FamousSparrow Deploys New SquawkDoor Backdoor and Updated SparrowDoor

Summary
Positive Technologies details FamousSparrow attacks in 2026 using new SquawkDoor and updated SparrowDoor backdoors, delivered through malicious LNK files and compromised websites displaying fake certificate prompts.
Key points
- The campaign targeted users in Nepal, the Philippines, Indonesia, Taiwan, Egypt, Germany, and the Czech Republic; researchers confirmed access to an international food-security research organization's information system.
- Compromised websites injected JavaScript that displayed a fake SSL error and offered a malicious MSI disguised as a certificate; LNK files also launched payloads through ftp.exe.
- SquawkDoor uses DLL sideloading, establishes persistence, checks for analysis environments, communicates with command-and-control servers, and supports commands including file operations, screenshots, and arbitrary command execution.
- The updated SparrowDoor combines built-in and downloadable plugins, improves stealth and persistence, and includes a keylogging plugin.
- Researchers linked some activity to other East Asian campaigns through shared techniques and infrastructure, while noting that infrastructure overlap alone does not confirm shared operators.
- LNK metadata and malware artifacts exposed a computer hostname that researchers linked to a suspected group member; they assess the person was likely involved in preparing the attack, but not a key operator.
Article Details
- Attack Vectors
- Compromised websites served injected JavaScript that replaced page content with a fake SSL error and prompted visitors to download a purported certificate. The downloaded MSI installed SquawkDoor or SparrowDoor.
- An Indonesian-language RAR archive contained a document-disguised LNK file. Opening it invoked ftp.exe to run a script that extracted and launched SquawkDoor components.
- A related 2024 attack used a ClickFix-style “I’m not a robot” lure and a malicious archive containing an LNK file. Both led to a CAB-based loader.
- Defensive Notes
- The website-injection script checked for Windows, contacted its configured server, and used /report-url and /track-download to log activity.
- SquawkDoor and SparrowDoor used malicious DLLs loaded by legitimate executables. SquawkDoor added a current-user startup entry; SparrowDoor created a service, with a current-user autorun entry as fallback.
- SquawkDoor could check for virtualized analysis environments and wait for a browser process before continuing. SparrowDoor disguised files by changing timestamps and applying hidden and system attributes.
Indicators of compromise
| Type | Indicator | Context |
|---|---|---|
| DOMAIN | pplpp[.]microsfot[.]vip | Encoded server address recovered from the malicious website-injection script. |
| DOMAIN | viscarae[.]com | Domain researchers associated with the SparrowDoor C2 endpoint pattern and previously linked infrastructure. |
| IPV4 | 103[.]27[.]108[.]55 | IP address to which viscarae.com previously resolved; the article describes an infrastructure overlap with reporting on UAT-8302. |
| SHA256 | 1a442a8e12c1571a0663e64e0ac9c930035bb267259b684cd9607f76be6d017b | CAB archive containing components of the SquawkDoor infection chain. |
| SHA256 | 1def54444cab1fd17fe5acb42dd0d2293bcb9ce72a8e955bf6796d10d662c4ff | Indonesian-language RAR archive carrying the SquawkDoor infection chain. |
| SHA256 | 39bdf92a70a1bb4f07e58cd1081f80fced85df01c1f14a56ed5783104c902439 | BAT script named info.dll executed through the malicious LNK file. |
| SHA256 | 4c7ae604ad1af90ea155865cb28fd7ccd6371f5ac172de6014b328514d4618e7 | Malicious LNK file that invoked ftp.exe to start the infection chain. |
| SHA256 | 56f7237236374acb77c4e158e6026bac9b05b16942a2c89d41bcce6230d42f8c | PowerShell script downloaded in the related ClickFix attack. |
| SHA256 | 595a43169bcc5154712311e37c192a8f4bf93fa2a2b5afff465c816b01a187f2 | CAB archive containing the loader components in the related 2024 attack. |
| SHA256 | 60292dee0e07a2b889d657e2fbd2f1cd517eaea58f1cfb1ed4a721a173520499 | Encrypted payload containing SquawkDoor in the LNK-delivered chain. |
| SHA256 | b379d07ba81d4190490d9893b2d6d830ff594e042dce26053ef07794d0403787 | Malicious MSI downloaded from the S3 bucket in the fake-certificate attacks. |
| SHA256 | c2570d398b4cae11ae87269e8b9c3a4f53d3860974be04471fa092a96ecebc1d | Loader payload named svctop.exl in the related 2024 attack. |
| SHA256 | c69534bb3e6d4e1c9b21f9e4745f6fb002cbcd3ab83f9ad208eb7bb135401062 | Malicious MSVCR110.dll used for DLL sideloading in the LNK-delivered SquawkDoor chain. |
| SHA256 | d5135980017905588e72f7030410c5903071f803cd4d4060eb51fc28b38b5ba1 | Malicious Tender.rar archive containing an LNK-led infection chain. |
| SHA256 | e5f7bbfc187264336dea5dfebfb5a7dd1e7fcdcc9692db55fbe6eb4d28f027bc | Malicious CertFixer.msi that installed the updated SparrowDoor backdoor. |
| SHA256 | f23e5391656b178bc0ab510b0fca6ffbd963cf94870c82a5920f0f338f561f18 | Malicious MSVCR110.dll variant used in the MSI-based infection chain. |
| SHA256 | f51dc5e1848daee4e607d46faa25033e1151060cd3482ad4439754440d6c4c01 | Malicious CertFixer.msi associated with the attack targeting Germany. |
| SHA256 | f8204ba0763622a5f7ed3ca9d8c970eb52d10505690b17c920039dead408fbc5 | Malicious MSVCR110.dll used for sideloading in the related 2024 attack. |
