# FamousSparrow

> As of 2026-08-24, FamousSparrow is a threat actor tracked by Threadlinqs Intelligence across 5 threats spanning malware, apt. ATT&CK coverage spans 53 techniques across 14 tactics in 5 of 5 tracked threats. Most-observed techniques: T1071.001 (Web Protocols), T1140 (Deobfuscate/Decode Files or Information), T1190 (Exploit Public-Facing Application).

- **Tracked threats:** 5
- **Categories:** MALWARE, APT
- **As of:** 2026-08-24

## ATT&CK techniques observed

53 techniques observed across 5 of 5 tracked threats. Tactics: Stealth (formerly Defense Evasion) (15), Command and Control (7), Execution (5), Persistence (5), Discovery (4), Resource Development (4).

- [T1071.001](https://intel.threadlinqs.com/technique/T1071.001) Web Protocols — Command and Control — observed in 5 of 5 tracked threats
- [T1140](https://intel.threadlinqs.com/technique/T1140) Deobfuscate/Decode Files or Information — Stealth (formerly Defense Evasion) — observed in 5 of 5 tracked threats
- [T1190](https://intel.threadlinqs.com/technique/T1190) Exploit Public-Facing Application — Initial Access — observed in 5 of 5 tracked threats
- [T1574.001](https://intel.threadlinqs.com/technique/T1574.001) DLL — Stealth (formerly Defense Evasion) — observed in 5 of 5 tracked threats
- [T1014](https://intel.threadlinqs.com/technique/T1014) Rootkit — Stealth (formerly Defense Evasion) — observed in 4 of 5 tracked threats
- [T1027](https://intel.threadlinqs.com/technique/T1027) Obfuscated Files or Information — Stealth (formerly Defense Evasion) — observed in 4 of 5 tracked threats
- [T1082](https://intel.threadlinqs.com/technique/T1082) System Information Discovery — Discovery — observed in 4 of 5 tracked threats
- [T1505.003](https://intel.threadlinqs.com/technique/T1505.003) Web Shell — Persistence — observed in 4 of 5 tracked threats
- [T1543.003](https://intel.threadlinqs.com/technique/T1543.003) Create or Modify System Process: Windows Service — Persistence — observed in 4 of 5 tracked threats
- [T1021.001](https://intel.threadlinqs.com/technique/T1021.001) Remote Desktop Protocol — Lateral Movement — observed in 3 of 5 tracked threats
- [T1021.002](https://intel.threadlinqs.com/technique/T1021.002) SMB/Windows Admin Shares — Lateral Movement — observed in 3 of 5 tracked threats
- [T1036.005](https://intel.threadlinqs.com/technique/T1036.005) Match Legitimate Resource Name or Location — Stealth (formerly Defense Evasion) — observed in 3 of 5 tracked threats
- [T1055](https://intel.threadlinqs.com/technique/T1055) Process Injection — Stealth (formerly Defense Evasion) — observed in 3 of 5 tracked threats
- [T1059.001](https://intel.threadlinqs.com/technique/T1059.001) PowerShell — Execution — observed in 3 of 5 tracked threats
- [T1070.004](https://intel.threadlinqs.com/technique/T1070.004) File Deletion — Stealth (formerly Defense Evasion) — observed in 3 of 5 tracked threats

## Tracked threats

- [SparrowDoor Backdoor: NCSC Malware Analysis Report on a Persistent Loader with Clipboard Logging, AV Detection, API Hooking, and Token Impersonation](https://intel.threadlinqs.com/threat/TL-2026-2136) — MEDIUM
- [FamousSparrow APT Targets Azerbaijani Oil & Gas Sector via ProxyShell/ProxyNotShell Exchange Exploitation](https://intel.threadlinqs.com/threat/TL-2026-2122) — CRITICAL
- [FamousSparrow APT Targets Azerbaijani Oil & Gas Industry via Exchange ProxyShell/ProxyNotShell (Deed RAT, Terndoor, Mofu Loader)](https://intel.threadlinqs.com/threat/TL-2026-0749) — CRITICAL
- [FamousSparrow APT Multi-Wave Intrusion at Azerbaijani Oil & Gas Company — Evolved Two-Stage DLL Sideloading Delivers Deed RAT (0xFF66ABCD) and Terndoor via Mofu Loader](https://intel.threadlinqs.com/threat/TL-2026-0509) — CRITICAL
- [UAT-9244 (China-Nexus FamousSparrow Cluster) — TernDoor Backdoor, PeerTime BitTorrent C2 Linux Implant, and BruteEntry ORB Scanner Targeting South American Telecom](https://intel.threadlinqs.com/threat/TL-2026-0191) — HIGH

## Related CVEs

5 CVEs referenced by tracked FamousSparrow activity.

- [CVE-2022-41082](https://intel.threadlinqs.com/cve/CVE-2022-41082)
- [CVE-2022-41040](https://intel.threadlinqs.com/cve/CVE-2022-41040)
- [CVE-2021-34523](https://intel.threadlinqs.com/cve/CVE-2021-34523)
- [CVE-2021-34473](https://intel.threadlinqs.com/cve/CVE-2021-34473)
- [CVE-2021-31207](https://intel.threadlinqs.com/cve/CVE-2021-31207)

## Full data

Infrastructure, IOC values and detection queries (Splunk SPL / Microsoft KQL / Sigma) require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/actor/FamousSparrow
