Full Report
China-linked APT group FamousSparrow hits targets in the Americas using upgraded SparrowDoor malware in new cyberespionage campaign, ESET reports.
Analysis Summary
# Threat Actor: FamousSparrow APT
## Attribution & Identity
- **Attribution:** China-linked Advanced Persistent Threat (APT) group.
- **Known Aliases:** FamousSparrow APT.
## Activity Summary
FamousSparrow APT is conducting a new cyberespionage campaign targeting entities in the Americas. This campaign involves the deployment of an upgraded version of their custom malware, SparrowDoor.
## Tactics, Techniques & Procedures
- Malware Usage: Utilizing the upgraded **SparrowDoor** malware.
- Objective Type: Cyberespionage campaign.
- *No specific MITRE ATT&CK IDs were provided in the source text.*
## Targeting
- **Sectors:** Not explicitly detailed, but implied to be significant targets relevant to cyberespionage.
- **Geography:** The Americas.
- **Victims:** Not specifically named in the summary provided.
## Tools & Infrastructure
- **Malware families used:** SparrowDoor (Upgraded version).
- **Infrastructure (C2, domains, IPs):** None specified/defanged in the provided text.
## Implications
This indicates continued, active cyberespionage operations by a China-linked actor specifically focusing on the Western Hemisphere, employing customized and updated malware (SparrowDoor) suggesting ongoing development and refinement of their toolset.
## Mitigations
- General detection and defense capabilities against cyberespionage activities.
- Specific focus on detecting and analyzing the SparrowDoor malware.