| SHA256 | fafb6ffd3ffcf414b702354f62a5216351af4566ed61ece7784846a6938bb8d9 | Hash of the legitimate executable abused for DLL sideloading in the described attacks. |
| URL | hxxps[:]//www[.]cloudf-update[.]com/down[.]txt | Next-stage download URL in the related 2024 ClickFix attack. |
| URL | hxxps[:]//www[.]cloudf-update[.]com/files/Tender[.]rar | Link to the malicious Tender.rar archive in a likely initial lure document. |
| URL | hxxps[:]//www[.]cloudf-update[.]com/wp-statics/test[.]doc | URL from which the PowerShell script downloaded the next stage. |
MITRE ATT&CK
T1027 · Obfuscated Files or InformationThe backdoor chains stored encrypted payloads and used obfuscated JavaScript or encrypted configuration data.T1036.007 · Double File ExtensionThe malicious Strategi_AS_Referensi_April2026.docx.lnk file used a document extension before its actual LNK extension.T1055 · Process InjectionSparrowDoor wrote its decrypted payload into a spawned msiexec.exe process and transferred execution to it.T1056.001 · KeyloggingSparrowDoor's built-in keylogging module installed a low-level keyboard hook and recorded keystrokes with active-window titles.T1059.001 · PowerShellThe related 2024 attack used a PowerShell script to download its next stage.T1059.003 · Windows Command ShellThe infection scripts and SquawkDoor used cmd.exe; SquawkDoor also supported C2 commands executed through the command interpreter.T1070.006 · TimestompSparrowDoor changed the timestamps of its working directory and files to match ntdll.dll.T1071.001 · Web ProtocolsThe website-injection script sent HTTP requests to its configured server, and SparrowDoor could communicate with its C2 server through HTTP POST requests.T1082 · System Information DiscoverySquawkDoor collected OS and computer information, while SparrowDoor collected a broader victim-system profile.T1105 · Ingress Tool TransferSparrowDoor could request missing PE plugins from its C2 server and receive files for creation in the temporary directory.T1113 · Screen CaptureA supported SquawkDoor C2 command captured a screenshot.T1189 · Drive-by CompromiseFamousSparrow injected JavaScript into compromised websites to show a fake SSL error and offer a malicious certificate download.T1204.002 · Malicious FileThe infection chains relied on users opening a malicious LNK file or executing a purported certificate installer.T1497.001 · System ChecksSquawkDoor checked memory, disk, registry, processes, drivers, devices, MAC addresses, screen resolution, and firmware for signs of virtualized analysis environments.T1497.003 · Time Based ChecksWhen configured to do so, SquawkDoor waited until a target browser process was running before continuing.T1518.001 · Security Software DiscoverySparrowDoor included the names of installed antivirus products in the system profile sent to its C2 server.T1543.003 · Windows ServiceSparrowDoor created an automatically launching Windows service named NisaSrv for persistence.T1547.001 · Registry Run Keys / Startup FolderSquawkDoor created a current-user startup entry named WindowsUpdateAssist; SparrowDoor used a current-user autorun key if service persistence failed.T1564.001 · Hidden Files and DirectoriesSparrowDoor applied hidden and system attributes to its working directory and files.T1574.001 · DLLLegitimate executables loaded attacker-supplied MSVCR110.dll or WTSAPI32.dll, which then loaded encrypted backdoor payloads.
People
Alexander BadaevPositive Technologies Senior Cyberthreat Intelligence Specialist credited on the research.imawuyaPentester whom the researchers assess with high confidence created and tested the Indonesia-targeting malicious LNK on her computer; they consider her likely a FamousSparrow member, but not a key operator.Maxim ShamanovPositive Technologies Advanced Threat Research Group specialist credited on the research.
Threat Actors
APT31Group mentioned among East Asian groups that have used malicious libraries named MSVCR110.dll; the article does not attribute the reported attacks to it.Earth EstriesName the article gives for FamousSparrow, also called Salt Typhoon.FamousSparrowGroup behind the reported SquawkDoor and updated SparrowDoor attacks; the article also calls it Salt Typhoon and Earth Estries.imawuyaResearchers assess with high confidence that she created and tested a malicious FamousSparrow LNK and consider her likely a group member, but not a key operator.MofangName the article gives for SectorM04, also called Whitefly.MustangPandaGroup previously observed using FTPlnk_phishing; researchers also describe it as a plausible, unconfirmed actor behind Operation GriefLure.Salt TyphoonName the article gives for FamousSparrow, also called Earth Estries.SectorM04Group the article also calls Whitefly or Mofang; a 2018 attack attributed to it used the same legitimate executable later seen in SquawkDoor attacks.Space PiratesEast Asian group the article also calls UAT-8302; reporting on it included infrastructure that overlapped with the researchers' SparrowDoor findings.UAT-8302Name the article gives for Space Pirates; its reported infrastructure overlapped with the researchers' SparrowDoor findings.UnsolicitedBookerGroup previously observed using FTPlnk_phishing; the article says it continues to target China.WhiteflyName the article gives for SectorM04, also called Mofang.
