Skip to main content
Mallory
🇨🇳 CN5 malware families

Famous Sparrow

Also known asfamous_sparrow

Famous Sparrow is a suspected China-nexus advanced persistent threat (APT) group active since at least 2019. It has a history of targeting hotels, governments, international organizations, and law firms. Recent reporting (Cisco Talos) assesses with high confidence that a China-linked cluster tracked as UAT-9244 closely overlaps with / is closely associated with Famous Sparrow and has targeted telecommunications providers/critical telecommunications infrastructure in South America since 2024 to maintain persistent access to communications infrastructure. In the UAT-9244 telecom-focused activity associated with Famous Sparrow, Talos reported use of three malware/tool families: (1) TernDoor, a Windows backdoor assessed as a CrowDoor variant with lineage back to SparrowDoor (long attributed to Famous Sparrow), deployed via DLL side-loading and executed in-memory (observed injected into msiexec.exe), with persistence via scheduled tasks and Registry Run keys and use of a malicious driver to suspend/terminate processes; (2) PeerTime, a multi-architecture Linux ELF backdoor (including ARM/MIPS/PowerPC/AArch64) using BitTorrent-based peer communications for instruction/payload retrieval, with tooling containing Simplified Chinese debug strings; and (3) BruteEntry, a Go-based credential brute-forcing/scanning tool used to scan and brute-force exposed services (including SSH, Postgres, and Tomcat) and to create ORB-like mass-scanning proxy/relay nodes on compromised edge devices. Aliases/related tracking noted in the content: FamousSparrow (stylistic variant) and the closely associated cluster designation UAT-9244; Talos also assessed overlap between UAT-9244 and Tropic Trooper.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

OPERATIONAL PROFILE

Targeting

Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.

Where they're from

Attributed origin per open-source reporting.

  • CN
MITRE ATT&CK

Tradecraft

11 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.

8 of 15 tactics19 techniques×N= number of intelligence reports citing this technique
MITRE ATT&CK
TA0043
Reconnaissance
1 technique
T1595
Active Scanning
TA0002
Execution
2 techniques
T1053
Scheduled Task/Job
T1053.005×2
Scheduled Task
T1059
Command and Scripting Interpreter
TA0003
Persistence
2 techniques
T1053
Scheduled Task/Job
T1053.005×2
Scheduled Task
T1547
Boot or Logon Autostart Execution
T1547.001×2
Registry Run Keys / Startup Folder
TA0004
Privilege Escalation
3 techniques
T1053
Scheduled Task/Job
T1053.005×2
Scheduled Task
T1055×3
Process Injection
T1547
Boot or Logon Autostart Execution
T1547.001×2
Registry Run Keys / Startup Folder
TA0005
Stealth
3 techniques
T1014
Rootkit
T1036×2
Masquerading
T1055×3
Process Injection
TA0006
Credential Access
1 technique
T1110×3
Brute Force
TA0007
Discovery
1 technique
T1082
System Information Discovery
TA0011
Command and Control
1 technique
T1105
Ingress Tool Transfer
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping11

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal5

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables

Domains, IPs, and hashes tied to this actor, refreshed continuously.