SparrowDoor
- First seen
- 2020-08-15 00:00:00
- Malware type
- backdoor
- Profile updated
- 2026-07-07 13:09:46
Targeted industries: government-and-public-sector defense-and-aerospace
Targeted regions: country_code:us country_code:ca
Context
SparrowDoor is a sophisticated backdoor used in cyber-espionage campaigns targeting government and defense industries. It is known for its stealth and ability to exfiltrate sensitive information.
Detection coverage
- 8 YARA rules
Used by threat actors
- FamousSparrow/GhostEmperor Vulnerability Exploit and Post-Compromise Activity (campaign)
Detection rules
- NCSC_Sparrowdoor_Sleep_Routine (yara-rule)
- NCSC_Sparrowdoor_Shellcode (yara-rule)
- NCSC_Sparrowdoor_Xor (yara-rule)
- NCSC_Sparrowdoor_Clipshot (yara-rule)
- NCSC_Sparrowdoor_Config (yara-rule)
- NCSC_Sparrowdoor_Apipatch (yara-rule)
- NCSC_Sparrowdoor_Strings (yara-rule)
- NCSC_Sparrowdoor_Loader (yara-rule)
Reports & references
- jsac.jpcert.or.jp — Jsac2025 1 5 Leon Chang Theo Chen En (report)
- ESET — Famoussparrow Suspicious Hotel Guest (report)
- ncsc.gov.uk — Ncsc Mar Sparrowdoor (report)
- virusbulletin.com — Unveiling Activities Tropic Trooper 2023 Deep Analysis Xiangoop Loader And Entryshell Payload (report)
- blog-en.itochuci.co.jp — 173200 (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Sparrow Door (report)