subsequently targeted governments, international organizations, engineering firms and law firms. FamousSparrow is the only group known to have employed the SparrowDoor backdoor.
For an in-depth technical analysis of the tools used by the group, you can consult the ESET Research article “You will always remember this as the day you finally caught FamousSparrow”, published on WeLiveSecurity.com. We recommend following ESET Research On Twitter (now X) for updates on the latest news of the ESET search.