Malware
BeaglesThe second attack we focused on involved a fake Claude website and the Beagles backdoor. The group used fake domains to download MSI files, each containing three components: a legitimate EXE, a DLL used for sideloading,CrowDoorfrom other tools in the same shared-codebase family, including earlier versions of SparrowDoor, CrowDoor, TernDoor, and Hemigate. The toolkit's evolution and a comparative table are provided in the "FamilyHemigatein the same shared-codebase family, including earlier versions of SparrowDoor, CrowDoor, TernDoor, and Hemigate. The toolkit's evolution and a comparative table are provided in the "Family development" section.PlugXused the same .exe file and a similarly named sideloaded DLL, MSVCR110.dll, but the final payload was PlugX. In our case, the final payload is a new tool that we named SquawkDoor. Malicious libraries namedSparrowDoorWe discovered a FamousSparrow campaign that used two tools: the new SquawkDoor backdoor and an updated version of the SparrowDoor backdoor.SquawkDoorWe discovered a FamousSparrow campaign that used two tools: the new SquawkDoor backdoor and an updated version of the SparrowDoor backdoor.TernDoorother tools in the same shared-codebase family, including earlier versions of SparrowDoor, CrowDoor, TernDoor, and Hemigate. The toolkit's evolution and a comparative table are provided in the "Family development"
Vendors
Amazonto log the download event, and also sends a request to downloadUrl to download the payload from an Amazon S3 bucket.Avastdirectory, similar to the directory used by SquawkDoor, and drops three files there: the legitimate Avast Antivirus Installer (NisaSrv.exe), the malicious WTSAPI32.dll library, and a file named NisaSrv containingESETused hhc.exe (SHA-256: fafb6ffd3ffcf414b702354f62a5216351af4566ed61ece7784846a6938bb8d9), a component of ESET Security Suite that is vulnerable to DLL sideloading. In 2018, the same file was used in an attack by
Products
Amazon S3to log the download event, and also sends a request to downloadUrl to download the payload from an Amazon S3 bucket.Avast Antivirus Installersimilar to the directory used by SquawkDoor, and drops three files there: the legitimate Avast Antivirus Installer (NisaSrv.exe), the malicious WTSAPI32.dll library, and a file named NisaSrv containing theESET Security Suite(SHA-256: fafb6ffd3ffcf414b702354f62a5216351af4566ed61ece7784846a6938bb8d9), a component of ESET Security Suite that is vulnerable to DLL sideloading. In 2018, the same file was used in an attack by SectorM04,Microsoft WindowsWhen the LNK file is launched, it executes the following command: "C:\Windows\System32\ftp.exe" -""s: _rels\info.dll
Tools
Countries
ChinaUnsolicitedBooker, which continues to target China, as described in our report and a report by the Chinese vendor ThreatBook.Czech RepublicThe primary targets in the observed campaigns were Nepal, the Philippines, Indonesia, Taiwan, Egypt, Germany, and the Czech Republic.EgyptThe primary targets in the observed campaigns were Nepal, the Philippines, Indonesia, Taiwan, Egypt, Germany, and the Czech Republic.GermanyThe primary targets in the observed campaigns were Nepal, the Philippines, Indonesia, Taiwan, Egypt, Germany, and the Czech Republic.IndonesiaThe primary targets in the observed campaigns were Nepal, the Philippines, Indonesia, Taiwan, Egypt, Germany, and the Czech Republic.NepalThe primary targets in the observed campaigns were Nepal, the Philippines, Indonesia, Taiwan, Egypt, Germany, and the Czech Republic.PhilippinesThe primary targets in the observed campaigns were Nepal, the Philippines, Indonesia, Taiwan, Egypt, Germany, and the Czech Republic.TaiwanThe primary targets in the observed campaigns were Nepal, the Philippines, Indonesia, Taiwan, Egypt, Germany, and the Czech Republic.Vietnam
Industries
Food-security researchGovernmentThe group is known for using its proprietary SparrowDoor backdoor and initially focused on attacks against hotels worldwide, as well as government and international organizations.Healthcaredescribed an APT campaign targeting Vietnamese military telecommunications and the Philippine healthcare sector. In this campaign, the attackers also used the ftp.exe -s: command, which launched a script, asHospitalityInternet service providersLater, FamousSparrow began actively targeting telecommunications companies and internet service providers, apparently seeking long-term access to lawful communications intercept systems.TelecommunicationsLater, FamousSparrow began actively targeting telecommunications companies and internet service providers, apparently seeking long-term access to lawful communications intercept systems.