Activity timeline
FamousSparrow appears in 5 tracked threats between and ; the busiest month was 2026-08 with 2 reports.
ATT&CK techniques observed
- T1071.001 Web Protocols — Command and Controlobserved in 5 of 5 tracked threats
- T1140 Deobfuscate/Decode Files or Information — Stealth (formerly Defense Evasion)observed in 5 of 5 tracked threats
- T1190 Exploit Public-Facing Application — Initial Accessobserved in 5 of 5 tracked threats
- T1574.001 DLL — Stealth (formerly Defense Evasion)observed in 5 of 5 tracked threats
- T1014 Rootkit — Stealth (formerly Defense Evasion)observed in 4 of 5 tracked threats
- T1027 Obfuscated Files or Information — Stealth (formerly Defense Evasion)observed in 4 of 5 tracked threats
- T1082 System Information Discovery — Discoveryobserved in 4 of 5 tracked threats
- T1505.003 Web Shell — Persistenceobserved in 4 of 5 tracked threats
- T1543.003 Create or Modify System Process: Windows Service — Persistenceobserved in 4 of 5 tracked threats
- T1021.001 Remote Desktop Protocol — Lateral Movementobserved in 3 of 5 tracked threats
- T1021.002 SMB/Windows Admin Shares — Lateral Movementobserved in 3 of 5 tracked threats
- T1036.005 Match Legitimate Resource Name or Location — Stealth (formerly Defense Evasion)observed in 3 of 5 tracked threats
- T1055 Process Injection — Stealth (formerly Defense Evasion)observed in 3 of 5 tracked threats
- T1059.001 PowerShell — Executionobserved in 3 of 5 tracked threats
- T1070.004 File Deletion — Stealth (formerly Defense Evasion)observed in 3 of 5 tracked threats
Tracked threats
- SparrowDoor Backdoor: NCSC Malware Analysis Report on a Persistent Loader with Clipboard Logging, AV Detection, API Hooking, and Token ImpersonationMEDIUM
- FamousSparrow APT Targets Azerbaijani Oil & Gas Sector via ProxyShell/ProxyNotShell Exchange ExploitationCRITICAL
- FamousSparrow APT Targets Azerbaijani Oil & Gas Industry via Exchange ProxyShell/ProxyNotShell (Deed RAT, Terndoor, Mofu Loader)CRITICAL
- FamousSparrow APT Multi-Wave Intrusion at Azerbaijani Oil & Gas Company — Evolved Two-Stage DLL Sideloading Delivers Deed RAT (0xFF66ABCD) and Terndoor via Mofu LoaderCRITICAL
- UAT-9244 (China-Nexus FamousSparrow Cluster) — TernDoor Backdoor, PeerTime BitTorrent C2 Linux Implant, and BruteEntry ORB Scanner Targeting South American TelecomHIGH