Threat intelligence specialists at the Positive Technologies Expert Security Center (PT ESC) have uncovered a new targeted campaign by FamousSparrow. The threat group has previously targeted the hospitality industry, government entities, and international organizations, and later shifted its focus to telecommunications companies and internet service providers in an effort to gain long-term access to their infrastructure. In this latest campaign, one confirmed target was the information system of an international research organization focused on food security.
Evidence of FamousSparrow activity was found in Nepal, the Philippines, Indonesia, Taiwan, Egypt, Germany, and the Czech Republic. Malicious files and infection chain components contained text in local languages, indicating that the attackers had tailored their operations to specific audiences in advance. The threat actors compromised selected websites and used targeted lures. The campaign's technical infrastructure also enabled them to track visits and downloads and scale the attacks if needed.
One infection vector involved compromised websites. The attackers injected a malicious script that mimicked a secure connection error and prompted visitors to install an SSL certificate, a digital document that encrypts data and verifies that a website is secure. Instead, the victim downloaded a malicious MSI file (a Windows Installer package used to install, update, and remove software), which deployed SquawkDoor or SparrowDoor on the system once executed.
The new SquawkDoor backdoor can collect system information, manipulate files, and execute operator commands. The updated SparrowDoor has an expanded feature set, additional communication protocols, and the ability to load modules that extend its capabilities after the attackers gain access to the target infrastructure. As a result, although the attacks identified so far appear to be targeted, the campaign infrastructure and malware capabilities could allow FamousSparrow to quickly expand both its geographic reach and the number of potential victims.
Although researchers have not observed mass distribution of the campaign, its reach spans seven countries across Asia, Europe, and Africa. The localization of malicious files and fake messages into specific languages shows that FamousSparrow prepares its attacks with the selected targets in mind. The compromise of an international research organization's system also indicates that the risk extends beyond commercial companies and government entities to include scientific and international organizations.
The research shows that FamousSparrow continues to evolve its proprietary toolset. The updated SparrowDoor has become more capable and stealthier, while the new SquawkDoor expands the group's ability to remotely control infected devices. At the same time, mechanisms for tracking visits and downloads could allow the attackers to turn targeted operations into a broader campaign. PT ESC experts recommend that organizations check their infrastructure against the published indicators of compromise and pay particular attention to unusual execution of installer files downloaded through a browser.