SparrowDoor

First seen
2020-08-15 00:00:00
Malware type
backdoor
Profile updated
2026-07-07 13:09:46

Targeted industries: government-and-public-sector defense-and-aerospace

Targeted regions: country_code:us country_code:ca

Context

SparrowDoor is a sophisticated backdoor used in cyber-espionage campaigns targeting government and defense industries. It is known for its stealth and ability to exfiltrate sensitive information.

Detection coverage

  • 8 YARA rules

Used by threat actors

  • FamousSparrow/GhostEmperor Vulnerability Exploit and Post-Compromise Activity (campaign)

Detection rules

  • NCSC_Sparrowdoor_Sleep_Routine (yara-rule)
  • NCSC_Sparrowdoor_Shellcode (yara-rule)
  • NCSC_Sparrowdoor_Xor (yara-rule)
  • NCSC_Sparrowdoor_Clipshot (yara-rule)
  • NCSC_Sparrowdoor_Config (yara-rule)
  • NCSC_Sparrowdoor_Apipatch (yara-rule)
  • NCSC_Sparrowdoor_Strings (yara-rule)
  • NCSC_Sparrowdoor_Loader (yara-rule)

Reports & references

  • jsac.jpcert.or.jp — Jsac2025 1 5 Leon Chang Theo Chen En (report)
  • ESET — Famoussparrow Suspicious Hotel Guest (report)
  • ncsc.gov.uk — Ncsc Mar Sparrowdoor (report)
  • virusbulletin.com — Unveiling Activities Tropic Trooper 2023 Deep Analysis Xiangoop Loader And Entryshell Payload (report)
  • blog-en.itochuci.co.jp — 173200 (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Sparrow Door (report)

External references