home.social

#famoussparrow — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #famoussparrow, aggregated by home.social.

fetched live
  1. China-linked FamousSparrow is targeting government organizations across Latin America with SparroWocky, a new C++ backdoor built for espionage and stealth.

    Listen/Read: hackread.com/china-famoussparr

    #Cybersecurity #FamousSparrow #SparroWocky #Malware #China #LatinAmerica

  2. 📢 FamousSparrow déploie SparroWocky, nouveau backdoor C++ ciblant l'Amérique latine

    Cet article documente la découverte de SparroWocky, le nouveau backdoor phare du groupe APT FamousSparrow, aligné sur la Chine et actif depuis au moins 2019. Depuis juillet 2025, FamousSparrow a concentré quasi-exclusivement ses opérations sur l'Amérique latine…

    📖 cyberveille : cyberveille.ch/posts/2026-09-2
    🌐 source : welivesecurity.com/en/eset-res
    🟢 vérification factuelle haute
    #AmériqueLatine #FamousSparrow #Cyberveille

  3. FamousSparrow Deploys SparroWocky Backdoor in Latin America Push

    Meet SparroWocky, a sneaky new backdoor that's been secretly targeting government agencies across Latin America since August 2025, courtesy of the China-aligned threat actor FamousSparrow. This modular malware mastermind can run commands, steal files, and even take screenshots, wreaking havoc on unsuspecting…

    osintsights.com/famoussparrow-

    #ChinaalignedThreatActor #Famoussparrow #SparrowockyBackdoor #LatinAmerica #GovernmentTargets

  4. FamousSparrow Targets Latin America with SparroWocky Backdoor

    Meet SparroWocky, a sneaky new backdoor that's helping the China-aligned threat actor FamousSparrow wreak havoc in Latin America. This modular C++ backdoor has been taking center stage since August 2025, replacing its predecessor SparrowDoor as the group's go-to tool.

    osintsights.com/famoussparrow-

    #ChinaalignedThreatActor #Famoussparrow #SparrowockyBackdoor #LatinAmerica #Statesponsored

  5. ESET reports China-linked FamousSparrow used the new C++ backdoor SparroWocky against government targets in eight Latin American countries from mid-2025 onward. The focus on stealth and persistence indicates long-term espionage operations against state networks. #FamousSparrow #SparroWocky #CyberEspionage

    cyberworldops.eu/en/sparrowock

  6. FamousSparrow spia l’Azerbaigian: il gruppo APT cinese colpisce l’industria petrolifera del corridoio energetico europeo

    Bitdefender ha documentato un'operazione di cyberspionaggio attribuita a FamousSparrow (APT cinese) contro un'azienda petrolifera azera: tre ondate di attacco tra dicembre 2025 e febbraio 2026, con ProxyNotShell su Exchange e i backdoor Deed RAT e Terndoor. L'Azerbaigian, diventato corridoio energetico strategico per l'Europa, è ora nel mirino dell'intelligence cinese.

    insicurezzadigitale.com/famous

  7. 📰 Chinese APT FamousSparrow Hits Azerbaijan Energy Sector with Deed RAT

    🇨🇳 Chinese APT FamousSparrow targets Azerbaijan's energy sector. Campaign used Exchange exploits to deploy an updated Deed RAT for cyber-espionage, signaling new geopolitical targeting. 🇦🇿 #APT #China #CyberSecurity #EnergySector #FamousSparrow

    🌐 cyber[.]netsecops[.]io

    🔗 cyber.netsecops.io/articles/ch

  8. FamousSparrow nel Caucaso: tre ondate di spionaggio cinese colpiscono il gas azero che alimenta l’Europa

    Il gruppo APT cinese FamousSparrow ha condotto un'operazione di cyberspionaggio in tre fasi successive contro una società petrolifera e del gas dell'Azerbaigian, sfruttando ripetutamente la stessa vulnerabilità di Microsoft Exchange. Un caso che illumina la strategia di Pechino per il controllo delle infrastrutture energetiche europee.

    insicurezzadigitale.com/famous

  9. 📢⚠️ China-linked #FamousSparrow hacking group targeted an oil and gas firm in #Azerbaijan using the ProxyNotShell exploit chain alongside Deed RAT and Terndoor malware across three persistent attack waves.

    Read: hackread.com/famoussparrow-oil

    #CyberSecurity #China #MSExchange #Malware #CyberAttack

  10. China-linked hackers exploit Microsoft Exchange in Azerbaijani energy firm attacks.

    A group of China-linked hackers, known as FamousSparrow, launched a sustained cyberattack on an Azerbaijani oil and gas company, exploiting Microsoft Exchange vulnerabilities in a multi-wave intrusion that spanned three months. The attackers used the ProxyNotShell exploit to gain and maintain access to…

    osintsights.com/china-linked-h

    #ChinalinkedHackers #MicrosoftExchange #Proxynotshell #Famoussparrow #EarthEstries

  11. YARA candidates from [PHIM] findings:

    → Substitution table triplet (.rdata, 0x10008898)
    → Export pattern K7UI_[digit]
    → Exception code 0xc0000409 on startup termination

