FamousSparrow Deploys New SquawkDoor Backdoor and Updated SparrowDoor

· Original article ↗

Summary

Positive Technologies details FamousSparrow attacks in 2026 using new SquawkDoor and updated SparrowDoor backdoors, delivered through malicious LNK files and compromised websites displaying fake certificate prompts.

Key points

  • The campaign targeted users in Nepal, the Philippines, Indonesia, Taiwan, Egypt, Germany, and the Czech Republic; researchers confirmed access to an international food-security research organization's information system.
  • Compromised websites injected JavaScript that displayed a fake SSL error and offered a malicious MSI disguised as a certificate; LNK files also launched payloads through ftp.exe.
  • SquawkDoor uses DLL sideloading, establishes persistence, checks for analysis environments, communicates with command-and-control servers, and supports commands including file operations, screenshots, and arbitrary command execution.
  • The updated SparrowDoor combines built-in and downloadable plugins, improves stealth and persistence, and includes a keylogging plugin.
  • Researchers linked some activity to other East Asian campaigns through shared techniques and infrastructure, while noting that infrastructure overlap alone does not confirm shared operators.
  • LNK metadata and malware artifacts exposed a computer hostname that researchers linked to a suspected group member; they assess the person was likely involved in preparing the attack, but not a key operator.

Article Details

Attack Vectors
  • Compromised websites served injected JavaScript that replaced page content with a fake SSL error and prompted visitors to download a purported certificate. The downloaded MSI installed SquawkDoor or SparrowDoor.
  • An Indonesian-language RAR archive contained a document-disguised LNK file. Opening it invoked ftp.exe to run a script that extracted and launched SquawkDoor components.
  • A related 2024 attack used a ClickFix-style “I’m not a robot” lure and a malicious archive containing an LNK file. Both led to a CAB-based loader.
Defensive Notes
  • The website-injection script checked for Windows, contacted its configured server, and used /report-url and /track-download to log activity.
  • SquawkDoor and SparrowDoor used malicious DLLs loaded by legitimate executables. SquawkDoor added a current-user startup entry; SparrowDoor created a service, with a current-user autorun entry as fallback.
  • SquawkDoor could check for virtualized analysis environments and wait for a browser process before continuing. SparrowDoor disguised files by changing timestamps and applying hidden and system attributes.

Indicators of compromise

TypeIndicatorContext
DOMAINpplpp[.]microsfot[.]vipEncoded server address recovered from the malicious website-injection script.
DOMAINviscarae[.]comDomain researchers associated with the SparrowDoor C2 endpoint pattern and previously linked infrastructure.
IPV4103[.]27[.]108[.]55IP address to which viscarae.com previously resolved; the article describes an infrastructure overlap with reporting on UAT-8302.
SHA2561a442a8e12c1571a0663e64e0ac9c930035bb267259b684cd9607f76be6d017bCAB archive containing components of the SquawkDoor infection chain.
SHA2561def54444cab1fd17fe5acb42dd0d2293bcb9ce72a8e955bf6796d10d662c4ffIndonesian-language RAR archive carrying the SquawkDoor infection chain.
SHA25639bdf92a70a1bb4f07e58cd1081f80fced85df01c1f14a56ed5783104c902439BAT script named info.dll executed through the malicious LNK file.
SHA2564c7ae604ad1af90ea155865cb28fd7ccd6371f5ac172de6014b328514d4618e7Malicious LNK file that invoked ftp.exe to start the infection chain.
SHA25656f7237236374acb77c4e158e6026bac9b05b16942a2c89d41bcce6230d42f8cPowerShell script downloaded in the related ClickFix attack.
SHA256595a43169bcc5154712311e37c192a8f4bf93fa2a2b5afff465c816b01a187f2CAB archive containing the loader components in the related 2024 attack.
SHA25660292dee0e07a2b889d657e2fbd2f1cd517eaea58f1cfb1ed4a721a173520499Encrypted payload containing SquawkDoor in the LNK-delivered chain.
SHA256b379d07ba81d4190490d9893b2d6d830ff594e042dce26053ef07794d0403787Malicious MSI downloaded from the S3 bucket in the fake-certificate attacks.
SHA256c2570d398b4cae11ae87269e8b9c3a4f53d3860974be04471fa092a96ecebc1dLoader payload named svctop.exl in the related 2024 attack.
SHA256c69534bb3e6d4e1c9b21f9e4745f6fb002cbcd3ab83f9ad208eb7bb135401062Malicious MSVCR110.dll used for DLL sideloading in the LNK-delivered SquawkDoor chain.
SHA256d5135980017905588e72f7030410c5903071f803cd4d4060eb51fc28b38b5ba1Malicious Tender.rar archive containing an LNK-led infection chain.
SHA256e5f7bbfc187264336dea5dfebfb5a7dd1e7fcdcc9692db55fbe6eb4d28f027bcMalicious CertFixer.msi that installed the updated SparrowDoor backdoor.
SHA256f23e5391656b178bc0ab510b0fca6ffbd963cf94870c82a5920f0f338f561f18Malicious MSVCR110.dll variant used in the MSI-based infection chain.
SHA256f51dc5e1848daee4e607d46faa25033e1151060cd3482ad4439754440d6c4c01Malicious CertFixer.msi associated with the attack targeting Germany.
SHA256f8204ba0763622a5f7ed3ca9d8c970eb52d10505690b17c920039dead408fbc5Malicious MSVCR110.dll used for sideloading in the related 2024 attack.
SHA256fafb6ffd3ffcf414b702354f62a5216351af4566ed61ece7784846a6938bb8d9Hash of the legitimate executable abused for DLL sideloading in the described attacks.
URLhxxps[:]//www[.]cloudf-update[.]com/down[.]txtNext-stage download URL in the related 2024 ClickFix attack.
URLhxxps[:]//www[.]cloudf-update[.]com/files/Tender[.]rarLink to the malicious Tender.rar archive in a likely initial lure document.
URLhxxps[:]//www[.]cloudf-update[.]com/wp-statics/test[.]docURL from which the PowerShell script downloaded the next stage.

