Thread Rating:
  • 1 Vote(s) - 5 Average
  • 1
  • 2
  • 3
  • 4
  • 5
FamousSparrow APT Wings in to Spy on Hotels, Governments
#1
Information 
Quote:A cyberespionage group dubbed “FamousSparrow” by researchers has taken flight, targeting hotels, governments and private organizations around the world with a custom backdoor called, appropriately, “SparrowDoor.” It’s one of the advanced persistent threats (APTs) that targeted the ProxyLogon vulnerabilities earlier this year, according to ESET, though its activity has only recently come to light.
 
According to the firm, the backdoor’s malicious actions include the ability to: rename or delete files; create directories; shut down processes; send information such as file attributes, file size and file write time; exfiltrate the content of a specified file; write data to a specified file; or establish an interactive reverse shell. There’s also a kill switch to remove persistence settings and all SparrowDoor files from the victim machines.
 
“The targeting, which includes governments worldwide, suggests that FamousSparrow’s intent is espionage,” researchers noted.
 
The ProxyLogon remote code execution (RCE) bug was disclosed in March, and was used by more than 10 APT groups to establish access via shellcode to Exchange mail servers worldwide in a flurry of attacks. According to ESET telemetry, FamousSparrow started to exploit the vulnerabilities the day following Microsoft’s release of a patch for the problem.
 
In FamousSparrow’s case, it used the bug to deploy SparrowDoor, which has been seen in other attacks (many of them against hotels), according to ESET. These additional campaigns have occurred both before and after ProxyLogon, and date back to August 2019, researchers noted.

Read more: FamousSparrow APT Spies on Hotels, Governments | Threatpost
[-] The following 1 user says Thank You to silversurfer for this post:
  • harlan4096
Reply


Messages In This Thread
FamousSparrow APT Wings in to Spy on Hotels, Governments - by silversurfer - 23 September 21, 16:46

Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
AMD reportedly set to launch EPYC 4004 ...
AMD launches EPYC 40...harlan4096 — 09:39
NoVirusThanks OSArmor v2.0.0.0
OSArmor has been u...harlan4096 — 07:10
Apple releases iOS 17.5.1 to fix Photo g...
Apple has released...harlan4096 — 07:08
Microsoft announces Copilot+ PCs and AI-...
On a special event...harlan4096 — 07:06
1.0.98 release (2024/05/19)
1.0.98 release (20...harlan4096 — 06:32

[-]
Birthdays
Today's Birthdays
avatar (48)Mirzojap
avatar (34)idilysaju
Upcoming Birthdays
avatar (37)axuben
avatar (38)ihijudu
avatar (38)odukoromu
avatar (44)Joanna4589

[-]
Online Staff
There are no staff members currently online.

>