    File IOC:
    SHA256: 8dfaa1f579de14bca8bb27c54a57dd87646a835969766ca9ddb81ecd9329f4e4
    Filename: K7UI.dll (K7 Antivirus masquerade)

    Full report (TLP:CLEAR), IOC bundle:
    github.com/seraphimdeck/SerapH

    Report ID: CTI-003
    Sample source: ESET malware-ioc (public)

    #FamousSparrow #SaltTyphoon #CTI #ThreatIntelligence #Infosec

  12. FamousSparrow / SparrowDoor static analysis.
    Legacy variant (2019-2022), SHA256: 8dfaa1f579...

    4 findings not present in public vendor reporting
    at time of analysis (ESET, UK NCSC, Trend Micro, Microsoft)

    → Inverted anti-sandbox logic
    → Three-table substitution system
    → .text section entropy anomaly
    → 113 indirect call sites in 26KB binary

    Thread: [PHIM] findings only.
    Full report: github.com/seraphimdeck/SerapH

    #FamousSparrow #SaltTyphoon #MalwareAnalysis #CTI

  13. Happy Monday everyone!

    Just got done reading an incredible article from ESET researchers describing an APT group that was long thought to be inactive alive in well! #FamousSparrow is a China-aligned APT group that has had no publicly documented activity since 2022 and was found using two previously undocumented versions of their backdoor, SparrowDoor. They used a mix of publicly available and custom tools for their attack ultimately leading to the deployment of SparrowDoor and ShadowPad (a privately sold backdoor). This report gets more and more interesting as you go so please go take the time to read it! Enjoy and Happy Hunting!

    You will always remember this as the day you finally caught FamousSparrow
    welivesecurity.com/en/eset-res

    Intel 471 Cyborg Security, Now Part of Intel 471 #ThreatIntel #ThreatHunting #ThreatDetection #HappyHunting #readoftheday

  14. Hey #CyberSecurity pros! 👋 Ready to dive into the latest threats and breaches making headlines?

    Our latest blog post is packed with need-to-know info to keep you ahead of the curve.

    🗞️ opalsec.io/daily-news-update-t

    Here's a quick rundown of what's inside:

    🕵️‍♂️ FamousSparrow's Return: The Chinese government-backed hacking group is back, targeting organizations in North America. Important distinction: ESET insists on tracking them separately from Salt Typhoon. Remember to prioritize TTPs and IOCs/IOAs accordingly!

    🗄️ RedCurl's Ransomware Twist: This corporate espionage group is now deploying "QWCrypt" ransomware, targeting Hyper-V servers. Phishing emails with malicious IMG attachments are the initial attack vector.

    😬 StreamElements Data Breach: A third-party service provider suffered a breach, exposing data of 210,000 customers.!

    🏛️ NSW Court System Data Theft: Sensitive documents, including AVOs, were stolen from the NSW Online Registry website. This could have serious consequences for victims of domestic violence.

    👨‍🎓 NYU Website Defacement: A hacker compromised NYU's website, leaking personal data of over 1 million students. Even with good intentions, the collateral damage is unacceptable.

    💰 Defense Contractor Fined: MORSE Corp will pay millions for failing to meet federal cybersecurity requirements. Third-party risk management is crucial!

    🤖 Atlantis AIO Automates Credential Stuffing: This new platform automates credential stuffing attacks against 140 online services. Stay vigilant against brute force attacks!

    🚨 Chrome Zero-Day Exploited: Google patched a zero-day vulnerability exploited in espionage campaigns targeting Russian organizations. Keep your browsers updated!

    👦 UK Warns of 'Com Networks': The UK's NCA is warning of a growing threat from online networks of teenage boys who are "dedicated to inflicting harm and committing a range of criminality." A very worrying trend that we need to be aware of.

    Ready for the full scoop? Read the full blog post here 👉 opalsec.io/daily-news-update-t

    #Cybersecurity #InfoSec #DataBreach #Ransomware #ThreatIntelligence #DataPrivacy #ZeroDay #FamousSparrow #RedCurl #StreamElements #NSWCourts #NYU #MORSECorp #AtlantisAIO #Chrome #ComNetworks #SecurityNews #CybersecurityThreats #InfoSecurity #CyberAttack #DataSecurity #PrivacyMatters #Vulnerability #Cybercrime #ThreatActor #ESET #SaltTyphoon #NIST #ZeroTrust #SaltTyphoon #CriticalInfrastructure

  15. @screaminggoat

    Looks #FamousSparrow’s link to #GhostEmperor is an IP address shared between the two groups (used around the same time)

    Comment found on securelist.com/ghostemperor-fr

  16. Surprised no one's looked into a7beea194785c8325bacae42d9a593eb26006830a7974bac5880e28947d2b535 yet
    It's a few weeks old now
    Might be related to #FamousSparrow ?

    ITW https://185.172[.]128.35/aaa/1173565226.png

Share on Mastodon

Enter the server where you have an account.