MITRE ATT&CK

T1027 · Obfuscated Files or InformationThe backdoor chains stored encrypted payloads and used obfuscated JavaScript or encrypted configuration data.T1036.007 · Double File ExtensionThe malicious Strategi_AS_Referensi_April2026.docx.lnk file used a document extension before its actual LNK extension.T1055 · Process InjectionSparrowDoor wrote its decrypted payload into a spawned msiexec.exe process and transferred execution to it.T1056.001 · KeyloggingSparrowDoor's built-in keylogging module installed a low-level keyboard hook and recorded keystrokes with active-window titles.T1059.001 · PowerShellThe related 2024 attack used a PowerShell script to download its next stage.T1059.003 · Windows Command ShellThe infection scripts and SquawkDoor used cmd.exe; SquawkDoor also supported C2 commands executed through the command interpreter.T1070.006 · TimestompSparrowDoor changed the timestamps of its working directory and files to match ntdll.dll.T1071.001 · Web ProtocolsThe website-injection script sent HTTP requests to its configured server, and SparrowDoor could communicate with its C2 server through HTTP POST requests.T1082 · System Information DiscoverySquawkDoor collected OS and computer information, while SparrowDoor collected a broader victim-system profile.T1105 · Ingress Tool TransferSparrowDoor could request missing PE plugins from its C2 server and receive files for creation in the temporary directory.T1113 · Screen CaptureA supported SquawkDoor C2 command captured a screenshot.T1189 · Drive-by CompromiseFamousSparrow injected JavaScript into compromised websites to show a fake SSL error and offer a malicious certificate download.T1204.002 · Malicious FileThe infection chains relied on users opening a malicious LNK file or executing a purported certificate installer.T1497.001 · System ChecksSquawkDoor checked memory, disk, registry, processes, drivers, devices, MAC addresses, screen resolution, and firmware for signs of virtualized analysis environments.T1497.003 · Time Based ChecksWhen configured to do so, SquawkDoor waited until a target browser process was running before continuing.T1518.001 · Security Software DiscoverySparrowDoor included the names of installed antivirus products in the system profile sent to its C2 server.T1543.003 · Windows ServiceSparrowDoor created an automatically launching Windows service named NisaSrv for persistence.T1547.001 · Registry Run Keys / Startup FolderSquawkDoor created a current-user startup entry named WindowsUpdateAssist; SparrowDoor used a current-user autorun key if service persistence failed.T1564.001 · Hidden Files and DirectoriesSparrowDoor applied hidden and system attributes to its working directory and files.T1574.001 · DLLLegitimate executables loaded attacker-supplied MSVCR110.dll or WTSAPI32.dll, which then loaded encrypted backdoor payloads.

People

Threat Actors

Malware

Vendors

Products

Tools

Countries

Industries

Related Articles